All In One Elementor Addon Slider Security & Risk Analysis

wordpress.org/plugins/ultimate-slider-toolkit

The MT Slider is an Elementor slider plugin that enables you to add advanced sliders to your WordPress website.

10 active installs v1.0.4 PHP 7.2+ WP 5.0+ Updated Oct 13, 2025
carouselimage-sliderslidertestimonial-slidervideo-slider
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is All In One Elementor Addon Slider Safe to Use in 2026?

Generally Safe

Score 100/100

All In One Elementor Addon Slider has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The "ultimate-slider-toolkit" v1.0.4 exhibits a generally strong security posture based on the provided static analysis. The absence of known vulnerabilities and CVEs, combined with a complete lack of SQL injection risks due to prepared statements, is highly positive. Furthermore, the plugin demonstrates excellent output escaping practices, with all 247 outputs properly escaped, mitigating cross-site scripting (XSS) risks. The absence of file operations and dangerous function usage is also a significant strength.

However, several areas raise concerns. The complete lack of nonce checks and capability checks across all entry points (even if the attack surface is currently reported as zero) is a significant weakness. This indicates a lack of fundamental security controls that could be exploited if any new entry points are introduced or if the current assessment of the attack surface is incomplete. The presence of two external HTTP requests, while not inherently insecure, warrants investigation to ensure they do not introduce third-party vulnerabilities or data leakage risks. The absence of any taint flow analysis or critical/high severity findings suggests that no immediate exploitable vulnerabilities were detected in the analyzed code paths, but the lack of comprehensive analysis (0 flows analyzed) leaves potential blind spots.

In conclusion, while the plugin has avoided past vulnerabilities and demonstrates good coding hygiene in areas like SQL and output escaping, the absence of authentication and authorization checks on potential entry points is a critical oversight. The two external HTTP requests also represent an area for scrutiny. The plugin's strengths lie in its avoidance of common vulnerability types and robust escaping, but its weaknesses lie in the missing fundamental security checks that are crucial for robust WordPress plugin security.

Key Concerns

  • No nonce checks implemented
  • No capability checks implemented
  • External HTTP requests present
  • No taint flows analyzed
Vulnerabilities
None known

All In One Elementor Addon Slider Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

All In One Elementor Addon Slider Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
247 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

100% escaped247 total outputs
Attack Surface

All In One Elementor Addon Slider Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionelementor/widgets/widgets_registeredultimate-slider-toolkit.php:38
actionwp_enqueue_scriptsultimate-slider-toolkit.php:112
actionadmin_enqueue_scriptsultimate-slider-toolkit.php:124
Maintenance & Trust

All In One Elementor Addon Slider Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 13, 2025
PHP min version7.2
Downloads804

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

All In One Elementor Addon Slider Developer Profile

Mobimint

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect All In One Elementor Addon Slider

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ultimate-slider-toolkit/assets/css/font-awesome.min.css/wp-content/plugins/ultimate-slider-toolkit/assets/css/style.css/wp-content/plugins/ultimate-slider-toolkit/assets/css/owl.carousel.min.css/wp-content/plugins/ultimate-slider-toolkit/assets/css/owl.theme.default.min.css/wp-content/plugins/ultimate-slider-toolkit/assets/js/owl.carousel.min.js/wp-content/plugins/ultimate-slider-toolkit/assets/js/custom.js/wp-content/plugins/ultimate-slider-toolkit/assets/js/admin-custom.js
Script Paths
/wp-content/plugins/ultimate-slider-toolkit/assets/js/owl.carousel.min.js/wp-content/plugins/ultimate-slider-toolkit/assets/js/custom.js/wp-content/plugins/ultimate-slider-toolkit/assets/js/admin-custom.js
Version Parameters
/wp-content/plugins/ultimate-slider-toolkit/assets/css/style.css?ver=/wp-content/plugins/ultimate-slider-toolkit/assets/js/custom.js?ver=/wp-content/plugins/ultimate-slider-toolkit/assets/js/admin-custom.js?ver=

HTML / DOM Fingerprints

CSS Classes
timeline-ustktimeline-scroll-wrappertimeline-containertimeline-pointdottimeline-yeartimeline-contentmobile-content+1 more
Data Attributes
data-year
JS Globals
usm_slider_settingstimelineData
FAQ

Frequently Asked Questions about All In One Elementor Addon Slider