WunderSlider Gallery Security & Risk Analysis

wordpress.org/plugins/wunderslider-gallery

WunderSlider Gallery turns default WordPress and NextGEN galleries into responsive fullscreen and embedded WunderSlider slideshows.

100 active installs v1.3.9 PHP + WP 3.6+ Updated Dec 12, 2013
banner-rotatoreffectsflickflickingfullscreen
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WunderSlider Gallery Safe to Use in 2026?

Generally Safe

Score 85/100

WunderSlider Gallery has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the "wunderslider-gallery" plugin v1.3.9 exhibits an excellent security posture. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events indicates a minimal attack surface. Furthermore, the code analysis reveals a strong adherence to secure coding practices, with no dangerous functions, no raw SQL queries, all output properly escaped, and no file operations or external HTTP requests detected. The lack of nonces and capability checks in the identified entry points (which are zero) is not a concern in this specific case as there are no such entry points to secure. The plugin's history is equally impressive, with no known CVEs, indicating a consistent track record of security. This plugin appears to be well-developed and maintained with security in mind. The only slight area for potential improvement, though not a current risk due to the lack of entry points, would be the inclusion of capability checks and nonces if any public-facing or editable functions were to be introduced in the future. However, as it stands, the plugin presents a very low risk to WordPress installations.

Vulnerabilities
None known

WunderSlider Gallery Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WunderSlider Gallery Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

WunderSlider Gallery Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

WunderSlider Gallery Maintenance & Trust

Maintenance Signals

WordPress version tested3.7.41
Last updatedDec 12, 2013
PHP min version
Downloads33K

Community Trust

Rating70/100
Number of ratings4
Active installs100
Developer Profile

WunderSlider Gallery Developer Profile

itthinx

27 plugins · 23K total installs

98
trust score
Avg Security Score
97/100
Avg Patch Time
3 days
View full developer profile
Detection Fingerprints

How We Detect WunderSlider Gallery

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wunderslider-gallery/lib/core/boot.php

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about WunderSlider Gallery