
JJ NextGen JQuery Carousel Security & Risk Analysis
wordpress.org/plugins/jj-nextgen-jquery-carouselAllows you to pick a gallery from the 'NextGen Gallery' plugin to use as a 'JQuery JCarousel'.
Is JJ NextGen JQuery Carousel Safe to Use in 2026?
Generally Safe
Score 85/100JJ NextGen JQuery Carousel has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "jj-nextgen-jquery-carousel" v1.1.8 plugin presents a mixed security picture. On the positive side, the attack surface is minimal, with only one shortcode and no unprotected AJAX handlers or REST API routes. The absence of known CVEs and historical vulnerabilities is also a strong indicator of good past maintenance and security practices. Furthermore, there are no external HTTP requests or file operations, and no taint analysis findings suggest no critical or high severity unsanitized paths were identified.
However, several concerning code signals significantly detract from its security posture. The presence of the `create_function` dangerous function, while not explicitly leveraged in a detected vulnerability, is a known security risk and should be avoided. More critically, all SQL queries are executed without prepared statements, which makes them highly susceptible to SQL injection vulnerabilities. The extremely low percentage of properly escaped output (4%) indicates a widespread lack of output sanitization, exposing users to potential cross-site scripting (XSS) attacks. The complete absence of nonce checks and capability checks on its single entry point means that any authenticated user, or potentially even unauthenticated users depending on context, could trigger the shortcode's functionality without proper authorization or verification.
Key Concerns
- Raw SQL queries without prepared statements
- Insufficient output escaping (4% proper)
- Dangerous function: create_function used
- Missing nonce checks
- Missing capability checks
JJ NextGen JQuery Carousel Security Vulnerabilities
JJ NextGen JQuery Carousel Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
JJ NextGen JQuery Carousel Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
JJ NextGen JQuery Carousel Maintenance & Trust
Maintenance Signals
Community Trust
JJ NextGen JQuery Carousel Alternatives
JJ NextGen JQuery Slider
jj-nextgen-jquery-slider
Allows you to pick a gallery from the 'NextGen Gallery' plugin to use as a 'JQuery Nivo slider'.
NextGEN Gallery Sidebar Widget
nextgen-gallery-sidebar-widget
A widget to show NextGEN galleries in your sidebar.
NextGen NivoSlider
nextgen-nivoslider
The NextGen Nivoslider plugin allows you to create a NivoSlider, using images from your NextGen gallery, with a simple shortcode or widget.
JJ NextGen JQuery Cycle
jj-nextgen-jquery-cycle
Allows you to pick a gallery from the 'NextGen Gallery' plugin to use with 'JQuery Cycle Lite'.
JJ NextGen Image List
jj-nextgen-image-list
Allows you to pick a gallery from the 'NextGen Gallery' plugin to list images from. You can list images vertically or horizontally.
JJ NextGen JQuery Carousel Developer Profile
5 plugins · 2K total installs
How We Detect JJ NextGen JQuery Carousel
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/jj-nextgen-jquery-carousel/script/jquery.jcarousel.min.js/wp-content/plugins/jj-nextgen-jquery-carousel/script/jquery.jj_ngg_shuffle.js/wp-content/plugins/jj-nextgen-jquery-carousel/skins/tango/skin.cssscript/jquery.jcarousel.min.jsscript/jquery.jj_ngg_shuffle.jsjj-nextgen-jquery-carousel/script/jquery.jcarousel.min.js?ver=jj-nextgen-jquery-carousel/script/jquery.jj_ngg_shuffle.js?ver=jj-nextgen-jquery-carousel/skins/tango/skin.css?ver=HTML / DOM Fingerprints
data-carousel-iddata-carousel-scrolldata-carousel-visibledata-carousel-wrapjj_carousel_options[jj-ngg-jquery-carousel]