Image Carousel Module for Divi Security & Risk Analysis

wordpress.org/plugins/image-carousel-divi

This plugin add an image carousel module to the Divi theme.

9K active installs v1.0.1 PHP 7.0+ WP 5.0+ Updated Jul 20, 2025
dividivi-carouseldivi-moduleimage-carousel
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Image Carousel Module for Divi Safe to Use in 2026?

Generally Safe

Score 100/100

Image Carousel Module for Divi has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10mo ago
Risk Assessment

The 'image-carousel-divi' v1.0.1 plugin exhibits a generally strong security posture based on the provided static analysis. The plugin has a very limited attack surface, with only one AJAX handler and no exposed REST API routes, shortcodes, or cron events. Crucially, the single AJAX entry point appears to be protected by nonce checks, indicating a good practice for preventing CSRF attacks. The code also demonstrates robust data handling by exclusively using prepared statements for SQL queries and having a high percentage of properly escaped output, minimizing risks of SQL injection and XSS respectively. The absence of file operations and external HTTP requests further reduces the potential for common plugin vulnerabilities.

There are no identified critical or high severity taint flows, and the plugin has no recorded vulnerability history, including known CVEs. This lack of past or present known vulnerabilities is a positive indicator. However, the analysis does reveal zero capability checks. While nonce checks are present for the AJAX handler, the absence of capability checks means that any authenticated user could potentially trigger the AJAX action, regardless of their specific role or permissions. This could be a concern if the AJAX action performs sensitive operations. Despite this one minor area for improvement, the plugin appears to be well-developed from a security perspective.

Key Concerns

  • Missing capability checks on AJAX handler
Vulnerabilities
None known

Image Carousel Module for Divi Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Image Carousel Module for Divi Release Timeline

v1.0.1Current
v1.0
v0.9.6
v0.9.5
v0.9.4
v0.9.3
v0.9.2
v0.9.1
v0.9
Code Analysis
Analyzed Mar 16, 2026

Image Carousel Module for Divi Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
19 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

95% escaped20 total outputs
Attack Surface

Image Carousel Module for Divi Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_lwp_get_carousel_imageslwp-image-carousel.php:73
WordPress Hooks 5
actionadmin_initincludes\class-lwp-image-carousel-rating.php:26
actionadmin_initincludes\class-lwp-image-carousel-rating.php:27
actionadmin_noticesincludes\class-lwp-image-carousel-rating.php:53
actiondivi_extensions_initlwp-image-carousel.php:38
filterplugin_row_metalwp-image-carousel.php:132
Maintenance & Trust

Image Carousel Module for Divi Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJul 20, 2025
PHP min version7.0
Downloads38K

Community Trust

Rating92/100
Number of ratings16
Active installs9K
Developer Profile

Image Carousel Module for Divi Developer Profile

learnhowwp

9 plugins · 31K total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Image Carousel Module for Divi

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/image-carousel-divi/fonts/slick.eot/wp-content/plugins/image-carousel-divi/fonts/slick.svg/wp-content/plugins/image-carousel-divi/fonts/slick.ttf/wp-content/plugins/image-carousel-divi/fonts/slick.woff

HTML / DOM Fingerprints

CSS Classes
lwp_image_carousel
Data Attributes
data-slides-showdata-slides-scroll
JS Globals
lwp_image_carousel_ajax_object
REST Endpoints
/wp-json/lwp-image-carousel/v1/get-images
Shortcode Output
<div class="lwp_image_carousel"><div class='lwp-image-carousel-wrapper'>
FAQ

Frequently Asked Questions about Image Carousel Module for Divi