Great Caroussel Security & Risk Analysis

wordpress.org/plugins/great-caroussel

Create beautiful carrousel, with any contents (image, text, video...)

500 active installs v1.08 PHP 5.6+ WP 3.5+ Updated Dec 6, 2025
carouselcarousselcarrouselcarrousselrotate
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Great Caroussel Safe to Use in 2026?

Generally Safe

Score 100/100

Great Caroussel has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The "great-caroussel" plugin v1.08 demonstrates a generally strong security posture based on the provided static analysis. The absence of critical or high-severity issues in taint analysis, coupled with a high percentage of prepared statements for SQL queries and properly escaped output, indicates good development practices. Furthermore, the plugin's vulnerability history is clean, with no recorded CVEs, suggesting a track record of security consciousness.

However, there are areas that warrant attention. The static analysis reveals a total of 6 entry points, none of which are unprotected. While this is positive, the absence of capability checks on all entry points is a concern. This means that while nonces might be present on AJAX handlers, the underlying user permissions to execute these actions are not explicitly verified, potentially allowing privileged actions by unauthorized users if other security layers are bypassed or misconfigured. The presence of 7 nonce checks is positive, but their universal application across all AJAX handlers is not explicitly stated and the lack of capability checks is a more significant oversight.

In conclusion, the plugin is well-developed with good core security practices in place. The main weakness lies in the apparent lack of explicit capability checks on its AJAX handlers, which could present a security risk if not handled by other plugin or WordPress-level security measures. The clean vulnerability history is a significant strength, but this single deduction regarding capability checks should be addressed to further harden the plugin.

Key Concerns

  • Missing capability checks on entry points
Vulnerabilities
None known

Great Caroussel Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Great Caroussel Code Analysis

Dangerous Functions
0
Raw SQL Queries
3
34 prepared
Unescaped Output
1
21 escaped
Nonce Checks
7
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

92% prepared37 total queries

Output Escaping

95% escaped22 total outputs
Data Flows
All sanitized

Data Flow Analysis

7 flows
great_caroussels (great-caroussel.php:233)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Great Caroussel Attack Surface

Entry Points6
Unprotected0

AJAX Handlers 5

authwp_ajax_remove_gcgreat-caroussel.php:337
authwp_ajax_gc_add_contentgreat-caroussel.php:421
authwp_ajax_gc_save_contentgreat-caroussel.php:495
authwp_ajax_gc_remove_contentgreat-caroussel.php:553
authwp_ajax_gc_order_contentgreat-caroussel.php:685

Shortcodes 1

[great-caroussel] great-caroussel.php:821
WordPress Hooks 2
actionadmin_menugreat-caroussel.php:197
actionadmin_print_stylesgreat-caroussel.php:217
Maintenance & Trust

Great Caroussel Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 6, 2025
PHP min version5.6
Downloads15K

Community Trust

Rating0/100
Number of ratings0
Active installs500
Developer Profile

Great Caroussel Developer Profile

manu225

17 plugins · 27K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
29 days
View full developer profile
Detection Fingerprints

How We Detect Great Caroussel

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/great-caroussel/css/admin.css

HTML / DOM Fingerprints

CSS Classes
great_carousselgc_add_contentgc_remove_contentgc_save_contentgc_remove_gc
Data Attributes
data-iddata-caroussel-iddata-content-id
JS Globals
great_caroussel_tablegreat_caroussel_contents_table
FAQ

Frequently Asked Questions about Great Caroussel