
Custom Post Carousels with Owl Security & Risk Analysis
wordpress.org/plugins/dd-post-carouselEasily add post carousels to your website. Works with any custom post type or regular posts. Controls allow for insertion of multiple carousels on a s …
Is Custom Post Carousels with Owl Safe to Use in 2026?
Generally Safe
Score 98/100Custom Post Carousels with Owl has a strong security track record. Known vulnerabilities have been patched promptly.
The "dd-post-carousel" plugin v1.4.12 exhibits a mixed security posture. On the positive side, the static analysis shows a relatively small attack surface with no unprotected entry points. All SQL queries are prepared, and there are no dangerous functions or file operations detected. The presence of nonce checks on all AJAX handlers is also a good security practice. However, a significant concern is the low percentage of properly escaped output (56%), which leaves a considerable portion of the plugin's output potentially vulnerable to Cross-Site Scripting (XSS) attacks. The vulnerability history indicates a pattern of medium severity XSS vulnerabilities, with the last one reported in 2025. While there are no currently unpatched vulnerabilities, this history suggests a recurring weakness in input sanitization or output escaping that needs to be addressed proactively. The bundled Select2 library, while not explicitly flagged as outdated, could represent a potential risk if it's not kept up-to-date with its own security patches.
In conclusion, while the plugin demonstrates some robust security practices like prepared SQL statements and nonce checks, the prevalent issue of unescaped output and past XSS vulnerabilities represent the most significant risks. The developer should prioritize thoroughly reviewing and escaping all output to mitigate XSS threats. The plugin also includes a bundled library, which adds a layer of dependency that requires ongoing vigilance. Overall, the plugin has strengths in its controlled entry points and SQL handling but weaknesses in output sanitization that warrant attention.
Key Concerns
- Output escaping (56% properly escaped)
- Vulnerability history (2 medium XSS)
- Bundled library (Select2)
Custom Post Carousels with Owl Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Custom Post Carousels with Owl <= 1.4.11 - Authenticated (Contributor+) Stored Cross-Site Scripting
Custom Post Carousels with Owl <= 1.4.6 - Authenticated (Editor+) Stored Cross-Site Scripting
Custom Post Carousels with Owl Code Analysis
Bundled Libraries
Output Escaping
Custom Post Carousels with Owl Attack Surface
AJAX Handlers 3
Shortcodes 1
WordPress Hooks 17
Maintenance & Trust
Custom Post Carousels with Owl Maintenance & Trust
Maintenance Signals
Community Trust
Custom Post Carousels with Owl Alternatives
Blog Designer Pack – Blog, Post Grid, Post Slider, Post Carousel, Category Post, News
blog-designer-pack
News & Blog plugin for post grid, post slider, post carousel, post filter, masonry, ticker & list category posts using shortcode, Elementor & Divi.
AnWP Post Grid and Post Carousel Slider for Elementor
anwp-post-grid-for-elementor
Easily create awesome post grids and post carousel sliders. Different widget types, powerful filters, "load more" button and many customizab …
Post Slider and Post Carousel with Post Vertical Scrolling Widget – A Responsive Post Slider
post-slider-and-carousel
Post Slider and Post Carousel display WordPress post in slider and carousel layouts with shortcode and Latest/Recent vertical post scrolling widget.
Carousel, Recent Post Slider and Banner Slider
spice-post-slider
Display your blog posts with a responsive, customizable slider that works smoothly on all devices.
Post Carousel Slider for Elementor
post-carousel-slider-for-elementor
Post Carousel Slider for Elementor, Elementor Post Slider, Elementor Post Carousel help to add post carousel with Elementor
Custom Post Carousels with Owl Developer Profile
6 plugins · 4K total installs
How We Detect Custom Post Carousels with Owl
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/dd-post-carousel/css/owl-carousel-2-admin.min.css/wp-content/plugins/dd-post-carousel/css/select2.min.css/wp-content/plugins/dd-post-carousel/js/select2.min.js/wp-content/plugins/dd-post-carousel/js/owl-carousel-2-admin.min.js/wp-content/plugins/dd-post-carousel/js/owl-carousel-2.min.js/wp-content/plugins/dd-post-carousel/css/owl-carousel-2.min.cssjs/owl-carousel-2-admin.min.jsjs/select2.min.jsjs/owl-carousel-2.min.jsdd-post-carousel/css/owl-carousel-2-admin.min.css?ver=dd-post-carousel/css/select2.min.css?ver=select2.js?ver=dd-owl-admin?ver=owl-carousel-2/js/owl-carousel-2.min.js?ver=owl-carousel-2/css/owl-carousel-2.min.css?ver=HTML / DOM Fingerprints
dd-owl-carousel-2data-owl-carousel-iddata-owl-carousel-settingsdd_owl_admin_script[owl-carousel-2