
Carousel Block – Responsive Image and Content Carousel Security & Risk Analysis
wordpress.org/plugins/b-carousel-blockCreate stunning carousels effortlessly with the Carousel Block. Showcase your images in an elegant carousel directly within the Gutenberg editor.
Is Carousel Block – Responsive Image and Content Carousel Safe to Use in 2026?
Generally Safe
Score 99/100Carousel Block – Responsive Image and Content Carousel has a strong security track record. Known vulnerabilities have been patched promptly.
The b-carousel-block plugin v1.2.2 exhibits a generally strong security posture based on the static analysis provided. The absence of dangerous functions, properly escaped output, and the exclusive use of prepared statements for SQL queries are positive indicators. The presence of nonce checks is also a good practice. However, the complete lack of capability checks is a notable weakness, as it means any entry point, if discovered, would not be protected by WordPress's role-based access control system. The vulnerability history, while showing only one past CVE, is concerning due to the nature of the historical vulnerability being Server-Side Request Forgery (SSRF), which can have severe implications if re-introduced. The fact that the last vulnerability was dated 2025-11-04 suggests the plugin may not be actively maintained or that the data source is future-dated.
While the static analysis reveals no immediate exploitable attack surface or taint flows, the lack of capability checks on any potential future entry points is a significant risk. The past SSRF vulnerability, even if patched, highlights a potential area of weakness. The presence of Freemius, a third-party bundling library, could introduce risks if not kept up-to-date, though this is not explicitly stated as an issue in the provided data. Overall, the plugin demonstrates good coding hygiene in many areas, but the absence of granular permission checks and the historical context of SSRF warrant careful consideration and vigilance.
Key Concerns
- No capability checks on any entry points
- Vulnerability history indicates past SSRF
- Bundled library (Freemius) present
Carousel Block – Responsive Image and Content Carousel Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
B Carousel Block – Responsive Image and Content Carousel <= 1.1.5 - Missing Authorization to Authenticated (Subscriber+) Server-Side Request Forgery
Carousel Block – Responsive Image and Content Carousel Code Analysis
Bundled Libraries
Output Escaping
Carousel Block – Responsive Image and Content Carousel Attack Surface
WordPress Hooks 9
Maintenance & Trust
Carousel Block – Responsive Image and Content Carousel Maintenance & Trust
Maintenance Signals
Community Trust
Carousel Block – Responsive Image and Content Carousel Alternatives
Slider and Carousel Block – Responsive, Accessible
blablablocks-slider-block
Build responsive, accessible sliders or carousel in the Block Editor fast templates, no code needed.
Eazy Image Slider Block
eazy-image-slider-block
Eazy Image Slider Block adds an easy to use and configurable slider block.
Spectra Gutenberg Blocks – Website Builder for the Block Editor
ultimate-addons-for-gutenberg
Power-up Gutenberg with advanced blocks for faster website creation. Build your WordPress website effortlessly using powerful building blocks!
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor
kadence-blocks
20+ AI-powered Gutenberg Blocks with endless options, enabling top-notch efficiency for high-performance dynamic website creation.
Page Builder: Pagelayer – Drag and Drop website builder
pagelayer
The most advanced frontend drag & drop page builder. Pagelayer is a light weight but extremely powerful Website Builder.
Carousel Block – Responsive Image and Content Carousel Developer Profile
120 plugins · 738K total installs
How We Detect Carousel Block – Responsive Image and Content Carousel
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/b-carousel-block/build/admin/dashboard.css/wp-content/plugins/b-carousel-block/build/admin/dashboard.js/wp-content/plugins/b-carousel-block/build/admin/dashboard.jsb-carousel-block/build/admin/dashboard.css?ver=b-carousel-block/build/admin/dashboard.js?ver=HTML / DOM Fingerprints
data-infobicbpipecheckbicbpricingurl<div id='bicbDashboard'