Logo Carousel Slider Security & Risk Analysis

wordpress.org/plugins/logo-carousel-slider

It allows you to easily create logo carousel/slider to display logos of clients, partners, sponsors, affiliates etc.

7K active installs v2.1.3 PHP + WP 4.4+ Updated Oct 19, 2021
logologo-carousellogo-carousel-sliderlogo-showcaselogo-slider
64
C · Use Caution
CVEs total1
Unpatched1
Last CVEApr 16, 2025
Safety Verdict

Is Logo Carousel Slider Safe to Use in 2026?

Use With Caution

Score 64/100

Logo Carousel Slider has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Apr 16, 2025Updated 4yr ago
Risk Assessment

The plugin "logo-carousel-slider" v2.1.3 exhibits a mixed security posture. On the positive side, it demonstrates good practices by using prepared statements for all SQL queries, performing nonce checks, and capability checks, and avoiding external HTTP requests and file operations. The attack surface is also relatively small with only one shortcode identified as an entry point, and importantly, no unprotected entry points were found in the static analysis. However, concerns arise from the presence of a dangerous function (`create_function`) and a notable percentage of output not being properly escaped (57%). This suggests a potential for cross-site scripting vulnerabilities, especially considering the plugin's vulnerability history.

The plugin has a history of known vulnerabilities, with one medium severity Cross-site Scripting (XSS) vulnerability identified and currently unpatched. The fact that the last vulnerability was recorded in April 2025, and it's still unpatched, is a significant concern. This pattern indicates a potential for ongoing security weaknesses and a lack of timely security patching by the developers. While the static analysis did not reveal critical or high severity taint flows, the combination of potentially unsafe coding practices like `create_function` and unescaped output, coupled with an existing unpatched XSS vulnerability, elevates the overall risk.

In conclusion, while "logo-carousel-slider" v2.1.3 has some strong security foundations, the identified dangerous function, insufficient output escaping, and an unpatched medium severity XSS vulnerability significantly detract from its security. Users should exercise caution and prioritize applying any available patches or consider alternative plugins if immediate security is paramount.

Key Concerns

  • Unpatched medium severity CVE
  • Presence of dangerous function: create_function
  • Insufficient output escaping (43% not properly escaped)
Vulnerabilities
1 published

Logo Carousel Slider Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-39525medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Logo Carousel Slider <= 2.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

Apr 16, 2025Unpatched
Version History

Logo Carousel Slider Release Timeline

v2.11 CVE
v2.01 CVE
v1.51 CVE
v1.41 CVE
v1.31 CVE
v1.21 CVE
v1.11 CVE
v1.01 CVE
Code Analysis
Analyzed Mar 16, 2026

Logo Carousel Slider Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
20
26 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

create_function$callback = create_function('', 'echo "'.str_replace('"', '\"', $section['desc']).'";');includes\class.settings-api.php:116

Output Escaping

57% escaped46 total outputs
Attack Surface

Logo Carousel Slider Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[logo_carousel_slider] includes\lcs-shortcodes.php:12
WordPress Hooks 15
actionadmin_enqueue_scriptsincludes\class.settings-api.php:35
filterimage_resize_dimensionsincludes\lcs-img-resizer.php:64
actionadd_meta_boxesincludes\lcs-metabox-overrider.php:32
filteradmin_post_thumbnail_htmlincludes\lcs-metabox-overrider.php:33
filtermedia_view_stringsincludes\lcs-metabox-overrider.php:34
actionadmin_initincludes\lcs-settings.php:26
actionadmin_menuincludes\lcs-settings.php:27
actioninitincludes\lcs-utility.php:16
actiondo_meta_boxesincludes\lcs-utility.php:18
actionadd_meta_boxesincludes\lcs-utility.php:20
actionsave_postincludes\lcs-utility.php:22
actiontemplate_redirectlcs-main.php:56
actionadmin_enqueue_scriptslcs-main.php:57
actionadmin_menulcs-main.php:62
filterwidget_textlcs-main.php:70
Maintenance & Trust

Logo Carousel Slider Maintenance & Trust

Maintenance Signals

WordPress version tested5.6.17
Last updatedOct 19, 2021
PHP min version
Downloads157K

Community Trust

Rating58/100
Number of ratings25
Active installs7K
Developer Profile

Logo Carousel Slider Developer Profile

wpWax

15 plugins · 62K total installs

69
trust score
Avg Security Score
86/100
Avg Patch Time
202 days
View full developer profile
Detection Fingerprints

How We Detect Logo Carousel Slider

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/logo-carousel-slider/css/owl.carousel.css/wp-content/plugins/logo-carousel-slider/css/owl.theme.css/wp-content/plugins/logo-carousel-slider/css/owl.transitions.css/wp-content/plugins/logo-carousel-slider/css/lcs-styles.css/wp-content/plugins/logo-carousel-slider/js/owl.carousel.min.js/wp-content/plugins/logo-carousel-slider/css/lcs-admin-styles.css/wp-content/plugins/logo-carousel-slider/js/lcs-admin-script.js
Script Paths
/wp-content/plugins/logo-carousel-slider/js/owl.carousel.min.js/wp-content/plugins/logo-carousel-slider/js/lcs-admin-script.js
Version Parameters
logo-carousel-slider/css/owl.carousel.css?ver=logo-carousel-slider/css/owl.theme.css?ver=logo-carousel-slider/css/owl.transitions.css?ver=logo-carousel-slider/css/lcs-styles.css?ver=logo-carousel-slider/js/owl.carousel.min.js?ver=logo-carousel-slider/css/lcs-admin-styles.css?ver=logo-carousel-slider/js/lcs-admin-script.js?ver=

HTML / DOM Fingerprints

CSS Classes
lcs-carousel
HTML Comments
<!-- Logo Carousel Slider Shortcode -->
Data Attributes
data-settings
JS Globals
lcs_settings
Shortcode Output
[logo-carousel-slider
FAQ

Frequently Asked Questions about Logo Carousel Slider