Ultimate WP Slider Security & Risk Analysis

wordpress.org/plugins/ultimate-wp-slider

Ultimate WP Slider lets you build touch-enabled, responsive, and modern sliders with your own content. Includes multiple styles, per-slide captions/li …

0 active installs v1.1.3 PHP 7.4+ WP 5.6+ Updated Aug 23, 2025
image-sliderresponsivesliderwordpress-sliderwp-slider
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Ultimate WP Slider Safe to Use in 2026?

Generally Safe

Score 100/100

Ultimate WP Slider has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7mo ago
Risk Assessment

The 'ultimate-wp-slider' v1.1.3 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, file operations, and external HTTP requests is a positive indicator. Furthermore, the plugin correctly utilizes prepared statements for all SQL queries and demonstrates a high percentage of properly escaped output, significantly mitigating risks of SQL injection and cross-site scripting. The presence of nonce and capability checks on all identified entry points (AJAX handlers and shortcodes) is commendable, as it prevents unauthorized access and actions. The plugin also benefits from no known historical vulnerabilities, suggesting a commitment to security by its developers.

While the plugin's security practices are robust, there are no specific immediate risks identified in the static analysis or taint analysis that would warrant significant deductions. The attack surface, while present with 4 AJAX handlers and 1 shortcode, is fully protected by authentication and permission checks, eliminating immediate concerns. The lack of critical or high severity taint flows and zero unpatched CVEs further strengthens this assessment. Overall, this plugin appears to be developed with security in mind, adhering to best practices. Any further assessment would require deeper code review for potential logic flaws or more nuanced vulnerabilities not captured by this analysis.

Vulnerabilities
None known

Ultimate WP Slider Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Ultimate WP Slider Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
214 escaped
Nonce Checks
6
Capability Checks
6
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

97% escaped220 total outputs
Data Flows
All sanitized

Data Flow Analysis

3 flows
ajax_preview_slider (ultimate-wp-slider.php:326)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Ultimate WP Slider Attack Surface

Entry Points5
Unprotected0

AJAX Handlers 4

authwp_ajax_uwps_attach_slideultimate-wp-slider.php:58
authwp_ajax_uwps_save_orderultimate-wp-slider.php:59
authwp_ajax_uwps_preview_sliderultimate-wp-slider.php:60
authwp_ajax_uwps_delete_sliderultimate-wp-slider.php:61

Shortcodes 1

[ultimate_wp_slider] shortcodes\class.ultimate-wp-slider-shortcode.php:8
WordPress Hooks 10
actionadmin_initclass.ultimate-wp-slider-settings.php:12
actioninitpost-types\class.ultimate-wp-slider-cpt.php:6
actioninitultimate-wp-slider.php:45
actionwp_enqueue_scriptsultimate-wp-slider.php:46
actionadmin_enqueue_scriptsultimate-wp-slider.php:47
actionwpultimate-wp-slider.php:48
actionadmin_menuultimate-wp-slider.php:51
actionadmin_post_uwps_create_sliderultimate-wp-slider.php:54
actionadmin_post_uwps_save_sliderultimate-wp-slider.php:55
actionuwps_enqueue_frontendultimate-wp-slider.php:64
Maintenance & Trust

Ultimate WP Slider Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedAug 23, 2025
PHP min version7.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Ultimate WP Slider Developer Profile

certainity

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Ultimate WP Slider

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ultimate-wp-slider/vendor/flexslider/flexslider.css/wp-content/plugins/ultimate-wp-slider/assets/css/frontend.css/wp-content/plugins/ultimate-wp-slider/assets/js/frontend.js/wp-content/plugins/ultimate-wp-slider/vendor/flexslider/jquery.flexslider-min.js/wp-content/plugins/ultimate-wp-slider/assets/css/admin.css/wp-content/plugins/ultimate-wp-slider/assets/js/admin.js
Version Parameters
ultimate-wp-slider/vendor/flexslider/flexslider.css?ver=ultimate-wp-slider/assets/css/frontend.css?ver=ultimate-wp-slider/assets/js/frontend.js?ver=ultimate-wp-slider/vendor/flexslider/jquery.flexslider-min.js?ver=ultimate-wp-slider/assets/css/admin.css?ver=ultimate-wp-slider/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
uwps-slider-wrapper
Data Attributes
data-uwps-slider-id
JS Globals
UWPS_ADMIN
Shortcode Output
[ultimate_wp_slider
FAQ

Frequently Asked Questions about Ultimate WP Slider