Amazing Team Member Carousel Security & Risk Analysis

wordpress.org/plugins/amazing-team-member-carousel

Super modern team member plugin. Unlimited Colors, 100% responsive, automatic resize images, unlimited items, shortcode powered, custom link and more

10 active installs v2.0 PHP + WP 3.0.1+ Updated Nov 22, 2014
carouselteam-memberteam-member-wordpress-pluginunlimited-colorswordpress-team-member
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Amazing Team Member Carousel Safe to Use in 2026?

Generally Safe

Score 85/100

Amazing Team Member Carousel has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The 'amazing-team-member-carousel' plugin v2.0 exhibits a concerning security posture despite a clean vulnerability history. Static analysis reveals significant weaknesses, including an unprotected AJAX handler, which is a direct entry point for potential malicious activity. The presence of raw SQL queries without prepared statements, coupled with a critically low rate of output escaping (only 4%), strongly suggests a high risk of SQL injection and cross-site scripting (XSS) vulnerabilities. Taint analysis further confirms these risks, with two flows identified as having unsanitized paths, rated as high severity. The use of the `create_function` is also a deprecated and potentially insecure practice. While the plugin has no recorded CVEs, this lack of history does not negate the clear vulnerabilities identified in the current code.

Key Concerns

  • Unprotected AJAX handler
  • SQL queries without prepared statements
  • Low rate of output escaping
  • High severity unsanitized taint flows
  • Use of dangerous function 'create_function'
Vulnerabilities
None known

Amazing Team Member Carousel Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Amazing Team Member Carousel Code Analysis

Dangerous Functions
1
Raw SQL Queries
1
0 prepared
Unescaped Output
191
7 escaped
Nonce Checks
4
Capability Checks
10
File Operations
5
External Requests
1
Bundled Libraries
2

Dangerous Functions Found

create_functionadd_filter( 'wp_default_editor', create_function('', 'return "tinymce";') );framework\bootstrap.php:195

Bundled Libraries

TinyMCESelect2

SQL Query Safety

0% prepared1 total queries

Output Escaping

4% escaped198 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
vp_ajax_wrapper (framework\bootstrap.php:75)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Amazing Team Member Carousel Attack Surface

Entry Points2
Unprotected1

AJAX Handlers 1

authwp_ajax_vp_ajax_wrapperframework\bootstrap.php:71

Shortcodes 1

[atmc] amazing-team-member-carousel.php:241
WordPress Hooks 38
actionadmin_headadmin\metabox\icon.php:14
actionwp_enqueue_scriptsamazing-team-member-carousel.php:26
actionwp_enqueue_scriptsamazing-team-member-carousel.php:29
actionplugins_loadedamazing-team-member-carousel.php:48
actioninitamazing-team-member-carousel.php:62
actioninitamazing-team-member-carousel.php:83
filterwidget_textamazing-team-member-carousel.php:243
actionadmin_headamazing-team-member-carousel.php:248
filtermce_external_pluginsamazing-team-member-carousel.php:261
filtermce_buttonsamazing-team-member-carousel.php:262
actionafter_setup_themeframework\bootstrap.php:41
actiontgmpa_registerframework\bootstrap.php:47
actioninitframework\bootstrap.php:112
actioncurrent_screenframework\bootstrap.php:113
actionadmin_enqueue_scriptsframework\bootstrap.php:114
actioncurrent_screenframework\bootstrap.php:115
filterclean_urlframework\bootstrap.php:116
actionadmin_footerframework\bootstrap.php:161
filterwp_default_editorframework\bootstrap.php:195
actioninitframework\classes\metabox.php:43
actionvp_option_first_activationframework\classes\option.php:81
actionadmin_menuframework\classes\option.php:100
actionadmin_noticesframework\classes\option.php:162
actioncurrent_screenframework\classes\shortcodegenerator.php:47
actionadmin_footerframework\classes\shortcodegenerator.php:58
filtermce_external_pluginsframework\classes\shortcodegenerator.php:288
filtermce_buttonsframework\classes\shortcodegenerator.php:289
filterwp_fullscreen_buttonsframework\classes\shortcodegenerator.php:290
filteradmin_print_stylesframework\classes\shortcodegenerator.php:291
actionadmin_enqueue_scriptsframework\classes\wp\enqueuer.php:27
actionadmin_headframework\includes\wpalchemy\MetaBox.php:22
actionadmin_footerframework\includes\wpalchemy\MetaBox.php:24
actionadmin_initframework\includes\wpalchemy\MetaBox.php:506
actionimport_post_metaframework\includes\wpalchemy\MetaBox.php:509
filteroutputframework\includes\wpalchemy\MetaBox.php:569
actionsave_postframework\includes\wpalchemy\MetaBox.php:579
actionadmin_headframework\includes\wpalchemy\MetaBox.php:619
actionadmin_footerframework\includes\wpalchemy\MetaBox.php:621
Maintenance & Trust

Amazing Team Member Carousel Maintenance & Trust

Maintenance Signals

WordPress version tested4.0.38
Last updatedNov 22, 2014
PHP min version
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Amazing Team Member Carousel Developer Profile

noor-e-alam

3 plugins · 120 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Amazing Team Member Carousel

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/amazing-team-member-carousel/js/owl.carousel.js/wp-content/plugins/amazing-team-member-carousel/css/owl.carousel.css/wp-content/plugins/amazing-team-member-carousel/css/owl.theme.css/wp-content/plugins/amazing-team-member-carousel/css/atmc.css/wp-content/plugins/amazing-team-member-carousel/css/atmc2.css
Script Paths
http://netdna.bootstrapcdn.com/font-awesome/4.0.1/css/font-awesome.css
Version Parameters
amazing-team-member-carousel/js/owl.carousel.js?ver=amazing-team-member-carousel/css/owl.carousel.css?ver=amazing-team-member-carousel/css/owl.theme.css?ver=amazing-team-member-carousel/css/atmc.css?ver=amazing-team-member-carousel/css/atmc2.css?ver=

HTML / DOM Fingerprints

CSS Classes
team-horizontalteamteam-picteam-detaildetail-socialsocial-iconsdetail-namedetail-title+1 more
HTML Comments
Loading CSS and JSEnqueue Font Awesome Stylesheet from MaxCDNSetup ContantsLoad Languages+6 more
Data Attributes
id="owl-team_data-member_infodata-metatitledata-settings
JS Globals
jQueryamazing_team_member_carousel_owl_jsamazing_team_member_carousel_modal_jsamazing_team_member_owl_main_cssamazing_team_member_owl_theme_cssamazing_team_member_carousel_main_css+2 more
Shortcode Output
<div class="section-header"> <h2><div class="team-horizontal" id="owl-team_<div class="team"> <div class="team-pic"><img src="<div class="team-detail"> <div class="detail-social"> <ul class="social-icons nav-default inline clearfix">
FAQ

Frequently Asked Questions about Amazing Team Member Carousel