Logo Showcase – Logo Slider, Carousel & Sponsors Gallery Security & Risk Analysis

wordpress.org/plugins/logo-showcase

Create beautiful logo showcases for clients, sponsors, partners, or brands using slider, grid, list, or ticker layouts — no coding required.

900 active installs v4.0.1 PHP + WP 4.0+ Updated Feb 9, 2026
clientslogo-carousellogo-showcaselogo-slidersponsors
77
B · Generally Safe
CVEs total2
Unpatched1
Last CVESep 22, 2025
Safety Verdict

Is Logo Showcase – Logo Slider, Carousel & Sponsors Gallery Safe to Use in 2026?

Mostly Safe

Score 77/100

Logo Showcase – Logo Slider, Carousel & Sponsors Gallery is generally safe to use. 2 past CVEs were resolved. Keep it updated.

2 known CVEs 1 unpatched Last CVE: Sep 22, 2025Updated 1mo ago
Risk Assessment

The logo-showcase plugin v4.0.1 exhibits a mixed security posture. On the positive side, it demonstrates good practices by not utilizing dangerous functions, performing file operations, or making external HTTP requests. All SQL queries are prepared, and the use of nonces and capability checks is present, albeit only on three entry points. The attack surface is relatively small with only two identified entry points, and importantly, none appear to be directly unprotected. However, a significant concern arises from the output escaping, where only 59% of outputs are properly escaped. This indicates a moderate risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data could potentially be rendered without adequate sanitization.

The vulnerability history of this plugin is a major red flag. With two known CVEs, one of which remains unpatched, the plugin has a track record of security flaws. The common vulnerability type being Cross-Site Scripting (XSS) directly correlates with the static analysis findings regarding insufficient output escaping. The fact that a vulnerability was identified as recently as September 2025 suggests ongoing security challenges and the importance of addressing the unpatched vulnerability swiftly.

In conclusion, while the plugin incorporates some fundamental security measures like prepared statements and nonce checks, the prevalence of XSS-related vulnerabilities in its history and the static analysis finding of poor output escaping significantly detract from its overall security. The unpatched CVE represents an immediate and critical risk that needs urgent attention. The developer should prioritize addressing this outstanding vulnerability and improving output sanitization across the plugin.

Key Concerns

  • Currently unpatched CVE
  • Insufficient output escaping
  • Medium severity CVEs in history
Vulnerabilities
2

Logo Showcase – Logo Slider, Carousel & Sponsors Gallery Security Vulnerabilities

CVEs by Year

2 CVEs in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2025-58684medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Logo Showcase <= 3.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

Sep 22, 2025Unpatched
CVE-2025-47497medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Logo Showcase <= 3.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

May 7, 2025 Patched in 3.0.5 (7d)
Code Analysis
Analyzed Mar 16, 2026

Logo Showcase – Logo Slider, Carousel & Sponsors Gallery Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
156
220 escaped
Nonce Checks
3
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

59% escaped376 total outputs
Attack Surface

Logo Showcase – Logo Slider, Carousel & Sponsors Gallery Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 1

authwp_ajax_tlsw_logoshowcase_dismiss_review_noticeinc\logo-showcase-metabox.php:1586

Shortcodes 1

[logo_showcase] shortcode\logo-showcase-shortcode.php:105
WordPress Hooks 13
actionadd_meta_boxesinc\logo-showcase-metabox.php:14
actionsave_postinc\logo-showcase-metabox.php:1451
actionadmin_noticesinc\logo-showcase-metabox.php:1566
actioninitinc\logo-showcase-postytpe.php:41
filtermanage_tplogoshowcase_posts_columnsinc\logo-showcase-postytpe.php:52
actionmanage_tplogoshowcase_posts_custom_columninc\logo-showcase-postytpe.php:65
filterenter_title_hereinc\logo-showcase-postytpe.php:75
actionedit_form_after_titleinc\logo-showcase-postytpe.php:126
filterwidget_textlogo-showcase-wordpress.php:21
actionplugins_loadedlogo-showcase-wordpress.php:32
actionwp_enqueue_scriptslogo-showcase-wordpress.php:46
actionadmin_enqueue_scriptslogo-showcase-wordpress.php:63
actionadmin_menulogo-showcase-wordpress.php:74
Maintenance & Trust

Logo Showcase – Logo Slider, Carousel & Sponsors Gallery Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 9, 2026
PHP min version
Downloads36K

Community Trust

Rating82/100
Number of ratings9
Active installs900
Developer Profile

Logo Showcase – Logo Slider, Carousel & Sponsors Gallery Developer Profile

Themepoints

19 plugins · 10K total installs

84
trust score
Avg Security Score
94/100
Avg Patch Time
66 days
View full developer profile
Detection Fingerprints

How We Detect Logo Showcase – Logo Slider, Carousel & Sponsors Gallery

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/logo-showcase/frontend/css/logo-showcase-wordpress.css/wp-content/plugins/logo-showcase/frontend/css/owl.carousel.css/wp-content/plugins/logo-showcase/frontend/css/tipso.css/wp-content/plugins/logo-showcase/admin/css/font-awesome.css/wp-content/plugins/logo-showcase/frontend/js/owl.carousel.js/wp-content/plugins/logo-showcase/frontend/js/tipso.js/wp-content/plugins/logo-showcase/admin/css/logo-showcase-menu-style.css/wp-content/plugins/logo-showcase/admin/js/logo-showcase-backend-admin.js+1 more
Script Paths
frontend/js/owl.carousel.jsfrontend/js/tipso.jsadmin/js/logo-showcase-backend-admin.jsadmin/js/color-picker.js
Version Parameters
logo-showcase/style.css?ver=logo-showcase-owl?ver=logo-showcase-tipso?ver=logo-showcase-awesome-css?ver=logo-showcase-owl-js?ver=logo-showcase-tipso-js?ver=logo-showcase-menu-style?ver=logo-showcase-admin-js?ver=logo_showcase_color_picker?ver=

HTML / DOM Fingerprints

CSS Classes
logo-showcase-mainlogoshowcase-arealogo-itemlogo-image-wrapperowl-carouseltipso
HTML Comments
Logo Showcase Widget AreaLogo ShowcaseLogo Showcase Shortcode
Data Attributes
data-iddata-show-titledata-show-linkdata-show-tooltipdata-tooltip-textdata-columns+4 more
JS Globals
logo_showcase_color_picker_params
Shortcode Output
[logo_showcase id="<?php echo do_shortcode( "[logo_showcase id=" ); ?>'
FAQ

Frequently Asked Questions about Logo Showcase – Logo Slider, Carousel & Sponsors Gallery