Awesome Carousel Slider Security & Risk Analysis

wordpress.org/plugins/awesome-carousel-slider

Here is a short description of the plugin. This should be no more than 150 characters. No markup here.

10 active installs v1.0.0 PHP 5.2.4+ WP 4.6+ Updated Oct 4, 2019
galleyimage-sliderslidervideo-silderwoocommerce-product-carousel-logo
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Awesome Carousel Slider Safe to Use in 2026?

Generally Safe

Score 85/100

Awesome Carousel Slider has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

This plugin exhibits a generally good security posture with several strengths, including the absence of known vulnerabilities and the consistent use of prepared statements for all SQL queries. The high percentage of properly escaped output (71%) is also a positive indicator of secure coding practices. However, a significant concern arises from the presence of one unprotected AJAX handler, which represents a direct entry point for potential attacks without proper authentication or authorization checks. Additionally, the two flows with unsanitized paths, although not classified as critical or high severity in the taint analysis, warrant attention as they could potentially lead to path traversal or arbitrary file access vulnerabilities under certain conditions. The plugin also uses a bundled library, Select2, which, while not explicitly flagged, could pose a risk if it's an outdated or vulnerable version, though no specific information on this is provided.

While the vulnerability history is clean, indicating a good track record, the static analysis reveals an immediate area of risk. The unprotected AJAX handler is the most pressing issue. The two unsanitized path flows are also a cause for concern, even if their severity is not explicitly high. The plugin has a moderate attack surface with seven entry points, one of which is not adequately protected. In conclusion, "awesome-carousel-slider" v1.0.0 has strong foundations in secure coding for SQL and output handling, but the unprotected AJAX handler and unsanitized path flows are critical weaknesses that need immediate remediation to ensure the plugin's overall security.

Key Concerns

  • Unprotected AJAX handler
  • Flows with unsanitized paths
  • Bundled libraries (potential risk)
Vulnerabilities
None known

Awesome Carousel Slider Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Awesome Carousel Slider Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Awesome Carousel Slider Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
212
525 escaped
Nonce Checks
2
Capability Checks
6
File Operations
0
External Requests
1
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

71% escaped737 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

4 flows2 with unsanitized paths
add_slide_template (includes/class-carousel-slider-hero-carousel.php:30)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Awesome Carousel Slider Attack Surface

Entry Points7
Unprotected1

AJAX Handlers 4

authwp_ajax_carousel_slider_save_imagesincludes/class-carousel-slider-admin.php:38
authwp_ajax_add_content_slideincludes/class-carousel-slider-hero-carousel.php:27
authwp_ajax_carousel_slider_quick_viewincludes/class-carousel-slider-product.php:47
noprivwp_ajax_carousel_slider_quick_viewincludes/class-carousel-slider-product.php:48

Shortcodes 3

[carousel] shortcodes/class-carousel-slider-deprecated-shortcode.php:31
[item] shortcodes/class-carousel-slider-deprecated-shortcode.php:32
[carousel_slide] shortcodes/class-carousel-slider-shortcode.php:29
WordPress Hooks 28
actionadmin_noticescarousel-slider.php:68
actioncarousel_slider_activationincludes/class-carousel-slider-activator.php:34
actioninitincludes/class-carousel-slider-admin.php:33
actionadd_meta_boxesincludes/class-carousel-slider-admin.php:34
filtermanage_edit-carousels_columnsincludes/class-carousel-slider-admin.php:35
filtermanage_carousels_posts_custom_columnincludes/class-carousel-slider-admin.php:36
actionsave_postincludes/class-carousel-slider-admin.php:37
filterpost_row_actionsincludes/class-carousel-slider-admin.php:41
filterattachment_fields_to_editincludes/class-carousel-slider-admin.php:44
filterattachment_fields_to_saveincludes/class-carousel-slider-admin.php:45
filteradmin_footer_textincludes/class-carousel-slider-credit.php:27
actionadmin_menuincludes/class-carousel-slider-documentation.php:27
actioninitincludes/class-carousel-slider-i18n.php:36
actionadd_meta_boxesincludes/class-carousel-slider-meta-box.php:29
actioncarousel_slider_after_shop_loop_itemincludes/class-carousel-slider-product.php:38
actioncarousel_slider_after_shop_loop_itemincludes/class-carousel-slider-product.php:42
filterposts_clausesincludes/class-carousel-slider-product.php:431
actionwp_loadedincludes/class-carousel-slider-script.php:27
actionwp_loadedincludes/class-carousel-slider-script.php:28
actionwp_enqueue_scriptsincludes/class-carousel-slider-script.php:30
actionadmin_enqueue_scriptsincludes/class-carousel-slider-script.php:32
actionadmin_footerincludes/class-carousel-slider-script.php:33
actioncarousel_slider_image_gallery_loopincludes/class-carousel-slider-structured-data.php:40
actioncarousel_slider_post_loopincludes/class-carousel-slider-structured-data.php:41
actioncarousel_slider_product_loopincludes/class-carousel-slider-structured-data.php:42
actionwp_footerincludes/class-carousel-slider-structured-data.php:44
actioninitincludes/class-carousel-slider-vc-element.php:31
actionwidgets_initwidgets/widget-carousel_slider.php:131
Maintenance & Trust

Awesome Carousel Slider Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.33
Last updatedOct 4, 2019
PHP min version5.2.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Awesome Carousel Slider Developer Profile

Raihanul Islam

17 plugins · 450 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Awesome Carousel Slider

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/awesome-carousel-slider/assets/css/owl.carousel.min.css/wp-content/plugins/awesome-carousel-slider/assets/css/slick.css/wp-content/plugins/awesome-carousel-slider/assets/css/style.css/wp-content/plugins/awesome-carousel-slider/assets/js/custom.js/wp-content/plugins/awesome-carousel-slider/assets/js/owl.carousel.min.js/wp-content/plugins/awesome-carousel-slider/assets/js/slick.min.js/wp-content/plugins/awesome-carousel-slider/assets/js/wow.min.js
Script Paths
/wp-content/plugins/awesome-carousel-slider/assets/js/custom.js/wp-content/plugins/awesome-carousel-slider/assets/js/owl.carousel.min.js/wp-content/plugins/awesome-carousel-slider/assets/js/slick.min.js/wp-content/plugins/awesome-carousel-slider/assets/js/wow.min.js
Version Parameters
/wp-content/plugins/awesome-carousel-slider/assets/css/owl.carousel.min.css?ver=/wp-content/plugins/awesome-carousel-slider/assets/css/slick.css?ver=/wp-content/plugins/awesome-carousel-slider/assets/css/style.css?ver=/wp-content/plugins/awesome-carousel-slider/assets/js/custom.js?ver=/wp-content/plugins/awesome-carousel-slider/assets/js/owl.carousel.min.js?ver=/wp-content/plugins/awesome-carousel-slider/assets/js/slick.min.js?ver=/wp-content/plugins/awesome-carousel-slider/assets/js/wow.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
carousel-slider-wrapcarousel-slider-content
HTML Comments
<!-- CAROUSEL SLIDER SHORTCODE -->
Data Attributes
data-wow-durationdata-wow-delay
JS Globals
carousel_slider_configs
Shortcode Output
[carousel_slider
FAQ

Frequently Asked Questions about Awesome Carousel Slider