
Yoo Slider – Image Slider & Video Slider Security & Risk Analysis
wordpress.org/plugins/yoo-sliderCraft a slider effortlessly with our WordPress plugin! Design image slider, video slider, carousel or even coverflow slider in seconds.
Is Yoo Slider – Image Slider & Video Slider Safe to Use in 2026?
Use With Caution
Score 63/100Yoo Slider – Image Slider & Video Slider has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The yoo-slider plugin version 2.2.0 presents a mixed security posture. While it demonstrates good practices in using prepared statements for all SQL queries and includes a substantial number of nonce and capability checks, significant concerns arise from its large, unprotected attack surface. A notable 11 out of 12 entry points, specifically AJAX handlers, lack authentication checks, creating a broad avenue for potential exploitation by unauthenticated users. The presence of one flow with unsanitized paths in taint analysis, although not classified as critical or high severity, warrants attention as it indicates a potential for input manipulation.
The plugin's vulnerability history is a significant red flag. With 5 known CVEs, one of which remains unpatched, and a history of Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerabilities, it suggests a pattern of insecure coding practices and an ongoing struggle with security patching. The most recent vulnerability being only from March 2024 further emphasizes the active nature of security issues with this plugin. Despite the strengths in SQL handling and output escaping (though not perfect at 67%), the numerous unprotected AJAX endpoints and the history of unpatched vulnerabilities considerably elevate the risk associated with this plugin.
Key Concerns
- Unprotected AJAX handlers
- Flows with unsanitized paths
- Unpatched CVEs
- History of medium severity CVEs
- Output escaping not fully implemented
Yoo Slider – Image Slider & Video Slider Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
Yoo Slider <= 2.1.1 - Reflected Cross-Site Scripting
Yoo Slider plugin <= 2.0.0 - Cross-Site Request Forgery
Yoo Slider plugin <= 2.0.0 - Cross-Site Request Forgery
Yoo Slider plugin <= 2.0.0 - Stored Cross-Site Scripting
Yoo Slider – Image Slider & Video Slider <= 2.0.0 - Cross-Site Request Forgery
Yoo Slider – Image Slider & Video Slider Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Yoo Slider – Image Slider & Video Slider Attack Surface
AJAX Handlers 11
Shortcodes 1
WordPress Hooks 14
Maintenance & Trust
Yoo Slider – Image Slider & Video Slider Maintenance & Trust
Maintenance Signals
Community Trust
Yoo Slider – Image Slider & Video Slider Alternatives
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider
ml-slider
Slider, gallery, carousel plugin for WordPress. Build your image slider, video slider, post slider, YouTube slider, or WooCommerce product slider.
Filmstrip Carousel
filmstrip-carousel
A responsive 3D filmstrip/coverflow carousel for images and video. Built with Three.js & WebGL. Lightweight, fast, and customizable.
Smart Slider 3
smart-slider-3
Responsive slider plugin to create sliders in visual editor easily. Build beautiful image slider, layer slider, video slider, post slider, and more.
Prime Slider – Addons for Elementor
bdthemes-prime-slider-lite
Create responsive sliders using Elementor for hero sections, posts, logos, images, products, testimonials, and more.
Master Slider – Responsive Touch Slider
master-slider
Build SEO friendly sliders fast and easy with touch swipe navigation that works smoothly across all devices.
Yoo Slider – Image Slider & Video Slider Developer Profile
1 plugin · 600 total installs
How We Detect Yoo Slider – Image Slider & Video Slider
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/yoo-slider/js/gks-admin-editor-block.js/wp-content/plugins/yoo-slider/css/gks-admin-editor-block.css/wp-content/plugins/yoo-slider/gks-config.php/wp-content/plugins/yoo-slider/classes/GKSCssBuilder.php/wp-content/plugins/yoo-slider/classes/GKSLicenseManager.php/wp-content/plugins/yoo-slider/classes/GKSNotificationManager.php/wp-content/plugins/yoo-slider/classes/gks-ajax.php/wp-content/plugins/yoo-slider/classes/premium/gks-premium-ajax.php+3 more/wp-content/plugins/yoo-slider/js/gks-shortcode-block.jsyoo-slider/style.css?ver=yoo-slider/script.js?ver=HTML / DOM Fingerprints
gks-slider-wrappergks-slider-itemgks-slider-navgks-slider-prevgks-slider-nextyooslider-block__wrapper<!-- Yoo Slider --><!-- Yoo Slider Block -->data-gks-slider-optionsdata-slider-idyooslider_ajax_urlyooslider_nonce/wp-json/gks/v1/sliders/wp-json/gks/v1/options[yooslider id=