WEN Logo Slider Security & Risk Analysis

wordpress.org/plugins/wen-logo-slider

Simple responsive logo slider for your WordPress site

1K active installs v3.6 PHP 5.6.2+ WP 4.7+ Updated Apr 5, 2026
carouselimage-carousellogologo-carouselslider
99
A · Safe
CVEs total1
Unpatched0
Last CVEMay 7, 2026
Safety Verdict

Is WEN Logo Slider Safe to Use in 2026?

Generally Safe

Score 99/100

WEN Logo Slider has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: May 7, 2026Updated 1mo ago
Risk Assessment

The wen-logo-slider plugin, version 3.5, demonstrates a generally strong security posture based on the provided static analysis. The absence of dangerous functions, SQL injection vulnerabilities, and file operations is a significant strength. Furthermore, the high percentage of properly escaped outputs and the presence of nonce and capability checks indicate good development practices for securing its limited entry points. The plugin's vulnerability history, with no recorded CVEs, further contributes to its favorable security profile, suggesting a commitment to maintaining a secure codebase or a lack of historically exploitable flaws.

However, the analysis does highlight a potential area for improvement. While the overall attack surface is small (limited to one shortcode), and there are no apparent unprotected entry points, the analysis does not provide details on the specific security checks associated with this shortcode. The taint analysis results are also absent, meaning potential data flow vulnerabilities from untrusted input to sensitive sinks cannot be fully assessed. Despite these minor points, the plugin appears to be developed with security in mind.

Key Concerns

  • No taint flow analysis performed
  • Potential for unescaped output
Vulnerabilities
1 published

WEN Logo Slider Security Vulnerabilities

CVEs by Year

1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-62127medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WEN Logo Slider <= 3.4.0 - Authenticated (Author+) Stored Cross-Site Scripting

May 7, 2026 Patched in 3.5 (5d)
Version History

WEN Logo Slider Release Timeline

v3.6Current
v3.5
v3.4.01 CVE
v3.3.01 CVE
v3.2.01 CVE
v3.1.01 CVE
v3.0.01 CVE
v2.0.81 CVE
v2.0.71 CVE
v2.0.61 CVE
v2.0.51 CVE
v2.0.41 CVE
v2.0.31 CVE
v2.0.21 CVE
v2.0.11 CVE
v2.0.01 CVE
v1.0.11 CVE
v1.0.01 CVE
Code Analysis
Analyzed Mar 16, 2026

WEN Logo Slider Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
22
159 escaped
Nonce Checks
2
Capability Checks
4
File Operations
0
External Requests
0
Bundled Libraries
2

Bundled Libraries

jQueryTinyMCE

Output Escaping

88% escaped181 total outputs
Attack Surface

WEN Logo Slider Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[WLS] includes\class-wen-logo-slider-shortcode.php:27
WordPress Hooks 23
filtermce_buttonsadmin\class-wen-logo-slider-admin.php:531
filtermce_external_pluginsadmin\class-wen-logo-slider-admin.php:532
actionplugins_loadedincludes\class-wen-logo-slider.php:146
actionadmin_enqueue_scriptsincludes\class-wen-logo-slider.php:170
actionadmin_enqueue_scriptsincludes\class-wen-logo-slider.php:171
actionadd_meta_boxesincludes\class-wen-logo-slider.php:179
actionsave_postincludes\class-wen-logo-slider.php:180
actionsave_postincludes\class-wen-logo-slider.php:181
actionadmin_head-post.phpincludes\class-wen-logo-slider.php:184
actionadmin_head-post-new.phpincludes\class-wen-logo-slider.php:185
filterpost_row_actionsincludes\class-wen-logo-slider.php:188
actionadmin_initincludes\class-wen-logo-slider.php:191
actionadmin_footerincludes\class-wen-logo-slider.php:192
actionadmin_footerincludes\class-wen-logo-slider.php:195
filterpost_updated_messagesincludes\class-wen-logo-slider.php:198
filtermce_external_languagesincludes\class-wen-logo-slider.php:201
actionadmin_menuincludes\class-wen-logo-slider.php:204
actionadmin_initincludes\class-wen-logo-slider.php:205
actionwp_enqueue_scriptsincludes\class-wen-logo-slider.php:219
actionwp_enqueue_scriptsincludes\class-wen-logo-slider.php:220
filterinitincludes\class-wen-logo-slider.php:222
filterwidget_textincludes\class-wen-logo-slider.php:225
filterwidget_textincludes\class-wen-logo-slider.php:226
Maintenance & Trust

WEN Logo Slider Maintenance & Trust

Maintenance Signals

WordPress version tested7.0
Last updatedApr 5, 2026
PHP min version5.6.2
Downloads72K

Community Trust

Rating88/100
Number of ratings10
Active installs1K
Developer Profile

WEN Logo Slider Developer Profile

WEN Themes

63 plugins · 34K total installs

100
trust score
Avg Security Score
100/100
Avg Patch Time
6 days
View full developer profile
Detection Fingerprints

How We Detect WEN Logo Slider

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wen-logo-slider/admin/css/wen-logo-slider-admin.css/wp-content/plugins/wen-logo-slider/admin/js/wen-logo-slider-admin.js/wp-content/plugins/wen-logo-slider/admin/js/wen-logo-slider-public.js/wp-content/plugins/wen-logo-slider/admin/js/wen-logo-slider-chosen.jquery.min.js/wp-content/plugins/wen-logo-slider/admin/js/wen-logo-slider-chosenImage.jquery.js/wp-content/plugins/wen-logo-slider/public/css/wen-logo-slider.css/wp-content/plugins/wen-logo-slider/public/js/wen-logo-slider.js/wp-content/plugins/wen-logo-slider/public/js/jquery.flexslider-min.js+1 more
Script Paths
/wp-content/plugins/wen-logo-slider/admin/js/wen-logo-slider-admin.js/wp-content/plugins/wen-logo-slider/admin/js/wen-logo-slider-public.js/wp-content/plugins/wen-logo-slider/admin/js/wen-logo-slider-chosen.jquery.min.js/wp-content/plugins/wen-logo-slider/admin/js/wen-logo-slider-chosenImage.jquery.js/wp-content/plugins/wen-logo-slider/public/js/wen-logo-slider.js/wp-content/plugins/wen-logo-slider/public/js/jquery.flexslider-min.js+1 more
Version Parameters
wen-logo-slider-admin.css?ver=wen-logo-slider-admin.js?ver=wen-logo-slider-public.js?ver=wen-logo-slider-chosen.jquery.min.js?ver=wen-logo-slider-chosenImage.jquery.js?ver=wen-logo-slider.css?ver=wen-logo-slider.js?ver=jquery.flexslider-min.js?ver=jquery.easing.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
wen-logo-slider-wrapperwen-logo-slider-containerwen-logo-slider-itemwen-logo-slider-caption
HTML Comments
<!-- WEN Logo Slider Shortcode Start --><!-- WEN Logo Slider Shortcode End --><!-- Start: WEN Logo Slider --><!-- End: WEN Logo Slider -->
Data Attributes
data-logo-slider-iddata-logo-slider-options
JS Globals
wen_logo_slider_options
Shortcode Output
[wen_logo_slider][wen_logo_slider_item]
FAQ

Frequently Asked Questions about WEN Logo Slider