Image Carousel For Divi Security & Risk Analysis

wordpress.org/plugins/image-carousel-for-divi

A divi image carousel module to create a slide-show with images.

1K active installs v1.8.1 PHP 7.4+ WP 4.9.8+ Updated Apr 8, 2025
dividivi-moduleimage-carousel
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Image Carousel For Divi Safe to Use in 2026?

Generally Safe

Score 92/100

Image Carousel For Divi has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "image-carousel-for-divi" plugin, version 1.8.1, exhibits a generally strong security posture in several key areas based on the provided static analysis. The absence of any reported CVEs, unpatched vulnerabilities, or recorded common vulnerability types in its history is a positive indicator of past and present security diligence. Furthermore, the plugin demonstrates good practices with all SQL queries utilizing prepared statements, and no dangerous functions, file operations, or external HTTP requests were detected. The attack surface is reported as zero, meaning no entry points were identified for potential exploitation. However, a significant concern arises from the complete lack of output escaping (0% properly escaped). This indicates that any data rendered by the plugin to the user interface could potentially be vulnerable to Cross-Site Scripting (XSS) attacks, allowing attackers to inject malicious scripts. The absence of nonce and capability checks, while seemingly benign given the zero attack surface, becomes a potential weakness should any new entry points be introduced in future versions without proper security considerations. The bundled Freemius library, while present, is noted as v1.0, and without further information on its specific version and known vulnerabilities, its age could represent a latent risk. In conclusion, while the plugin benefits from a clean vulnerability history and secure handling of database operations and file system access, the critical lack of output escaping presents a substantial risk that requires immediate attention. The absence of explicit security checks like nonces and capability checks, coupled with the potentially outdated bundled library, also warrants consideration for future hardening.

Key Concerns

  • 0% output escaping
  • Bundled outdated library (Freemius v1.0)
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Image Carousel For Divi Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Image Carousel For Divi Release Timeline

v1.8.1Current
v1.8.0
v1.7.1
v1.7.0
v1.6.1
v1.6.0
v1.5.0
v1.4.0
v1.3.0
v1.2.0
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

Image Carousel For Divi Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
11
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

Output Escaping

0% escaped11 total outputs
Attack Surface

Image Carousel For Divi Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionet_builder_readysrc\Loader.php:55
actiondivi_extensions_initsrc\Loader.php:56
actionwp_enqueue_scriptssrc\Loader.php:58
actionadmin_menusrc\Loader.php:62
Maintenance & Trust

Image Carousel For Divi Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 8, 2025
PHP min version7.4
Downloads28K

Community Trust

Rating80/100
Number of ratings6
Active installs1K
Developer Profile

Image Carousel For Divi Developer Profile

wptools

16 plugins · 6K total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Image Carousel For Divi

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/image-carousel-for-divi/resources/slick/slick.min.js/wp-content/plugins/image-carousel-for-divi/resources/slick/slick.css/wp-content/plugins/image-carousel-for-divi/resources/slick/slick-theme.css/wp-content/plugins/image-carousel-for-divi/resources/js/script.js
Script Paths
/wp-content/plugins/image-carousel-for-divi/resources/slick/slick.min.js/wp-content/plugins/image-carousel-for-divi/resources/js/script.js
Version Parameters
/wp-content/plugins/image-carousel-for-divi/resources/slick/slick.min.js?ver=/wp-content/plugins/image-carousel-for-divi/resources/slick/slick.css?ver=/wp-content/plugins/image-carousel-for-divi/resources/slick/slick-theme.css?ver=/wp-content/plugins/image-carousel-for-divi/resources/js/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
et_pb_wptools_carousel_image_item
Data Attributes
data-admin_labeldata-slugdata-module_iddata-icon_colordata-icon_hover_colordata-background_layout+125 more
JS Globals
wptools_slick_init
Shortcode Output
[et_pb_wptools_carousel_image]
FAQ

Frequently Asked Questions about Image Carousel For Divi