Logo Showcase with Logo Carousel, Logo Slider & Logo Grid Security & Risk Analysis

wordpress.org/plugins/hm-logo-showcase

Easiest logo slider plugin to create, display and manage your clients, partners, supporters, and sponsors logos on your WordPress site.

200 active installs v2.0.9 PHP 7.2+ WP 5.4+ Updated Jan 17, 2026
client-logo-carouselclient-logo-sliderimage-carousellogo-carousellogo-slider
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Logo Showcase with Logo Carousel, Logo Slider & Logo Grid Safe to Use in 2026?

Generally Safe

Score 100/100

Logo Showcase with Logo Carousel, Logo Slider & Logo Grid has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "hm-logo-showcase" plugin v2.0.9 exhibits a generally good security posture, with several positive indicators. The absence of known CVEs and a clean vulnerability history suggests a well-maintained and secure codebase over time. The plugin also demonstrates good practices by utilizing prepared statements for all SQL queries and including capability checks for its entry points.

However, the static analysis reveals a few areas of concern. The presence of the `unserialize` function, a common source of deserialization vulnerabilities, warrants careful attention, especially since no taint flows were found during analysis. While the current taint analysis didn't uncover issues, the potential for `unserialize` to be exploited remains. Additionally, a significant percentage of output (39%) is not properly escaped, presenting a risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is outputted directly without sanitization.

Overall, the plugin is relatively secure due to its lack of historical vulnerabilities and good SQL practices. However, the presence of `unserialize` and the notable amount of unescaped output represent potential attack vectors that could be exploited under specific circumstances. Vigilance and potential code review around these specific functions are recommended.

Key Concerns

  • Dangerous function 'unserialize' present
  • Significant portion of output unescaped
Vulnerabilities
None known

Logo Showcase with Logo Carousel, Logo Slider & Logo Grid Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Logo Showcase with Logo Carousel, Logo Slider & Logo Grid Code Analysis

Dangerous Functions
4
Raw SQL Queries
0
2 prepared
Unescaped Output
33
52 escaped
Nonce Checks
2
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
1

Dangerous Functions Found

unserialize$this->settings = stripslashes_deep( unserialize( get_option('hmls_grid_content_settings') ) );core\grid-content.php:27
unserialize$this->settings = stripslashes_deep( unserialize( get_option('hmls_grid_style_settings') ) );core\grid-styles.php:27
unserialize$this->settings = stripslashes_deep( unserialize( get_option('hmls_slide_content_settings') ) );core\slide-content.php:26
unserialize$this->settings = stripslashes_deep( unserialize( get_option('hmls_slide_styles_settings') ) );core\slide-styles.php:26

Bundled Libraries

Freemius1.0

SQL Query Safety

100% prepared2 total queries

Output Escaping

61% escaped85 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<grid> (admin\view\grid.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Logo Showcase with Logo Carousel, Logo Slider & Logo Grid Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[hm_logo_showcase] front\cls-hmls-front.php:101
WordPress Hooks 14
filterplugin_row_metahm-logo-showcase.php:57
filtermanage_hmls_logo_posts_columnshm-logo-showcase.php:76
actionmanage_hmls_logo_posts_custom_columnhm-logo-showcase.php:106
filtermanage_edit-hmls_logo_sortable_columnshm-logo-showcase.php:116
actionplugins_loadedinc\cls-hmls-master.php:26
actionadmin_enqueue_scriptsinc\cls-hmls-master.php:45
actioninitinc\cls-hmls-master.php:46
actioninitinc\cls-hmls-master.php:47
actionadd_meta_boxesinc\cls-hmls-master.php:48
actionsave_postinc\cls-hmls-master.php:49
actionadmin_menuinc\cls-hmls-master.php:50
actionadmin_initinc\cls-hmls-master.php:51
filteradmin_post_thumbnail_htmlinc\cls-hmls-master.php:53
actionwp_enqueue_scriptsinc\cls-hmls-master.php:58
Maintenance & Trust

Logo Showcase with Logo Carousel, Logo Slider & Logo Grid Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 17, 2026
PHP min version7.2
Downloads8K

Community Trust

Rating100/100
Number of ratings6
Active installs200
Developer Profile

Logo Showcase with Logo Carousel, Logo Slider & Logo Grid Developer Profile

Hossni Mubarak

13 plugins · 8K total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
146 days
View full developer profile
Detection Fingerprints

How We Detect Logo Showcase with Logo Carousel, Logo Slider & Logo Grid

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/hm-logo-showcase/assets/css/cls-hmls-admin.css/wp-content/plugins/hm-logo-showcase/assets/css/fontawesome/css/all.min.css/wp-content/plugins/hm-logo-showcase/assets/js/cls-hmls-admin.js
Script Paths
/wp-content/plugins/hm-logo-showcase/assets/js/cls-hmls-admin.js
Version Parameters
hm-logo-showcase/assets/css/cls-hmls-admin.css?ver=hm-logo-showcase/assets/css/fontawesome/css/all.min.css?ver=hm-logo-showcase/assets/js/cls-hmls-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
hmls-admin-logo-listcls-hmls-
Data Attributes
data-hmls_sliderdata-hmls_grid
JS Globals
hmls_plugin_array
REST Endpoints
/wp-json/hmls/v1/get_logos
Shortcode Output
[hmls_slider[hmls_grid
FAQ

Frequently Asked Questions about Logo Showcase with Logo Carousel, Logo Slider & Logo Grid