Carousel Block – Responsive Image and Content Carousel Security & Risk Analysis

wordpress.org/plugins/b-carousel-block

Create stunning carousels effortlessly with the Carousel Block. Showcase your images in an elegant carousel directly within the Gutenberg editor.

6K active installs v1.2.2 PHP 7.1+ WP 6.5+ Updated Mar 4, 2026
blockclient-logo-slidergutenberg-blockimage-sliderlogo-carousel
99
A · Safe
CVEs total1
Unpatched0
Last CVENov 4, 2025
Download
Safety Verdict

Is Carousel Block – Responsive Image and Content Carousel Safe to Use in 2026?

Generally Safe

Score 99/100

Carousel Block – Responsive Image and Content Carousel has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Nov 4, 2025Updated 1mo ago
Risk Assessment

The b-carousel-block plugin v1.2.2 exhibits a generally strong security posture based on the static analysis provided. The absence of dangerous functions, properly escaped output, and the exclusive use of prepared statements for SQL queries are positive indicators. The presence of nonce checks is also a good practice. However, the complete lack of capability checks is a notable weakness, as it means any entry point, if discovered, would not be protected by WordPress's role-based access control system. The vulnerability history, while showing only one past CVE, is concerning due to the nature of the historical vulnerability being Server-Side Request Forgery (SSRF), which can have severe implications if re-introduced. The fact that the last vulnerability was dated 2025-11-04 suggests the plugin may not be actively maintained or that the data source is future-dated.

While the static analysis reveals no immediate exploitable attack surface or taint flows, the lack of capability checks on any potential future entry points is a significant risk. The past SSRF vulnerability, even if patched, highlights a potential area of weakness. The presence of Freemius, a third-party bundling library, could introduce risks if not kept up-to-date, though this is not explicitly stated as an issue in the provided data. Overall, the plugin demonstrates good coding hygiene in many areas, but the absence of granular permission checks and the historical context of SSRF warrant careful consideration and vigilance.

Key Concerns

  • No capability checks on any entry points
  • Vulnerability history indicates past SSRF
  • Bundled library (Freemius) present
Vulnerabilities
1

Carousel Block – Responsive Image and Content Carousel Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-12388medium · 6.4Server-Side Request Forgery (SSRF)

B Carousel Block – Responsive Image and Content Carousel <= 1.1.5 - Missing Authorization to Authenticated (Subscriber+) Server-Side Request Forgery

Nov 4, 2025 Patched in 1.1.6 (1d)
Code Analysis
Analyzed Mar 16, 2026

Carousel Block – Responsive Image and Content Carousel Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
5 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius

Output Escaping

100% escaped5 total outputs
Attack Surface

Carousel Block – Responsive Image and Content Carousel Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionadmin_menuincludes\admin\SubMenu.php:8
actioninitincludes\Patterns.php:8
filterplugin_row_metaindex.php:42
actioninitindex.php:43
actionadmin_enqueue_scriptsindex.php:44
actionenqueue_block_editor_assetsindex.php:45
filterplugin_action_linksindex.php:47
filterdefault_titleindex.php:48
filterdefault_contentindex.php:49
Maintenance & Trust

Carousel Block – Responsive Image and Content Carousel Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 4, 2026
PHP min version7.1
Downloads90K

Community Trust

Rating100/100
Number of ratings6
Active installs6K
Developer Profile

Carousel Block – Responsive Image and Content Carousel Developer Profile

colorlibplugins

120 plugins · 738K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
140 days
View full developer profile
Detection Fingerprints

How We Detect Carousel Block – Responsive Image and Content Carousel

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/b-carousel-block/build/admin/dashboard.css/wp-content/plugins/b-carousel-block/build/admin/dashboard.js
Script Paths
/wp-content/plugins/b-carousel-block/build/admin/dashboard.js
Version Parameters
b-carousel-block/build/admin/dashboard.css?ver=b-carousel-block/build/admin/dashboard.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-info
JS Globals
bicbpipecheckbicbpricingurl
Shortcode Output
<div id='bicbDashboard'
FAQ

Frequently Asked Questions about Carousel Block – Responsive Image and Content Carousel