
Whook content slider Security & Risk Analysis
wordpress.org/plugins/whook-content-sliderWordress website or developer need to showcase work or case study on home page of website. Bloggers need to showcase their featured blogs on the home …
Is Whook content slider Safe to Use in 2026?
Generally Safe
Score 85/100Whook content slider has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The whook-content-slider plugin v1.0 exhibits a mixed security posture. On the positive side, it has a small attack surface with only one identified entry point (a shortcode), and importantly, no AJAX handlers or REST API routes are exposed without proper authentication checks. The plugin also demonstrates good practices by exclusively using prepared statements for its single SQL query, indicating a resistance to SQL injection vulnerabilities. There are no recorded CVEs, suggesting a history of reasonable security, or at least no publicly disclosed critical issues.
However, significant concerns arise from the lack of output escaping. With 14 total outputs and 0% properly escaped, the plugin is highly vulnerable to Cross-Site Scripting (XSS) attacks. Any user-provided data that is displayed through the plugin's shortcode is likely to be rendered directly, allowing an attacker to inject malicious scripts into the victim's browser. Furthermore, the absence of nonce checks and capability checks on the identified entry point (the shortcode) means that even if the shortcode itself doesn't directly perform sensitive actions, it could be leveraged in conjunction with other vulnerabilities or used to trigger unintended plugin behavior without proper authorization checks.
In conclusion, while the plugin avoids common pitfalls like raw SQL queries and a large attack surface, the complete lack of output escaping presents a critical security weakness. The absence of nonce and capability checks on the shortcode further exacerbates this risk. Mitigation of XSS vulnerabilities is paramount for this plugin.
Key Concerns
- Unescaped output found
- Missing nonce checks on entry point
- Missing capability checks on entry point
Whook content slider Security Vulnerabilities
Whook content slider Code Analysis
SQL Query Safety
Output Escaping
Whook content slider Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
Whook content slider Maintenance & Trust
Maintenance Signals
Community Trust
Whook content slider Alternatives
Ditty – Responsive News Tickers, Sliders, and Lists
ditty-news-ticker
Ditty offers a range of content display options, including its signature news ticker and customizable layouts.
Slider Pro
sliderpro
Slider Pro is a responsive slider plugin that offers Premium features for FREE, including animated layers, post content, full width layout and more.
Slider Pro
slider-pro-wp
A modular, responsive and touch-enabled jQuery slider plugin that enables you to create elegant and professionally looking sliders
Custom Post Slider
custom-post-slider
Custom Post Slider Plugin Display Post with Owl Slider order by date, title, random... Developer can override HTML or create new layout in their theme …
Post Sliders
post-sliders
Post Slider Plugin is a handy and effective solution for anyone seeking a responsive post slider. It offers a variety of slider templates to set up yo …
Whook content slider Developer Profile
3 plugins · 20 total installs
How We Detect Whook content slider
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/whook-content-slider/css/owl.carousel.min.css/wp-content/plugins/whook-content-slider/css/slider-style.css/wp-content/plugins/whook-content-slider/js/owl.carousel.min.js/wp-content/plugins/whook-content-slider/js/wrcis-slider-js.js/wp-content/plugins/whook-content-slider/js/owl.carousel.min.js/wp-content/plugins/whook-content-slider/js/wrcis-slider-js.jswhook-content-slider/css/owl.carousel.min.css?ver=whook-content-slider/css/slider-style.css?ver=whook-content-slider/js/owl.carousel.min.js?ver=whook-content-slider/js/wrcis-slider-js.js?ver=HTML / DOM Fingerprints
main-slider-areaslider-title-areabanner-sliderowl-carouselitemslider-imageslider-contentslider-content-area+11 moredata-slide-todata-targetDtSliderClass[dt_slider]