WP Content Slideshow Security & Risk Analysis

wordpress.org/plugins/wp-content-slideshow

WP Content Slideshow is the perfect Slideshow for Wordpress. It displays up to 5 Posts or Pages with Tile, Description and Image for every Post.

100 active installs v2.3 PHP + WP 3.0+ Updated Jul 14, 2012
content-slideshowfeatured-content-slideshowslideshowwp-slideshow
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Content Slideshow Safe to Use in 2026?

Generally Safe

Score 85/100

WP Content Slideshow has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 13yr ago
Risk Assessment

The 'wp-content-slideshow' v2.3 plugin exhibits a generally good security posture concerning its attack surface and the absence of known vulnerabilities. The static analysis shows no AJAX handlers, REST API routes, cron events, or file operations, significantly limiting potential external entry points. All SQL queries are properly prepared, and there are no external HTTP requests, which are positive indicators. However, a critical concern arises from the complete lack of output escaping. With 38 outputs identified and none properly escaped, this presents a significant risk of Cross-Site Scripting (XSS) vulnerabilities. Attackers could potentially inject malicious scripts through the slideshow's output, impacting users viewing the content. The absence of nonce and capability checks also weakens the security, particularly if any of the entry points, however limited, were to be exploited.

Key Concerns

  • No output escaping
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

WP Content Slideshow Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP Content Slideshow Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
38
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped38 total outputs
Attack Surface

WP Content Slideshow Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[contentSlideshow] wp-content-slideshow.php:78
WordPress Hooks 4
actionadmin_menuwp-content-slideshow.php:19
actionwp_enqueue_scriptswp-content-slideshow.php:30
actionadmin_initwp-content-slideshow.php:41
actionsave_postwp-content-slideshow.php:42
Maintenance & Trust

WP Content Slideshow Maintenance & Trust

Maintenance Signals

WordPress version tested3.1.4
Last updatedJul 14, 2012
PHP min version
Downloads63K

Community Trust

Rating50/100
Number of ratings2
Active installs100
Developer Profile

WP Content Slideshow Developer Profile

IWEBIX

6 plugins · 240 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP Content Slideshow

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-content-slideshow/scripts/jquery.cycle.all.2.72.js/wp-content/plugins/wp-content-slideshow/scripts/slideshow.js
Script Paths
/wp-content/plugins/wp-content-slideshow/scripts/jquery.cycle.all.2.72.js/wp-content/plugins/wp-content-slideshow/scripts/slideshow.js
Version Parameters
wp-content-slideshow/scripts/jquery.cycle.all.2.72.js?ver=wp-content-slideshow/scripts/slideshow.js?ver=

HTML / DOM Fingerprints

CSS Classes
content_slideshowslideshow-navslideme
Data Attributes
content_slider
Shortcode Output
<div id="content-slideshow"> <div class="content_slideshow"> <ul>
FAQ

Frequently Asked Questions about WP Content Slideshow