
Logo Carousel Slider Security & Risk Analysis
wordpress.org/plugins/logo-carousel-sliderIt allows you to easily create logo carousel/slider to display logos of clients, partners, sponsors, affiliates etc.
Is Logo Carousel Slider Safe to Use in 2026?
Use With Caution
Score 64/100Logo Carousel Slider has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The plugin "logo-carousel-slider" v2.1.3 exhibits a mixed security posture. On the positive side, it demonstrates good practices by using prepared statements for all SQL queries, performing nonce checks, and capability checks, and avoiding external HTTP requests and file operations. The attack surface is also relatively small with only one shortcode identified as an entry point, and importantly, no unprotected entry points were found in the static analysis. However, concerns arise from the presence of a dangerous function (`create_function`) and a notable percentage of output not being properly escaped (57%). This suggests a potential for cross-site scripting vulnerabilities, especially considering the plugin's vulnerability history.
The plugin has a history of known vulnerabilities, with one medium severity Cross-site Scripting (XSS) vulnerability identified and currently unpatched. The fact that the last vulnerability was recorded in April 2025, and it's still unpatched, is a significant concern. This pattern indicates a potential for ongoing security weaknesses and a lack of timely security patching by the developers. While the static analysis did not reveal critical or high severity taint flows, the combination of potentially unsafe coding practices like `create_function` and unescaped output, coupled with an existing unpatched XSS vulnerability, elevates the overall risk.
In conclusion, while "logo-carousel-slider" v2.1.3 has some strong security foundations, the identified dangerous function, insufficient output escaping, and an unpatched medium severity XSS vulnerability significantly detract from its security. Users should exercise caution and prioritize applying any available patches or consider alternative plugins if immediate security is paramount.
Key Concerns
- Unpatched medium severity CVE
- Presence of dangerous function: create_function
- Insufficient output escaping (43% not properly escaped)
Logo Carousel Slider Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Logo Carousel Slider <= 2.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
Logo Carousel Slider Release Timeline
Logo Carousel Slider Code Analysis
Dangerous Functions Found
Output Escaping
Logo Carousel Slider Attack Surface
Shortcodes 1
WordPress Hooks 15
Maintenance & Trust
Logo Carousel Slider Maintenance & Trust
Maintenance Signals
Community Trust
Logo Carousel Slider Alternatives
Unlimited Logo Carousel
unlimited-logo-carousel
Unlimited Logo Carousel allows you to easily create logo carousel/slider to display logos of clients, partners, sponsors, affiliates etc.
Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation
gs-logo-slider
Logo Slider: The best responsive plugin for Logo Showcase, Logo Carousel, and displaying clients' logos. Includes shortcode generator with preview!
WP Logo Showcase Responsive Slider and Carousel
wp-logo-showcase-responsive-slider-slider
WP Logo Showcase Responsive Slider and Carousel allows you to display logos of clients, sponsors, brands, or partners in a professional and responsive …
Logo Carousel – Responsive Logo Slider, Logo Showcase, and Clients Logo Gallery
logo-carousel-free
Add, display, and manage clients, partners, sponsors, and brand logos with multiple slideshows on your site. Customizable – No coding required!
Logo Slider and Showcase
wp-logo-showcase
Logo Slider and Showcase plugin is fully Responsive and Mobile Friendly to display your partner logo in slider and grid views.
Logo Carousel Slider Developer Profile
15 plugins · 62K total installs
How We Detect Logo Carousel Slider
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/logo-carousel-slider/css/owl.carousel.css/wp-content/plugins/logo-carousel-slider/css/owl.theme.css/wp-content/plugins/logo-carousel-slider/css/owl.transitions.css/wp-content/plugins/logo-carousel-slider/css/lcs-styles.css/wp-content/plugins/logo-carousel-slider/js/owl.carousel.min.js/wp-content/plugins/logo-carousel-slider/css/lcs-admin-styles.css/wp-content/plugins/logo-carousel-slider/js/lcs-admin-script.js/wp-content/plugins/logo-carousel-slider/js/owl.carousel.min.js/wp-content/plugins/logo-carousel-slider/js/lcs-admin-script.jslogo-carousel-slider/css/owl.carousel.css?ver=logo-carousel-slider/css/owl.theme.css?ver=logo-carousel-slider/css/owl.transitions.css?ver=logo-carousel-slider/css/lcs-styles.css?ver=logo-carousel-slider/js/owl.carousel.min.js?ver=logo-carousel-slider/css/lcs-admin-styles.css?ver=logo-carousel-slider/js/lcs-admin-script.js?ver=HTML / DOM Fingerprints
lcs-carousel<!-- Logo Carousel Slider Shortcode -->data-settingslcs_settings[logo-carousel-slider