Jeba Waterwheel Carousel Security & Risk Analysis

wordpress.org/plugins/jeba-waterwheel-carousel

Jeba Waterwheel Carousel is an awesome carousel, super lightweight plugin for your wordpress website post carousel.

10 active installs v1.0 PHP + WP 3.0.1+ Updated Jul 4, 2015
awesome-carouselcarouseljeba-carouselpost-carouseltiny-carousel
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Jeba Waterwheel Carousel Safe to Use in 2026?

Generally Safe

Score 85/100

Jeba Waterwheel Carousel has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The jeba-waterwheel-carousel plugin version 1.0 exhibits a generally strong security posture based on the provided static analysis. The code demonstrates excellent practices by avoiding dangerous functions, performing all SQL queries with prepared statements, and properly escaping all output. There are no observed file operations or external HTTP requests, further reducing the potential attack surface. The absence of any recorded vulnerabilities, including CVEs, also points to a history of secure development or a lack of focused security research targeting this plugin.

However, the analysis does highlight a significant area of concern: the complete lack of capability checks and nonce checks across all identified entry points, including the single shortcode. While the plugin doesn't have a large attack surface in terms of entry points (only one shortcode), the absence of these fundamental WordPress security mechanisms means that any user, regardless of their role or permissions, could potentially interact with and manipulate the functionality of the shortcode. This oversight could lead to unauthorized actions if the shortcode's internal logic were to perform sensitive operations, even if no direct SQL injection or cross-site scripting is immediately apparent from the static analysis alone.

In conclusion, the plugin benefits from robust data handling and output sanitization, which is a significant strength. The lack of known vulnerabilities is also a positive indicator. Nevertheless, the omission of crucial security checks like capability and nonce verification for its shortcode represents a notable weakness that could be exploited in conjunction with other potential vulnerabilities or in specific attack scenarios. Addressing this would significantly bolster the plugin's security.

Key Concerns

  • Missing capability checks on shortcode
  • Missing nonce checks on shortcode
Vulnerabilities
None known

Jeba Waterwheel Carousel Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Jeba Waterwheel Carousel Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

Jeba Waterwheel Carousel Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Jeba Waterwheel Carousel Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[carousel] jeba-index.php:96
WordPress Hooks 4
actioninitjeba-index.php:13
actioninitjeba-index.php:21
actionwp_footerjeba-index.php:66
actioninitjeba-index.php:98
Maintenance & Trust

Jeba Waterwheel Carousel Maintenance & Trust

Maintenance Signals

WordPress version tested4.0.38
Last updatedJul 4, 2015
PHP min version
Downloads2K

Community Trust

Rating20/100
Number of ratings1
Active installs10
Developer Profile

Jeba Waterwheel Carousel Developer Profile

Md Jahed

12 plugins · 210 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Jeba Waterwheel Carousel

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/jeba-waterwheel-carousel/js/style.css/wp-content/plugins/jeba-waterwheel-carousel/js/jquery.waterwheelCarousel.js
Script Paths
/wp-content/plugins/jeba-waterwheel-carousel/js/jquery.waterwheelCarousel.js

HTML / DOM Fingerprints

CSS Classes
waterwheel-carousel
Data Attributes
data-waterwheel-carousel
JS Globals
jQuery$
Shortcode Output
<h1><div id="carousel"><a href="#"><img src=id="item-
FAQ

Frequently Asked Questions about Jeba Waterwheel Carousel