
Wonder Slider Lite Security & Risk Analysis
wordpress.org/plugins/wonderplugin-slider-liteFully responsive WordPress slider - 3D transition effects, built-in Lightbox gallery, supports images, mp4 videos, YouTube, Vimeo and WordPress posts.
Is Wonder Slider Lite Safe to Use in 2026?
Generally Safe
Score 98/100Wonder Slider Lite has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin "wonderplugin-slider-lite" v14.5 exhibits a mixed security posture with some encouraging strengths but notable areas for improvement. On the positive side, the plugin demonstrates good practices by implementing nonce checks and capability checks on a significant number of its entry points, and it has no unpatched CVEs. However, the static analysis reveals a critical weakness with the use of the `unserialize` function without apparent sanitization, which is a known risk for arbitrary code execution. Furthermore, the taint analysis indicates a substantial number of flows with unsanitized paths, specifically 9 high-severity flows, suggesting potential vulnerabilities in how user input is handled before being used in operations. The vulnerability history shows a pattern of medium-severity Cross-site Scripting (XSS) vulnerabilities, which, while currently patched, points to a recurring issue in output escaping, a concern reinforced by the static analysis showing only 39% of outputs are properly escaped.
While the limited attack surface and the absence of critical unpatched vulnerabilities are strengths, the presence of `unserialize` and the high number of unsanitized taint flows are significant red flags. The historical XSS issues and the low percentage of properly escaped outputs further highlight a need for more robust input validation and output encoding. Overall, the plugin has some foundational security measures in place, but the identified risks, particularly around data deserialization and input sanitization, require immediate attention to mitigate potential security breaches.
Key Concerns
- Use of unserialize without clear sanitization
- High number of unsanitized taint flows (9 high severity)
- Low percentage of properly escaped outputs (39%)
- Historical XSS vulnerabilities indicate output escaping issues
Wonder Slider Lite Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Wonder Slider Lite & Wonder Slider <= 14.4 - Authenticated (Contributor+) Dom-based Stored Cross-Site Scripting
Wonder Slider Lite <= 13.9 - Reflected Cross-Site Scripting via 'page'
Wonder Slider Lite Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Wonder Slider Lite Attack Surface
AJAX Handlers 2
REST API Routes 1
Shortcodes 1
WordPress Hooks 19
Maintenance & Trust
Wonder Slider Lite Maintenance & Trust
Maintenance Signals
Community Trust
Wonder Slider Lite Alternatives
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider
ml-slider
Slider, gallery, carousel plugin for WordPress. Build your image slider, video slider, post slider, YouTube slider, or WooCommerce product slider.
Prime Slider – Addons for Elementor
bdthemes-prime-slider-lite
Create responsive sliders using Elementor for hero sections, posts, logos, images, products, testimonials, and more.
Master Slider – Responsive Touch Slider
master-slider
Build SEO friendly sliders fast and easy with touch swipe navigation that works smoothly across all devices.
Ovation Elements
ovation-elements
Transform your site with captivating sliders. Perfect for beginners and advanced users. Create and customize with our ultimate slider plugin.
Slider for Photos Images Videos
media-slider
Create responsive image and video sliders with thumbnails, navigation, autoplay, and carousel layouts for your site.
Wonder Slider Lite Developer Profile
6 plugins · 26K total installs
How We Detect Wonder Slider Lite
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wonderplugin-slider-lite/engine/wonderpluginslider.js/wp-content/plugins/wonderplugin-slider-lite/engine/wonderpluginsliderskins.js/wp-content/plugins/wonderplugin-slider-lite/engine/wonderpluginsliderengine.css/wp-content/plugins/wonderplugin-slider-lite/app/wonderplugin-slider-creator.js/wp-content/plugins/wonderplugin-slider-lite/wonderpluginslider.css/wp-content/plugins/wonderplugin-slider-lite/app/block/block.build.jshttps://www.wonderplugin.com/wordpress-slider/wonderplugin-slider-lite/engine/wonderpluginslider.js?ver=wonderplugin-slider-lite/engine/wonderpluginsliderskins.js?ver=wonderplugin-slider-lite/engine/wonderpluginsliderengine.css?ver=wonderplugin-slider-lite/app/wonderplugin-slider-creator.js?ver=wonderplugin-slider-lite/wonderpluginslider.css?ver=wonderplugin-slider-lite/app/block/block.build.js?ver=HTML / DOM Fingerprints
wonderplugin-slider-containerwonderplugincustomsliderWonderSlider Lite Plugindata-wonderplugin-sliderwonderplugin_slider_configWonderPluginSlider/wp-json/wonderplugin/slider/itemlist[wonderplugin_slider