Widget Post Slider Security & Risk Analysis

wordpress.org/plugins/widget-post-slider

Widget Post Slider to display posts image in a slider from category.

1K active installs v1.3.6 PHP + WP 4.3+ Updated Apr 10, 2024
category-posts-sliderlatest-posts-widget-sliderposts-widgetwidgetwidget-post-slider
85
A · Safe
CVEs total1
Unpatched0
Last CVEApr 22, 2024
Safety Verdict

Is Widget Post Slider Safe to Use in 2026?

Generally Safe

Score 85/100

Widget Post Slider has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Apr 22, 2024Updated 2yr ago
Risk Assessment

The static analysis of the 'widget-post-slider' plugin version 1.3.6 reveals a generally good security posture. The plugin demonstrates strong adherence to secure coding practices, with no identified dangerous functions, file operations, or external HTTP requests. SQL queries are all prepared statements, and the vast majority of output is properly escaped, minimizing the risk of direct code injection or data leakage through these vectors. The attack surface is also minimal, with no AJAX handlers, REST API routes, shortcodes, or cron events exposed without authentication or permission checks, indicating a thoughtful approach to limiting entry points.

Key Concerns

  • No capability checks found
  • No nonce checks found
  • 1 Medium severity CVE known
  • 3% of output not properly escaped
Vulnerabilities
1 published

Widget Post Slider Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-32801medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Widget Post Slider <= 1.3.5. - Authenticated (Admin+) Stored Cross-Site Scripting

Apr 22, 2024 Patched in 1.3.6 (8d)
Version History

Widget Post Slider Release Timeline

v1.3.51 CVE
v1.3.41 CVE
v1.3.31 CVE
v1.3.21 CVE
v1.3.11 CVE
v1.31 CVE
v1.21 CVE
v1.0.11 CVE
v1.01 CVE
Code Analysis
Analyzed Mar 16, 2026

Widget Post Slider Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
35 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

97% escaped36 total outputs
Attack Surface

Widget Post Slider Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionwidgets_initinc\functions.php:12
actionwp_enqueue_scriptsinc\scripts.php:20
actioninitwidget-post-slider.php:34
Maintenance & Trust

Widget Post Slider Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedApr 10, 2024
PHP min version
Downloads63K

Community Trust

Rating86/100
Number of ratings6
Active installs1K
Developer Profile

Widget Post Slider Developer Profile

ShapedPlugin LLC

18 plugins · 315K total installs

78
trust score
Avg Security Score
98/100
Avg Patch Time
361 days
View full developer profile
Detection Fingerprints

How We Detect Widget Post Slider

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/widget-post-slider/assets/css/slick.css/wp-content/plugins/widget-post-slider/assets/css/font-awesome.min.css/wp-content/plugins/widget-post-slider/assets/css/style.css/wp-content/plugins/widget-post-slider/assets/js/slick.min.js
Script Paths
/wp-content/plugins/widget-post-slider/assets/js/slick.min.js
Version Parameters
widget-post-slider/assets/css/slick.css?ver=widget-post-slider/assets/css/font-awesome.min.css?ver=widget-post-slider/assets/css/style.css?ver=widget-post-slider/assets/js/slick.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
widget-post-slider-areawidget-post-slider-wrap
FAQ

Frequently Asked Questions about Widget Post Slider