Up down image slideshow gallery Security & Risk Analysis

wordpress.org/plugins/up-down-image-slideshow-gallery

Up down image slideshow gallery lets showcase images in a vertical move style. Single image at a time and pull one by one continually.

20 active installs v12.1 PHP + WP 3.4+ Updated Oct 29, 2023
galleryimageslideshow
84
B · Generally Safe
CVEs total1
Unpatched0
Last CVEOct 30, 2023
Safety Verdict

Is Up down image slideshow gallery Safe to Use in 2026?

Mostly Safe

Score 84/100

Up down image slideshow gallery is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved.

1 known CVELast CVE: Oct 30, 2023Updated 2yr ago
Risk Assessment

The "up-down-image-slideshow-gallery" plugin v12.1 exhibits a mixed security posture. On the positive side, the code demonstrates good practices by utilizing prepared statements for all SQL queries, avoiding dangerous functions, and performing file operations or external HTTP requests, which are significant security strengths. The presence of nonce checks is also a positive indicator of security awareness. However, there are notable areas of concern that warrant attention. The lack of capability checks on entry points is a significant weakness, as it means that unauthorized users could potentially interact with the plugin's functionality. Furthermore, the output escaping is only 54% proper, indicating a high likelihood of cross-site scripting (XSS) vulnerabilities. The vulnerability history reveals a past high-severity SQL injection vulnerability, which, while currently patched, highlights a historical weakness in handling user input for database operations. This past incident, combined with the current low output escaping percentage, suggests a potential for new XSS vulnerabilities to emerge if not diligently addressed.

Key Concerns

  • Low output escaping percentage (54%)
  • No capability checks on entry points
  • One high-severity past CVE (SQLi)
Vulnerabilities
1 published

Up down image slideshow gallery Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

High
1

1 total CVE

CVE-2023-5435high · 8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Up down image slideshow gallery <= 12.0 - Authenticated (Subscriber+) SQL Injection via Shortcode

Oct 30, 2023 Patched in 12.1 (85d)
Version History

Up down image slideshow gallery Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Up down image slideshow gallery Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
24 prepared
Unescaped Output
30
35 escaped
Nonce Checks
4
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared24 total queries

Output Escaping

54% escaped65 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
<image-management-show> (pages/image-management-show.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Up down image slideshow gallery Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[up-slideshow] up-down-image-slideshow-gallery.php:175
WordPress Hooks 5
actionplugins_loadedup-down-image-slideshow-gallery.php:308
actionwp_enqueue_scriptsup-down-image-slideshow-gallery.php:309
actionplugins_loadedup-down-image-slideshow-gallery.php:310
actionadmin_menuup-down-image-slideshow-gallery.php:313
actionadmin_enqueue_scriptsup-down-image-slideshow-gallery.php:314
Maintenance & Trust

Up down image slideshow gallery Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedOct 29, 2023
PHP min version
Downloads15K

Community Trust

Rating20/100
Number of ratings1
Active installs20
Developer Profile

Up down image slideshow gallery Developer Profile

gopiplus

54 plugins · 17K total installs

75
trust score
Avg Security Score
82/100
Avg Patch Time
72 days
View full developer profile
Detection Fingerprints

How We Detect Up down image slideshow gallery

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/up-down-image-slideshow-gallery/css/style.css/wp-content/plugins/up-down-image-slideshow-gallery/images/loader.gif/wp-content/plugins/up-down-image-slideshow-gallery/js/script.js/wp-content/plugins/up-down-image-slideshow-gallery/js/udisg_show.js
Script Paths
/wp-content/plugins/up-down-image-slideshow-gallery/js/script.js/wp-content/plugins/up-down-image-slideshow-gallery/js/udisg_show.js
Version Parameters
up-down-image-slideshow-gallery/css/style.css?ver=up-down-image-slideshow-gallery/js/script.js?ver=up-down-image-slideshow-gallery/js/udisg_show.js?ver=

HTML / DOM Fingerprints

CSS Classes
udisg_widgetss
Data Attributes
udisg_Wrapperidudisg_WidthHeightudisg_ImageArrayudisg_Displaymodeudisg_Orientationudisg_Persist+1 more
JS Globals
udisg_SlideShowudisg_Show
Shortcode Output
<div id="udisg_widgetss" style="max-width:100%"></div>
FAQ

Frequently Asked Questions about Up down image slideshow gallery