
Carousel Ultimate Security & Risk Analysis
wordpress.org/plugins/carouselCarousel Ultimate WordPress Plugin allows you to easily create Responsive carousel/slider/post slider/logo showcase/ team etc.
Is Carousel Ultimate Safe to Use in 2026?
High Risk
Score 42/100Carousel Ultimate carries significant security risk with 2 known CVEs, 2 still unpatched. Consider switching to a maintained alternative.
The plugin "carousel" v1.8 exhibits a mixed security posture. On the positive side, the static analysis reveals no direct attack surface in the form of AJAX handlers, REST API routes, shortcodes, or cron events that are exposed without authentication. Furthermore, the code demonstrates excellent adherence to secure coding practices by utilizing prepared statements for all SQL queries, properly escaping all outputs, and avoiding dangerous functions and file operations. There are also no external HTTP requests or bundled libraries to consider. However, a significant concern arises from the vulnerability history, which indicates two known medium-severity Cross-Site Scripting (XSS) vulnerabilities, both of which are currently unpatched. The fact that the last vulnerability was discovered relatively recently (2025-09-22) and remains unaddressed is a critical red flag. This suggests a lack of ongoing security maintenance and responsiveness from the developer, despite the code's otherwise good static analysis results.
Key Concerns
- Unpatched Medium CVE
- Unpatched Medium CVE
Carousel Ultimate Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Carousel Ultimate <= 1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
Carousel Ultimate <= 1.8 - Authenticated (Editor+) Stored Cross-Site Scripting
Carousel Ultimate Code Analysis
Output Escaping
Carousel Ultimate Attack Surface
WordPress Hooks 6
Maintenance & Trust
Carousel Ultimate Maintenance & Trust
Maintenance Signals
Community Trust
Carousel Ultimate Alternatives
Divi Carousel Free (Divi5 Support)
wow-carousel-for-divi-lite
Create beautiful, responsive image and logo carousels for the Divi Builder — no code required.
WP Logo Showcase Responsive Slider and Carousel
wp-logo-showcase-responsive-slider-slider
WP Logo Showcase Responsive Slider and Carousel allows you to display logos of clients, sponsors, brands, or partners in a professional and responsive …
Divi Carousel Lite – 17+ Carousel Module
carousels-slider-for-divi
Divi Carousel Lite, the ultimate Divi Builder plugin with 17+ modules like image carousel, testimonial carousel, logo carousel, team carousel, and mor …
WEN Logo Slider
wen-logo-slider
Simple responsive logo slider for your WordPress site
Logo Showcase with Logo Carousel, Logo Slider & Logo Grid
hm-logo-showcase
Easiest logo slider plugin to create, display and manage your clients, partners, supporters, and sponsors logos on your WordPress site.
Carousel Ultimate Developer Profile
19 plugins · 10K total installs
How We Detect Carousel Ultimate
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/carousel/assets/css/font-awesome.min.css/wp-content/plugins/carousel/assets/css/owl.carousel.min.css/wp-content/plugins/carousel/assets/css/owl.theme.default.css/wp-content/plugins/carousel/assets/css/animate.css/wp-content/plugins/carousel/assets/css/style.css/wp-content/plugins/carousel/assets/js/app_script.js/wp-content/plugins/carousel/assets/js/owl.carousel.js/wp-content/plugins/carousel/assets/js/jquery.mousewheel.min.js+4 more/wp-content/plugins/carousel/assets/js/app_script.js/wp-content/plugins/carousel/assets/js/owl.carousel.js/wp-content/plugins/carousel/assets/js/jquery.mousewheel.min.js/wp-content/plugins/carousel/assets/js/jscolor.js/wp-content/plugins/carousel/admin/js/tp-carousel-pro-admin.js/wp-content/plugins/carousel/assets/js/wp-color-picker-alpha.jsver=1.0.0HTML / DOM Fingerprints
content_area-tpcarouselpro-carpro_slider_itemscarpro_slider_itemsdesktopcarpro_slider_itemsdesktopsmallcarpro_slider_itemsmobilecarpro_slider_loopcarpro_slider_margin+28 morecarpros_pro_ajaxcarpros_pro_ajaxurl