Logo Showcase Ultimate – Logo Carousel, Logo Slider & Logo Grid Security & Risk Analysis

wordpress.org/plugins/logo-showcase-ultimate

Ultimate logo showcase plugin to create responsive logo carousel, logo slider & logo grid and display unlimited clients, partners, sponsors logos

4K active installs v1.4.5 PHP + WP 4.0+ Updated Apr 28, 2025
logologo-carousellogo-gridlogo-showcaselogo-slider
88
A · Safe
CVEs total3
Unpatched0
Last CVEApr 9, 2025
Safety Verdict

Is Logo Showcase Ultimate – Logo Carousel, Logo Slider & Logo Grid Safe to Use in 2026?

Generally Safe

Score 88/100

Logo Showcase Ultimate – Logo Carousel, Logo Slider & Logo Grid has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

3 known CVEsLast CVE: Apr 9, 2025Updated 1yr ago
Risk Assessment

The logo-showcase-ultimate plugin v1.4.5 exhibits a mixed security posture. While the static analysis reveals a limited attack surface with no directly unprotected entry points, the presence of the 'unserialize' function is a significant concern. Furthermore, the fact that 100% of SQL queries are not using prepared statements poses a substantial risk for SQL injection vulnerabilities. The taint analysis, while showing no critical or high severity flows, did identify one flow with unsanitized paths, indicating potential for further issues if not addressed.

The plugin's vulnerability history is a major red flag. With a total of 3 known CVEs, including 2 high and 1 medium severity, and a recent vulnerability logged in April 2025, there's a clear pattern of past security weaknesses. The types of historical vulnerabilities, such as Remote File Inclusion, Cross-site Scripting, and Deserialization of Untrusted Data, directly correlate with the code signals like 'unserialize' and the lack of prepared statements. This history suggests that the developers may struggle with secure coding practices, particularly concerning input validation and data handling.

In conclusion, despite a relatively small attack surface and good output escaping percentages, the core issues of raw SQL queries, the use of 'unserialize', and a history of significant vulnerabilities create a notable risk. The absence of currently unpatched CVEs is a positive sign, but the underlying patterns of insecurity require careful consideration.

Key Concerns

  • Raw SQL queries without prepared statements
  • Use of 'unserialize' function
  • Historical high severity vulnerabilities
  • Historical medium severity vulnerabilities
  • Unsanitized path in taint analysis
Vulnerabilities
3 published

Logo Showcase Ultimate – Logo Carousel, Logo Slider & Logo Grid Security Vulnerabilities

CVEs by Year

2 CVEs in 2024
2024
1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

High
2
Medium
1

3 total CVEs

CVE-2025-32499high · 8.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

Logo Showcase Ultimate <= 1.4.4 - Authenticated (Contributor+) Local File Inclusion

Apr 9, 2025 Patched in 1.4.5 (22d)
CVE-2024-8046medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Logo Showcase Ultimate – Logo Carousel, Logo Slider & Logo Grid <= 1.4.1 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload

Aug 26, 2024 Patched in 1.4.2 (1d)
CVE-2024-1951high · 7.5Deserialization of Untrusted Data

Logo Showcase Ultimate – Logo Carousel, Logo Slider & Logo Grid <= 1.3.8 - Authenticated(Contributor+) PHP Object Injection

Mar 5, 2024 Patched in 1.3.9 (149d)
Code Analysis
Analyzed Mar 16, 2026

Logo Showcase Ultimate – Logo Carousel, Logo Slider & Logo Grid Code Analysis

Dangerous Functions
1
Raw SQL Queries
1
0 prepared
Unescaped Output
27
137 escaped
Nonce Checks
2
Capability Checks
3
File Operations
1
External Requests
2
Bundled Libraries
0

Dangerous Functions Found

unserialize$unserialized_data = unserialize( base64_decode( $wcpscu_data ) );lcg_adl_main.php:112

SQL Query Safety

0% prepared1 total queries

Output Escaping

84% escaped164 total outputs
Data Flows · Security
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
formActionUrl (classes\appsero\src\License.php:713)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Logo Showcase Ultimate – Logo Carousel, Logo Slider & Logo Grid Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[logo_showcase] classes\lcg-shortcode.php:13
WordPress Hooks 33
actionswitch_themeclasses\appsero\src\Insights.php:134
actionswitch_themeclasses\appsero\src\Insights.php:135
actionadmin_footerclasses\appsero\src\Insights.php:147
actionadmin_noticesclasses\appsero\src\Insights.php:165
actionadmin_initclasses\appsero\src\Insights.php:168
filtercron_schedulesclasses\appsero\src\Insights.php:174
actionadmin_menuclasses\appsero\src\License.php:205
actionafter_switch_themeclasses\appsero\src\License.php:704
actionswitch_themeclasses\appsero\src\License.php:705
filterpre_set_site_transient_update_pluginsclasses\appsero\src\Updater.php:42
filterplugins_apiclasses\appsero\src\Updater.php:43
filterpre_set_site_transient_update_themesclasses\appsero\src\Updater.php:52
actionelementor/widgets/registerclasses\elementor\init.php:11
actioninitclasses\gutenberg\init.php:81
actioninitclasses\lcg-adl-custom-post.php:13
filterpost_updated_messagesclasses\lcg-adl-metabox.php:14
filtermanage_lcg_shortcode_posts_columnsclasses\lcg-adl-metabox.php:16
actionmanage_lcg_shortcode_posts_custom_columnclasses\lcg-adl-metabox.php:17
actiondo_meta_boxesclasses\lcg-adl-metabox.php:18
actionadd_meta_boxesclasses\lcg-adl-metabox.php:19
actionedit_postclasses\lcg-adl-metabox.php:20
actionadd_meta_boxesclasses\lcg-metabox-overrider.php:21
filteradmin_post_thumbnail_htmlclasses\lcg-metabox-overrider.php:22
filtermedia_view_stringsclasses\lcg-metabox-overrider.php:23
actioninitlcg_adl_main.php:60
actionadmin_enqueue_scriptslcg_adl_main.php:61
actiontemplate_redirectlcg_adl_main.php:62
actionadmin_menulcg_adl_main.php:63
actionelementor/preview/enqueue_styleslcg_adl_main.php:67
actionelementor/preview/enqueue_scriptslcg_adl_main.php:68
actionenqueue_block_editor_assetslcg_adl_main.php:70
actionadmin_noticeslcg_adl_main.php:73
actionadmin_initlcg_adl_main.php:77
Maintenance & Trust

Logo Showcase Ultimate – Logo Carousel, Logo Slider & Logo Grid Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 28, 2025
PHP min version
Downloads86K

Community Trust

Rating94/100
Number of ratings27
Active installs4K
Developer Profile

Logo Showcase Ultimate – Logo Carousel, Logo Slider & Logo Grid Developer Profile

wpWax

15 plugins · 62K total installs

69
trust score
Avg Security Score
86/100
Avg Patch Time
202 days
View full developer profile
Detection Fingerprints

How We Detect Logo Showcase Ultimate – Logo Carousel, Logo Slider & Logo Grid

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/logo-showcase-ultimate/assets/css/style.css/wp-content/plugins/logo-showcase-ultimate/assets/css/vendor/swiper-bundle.min.css/wp-content/plugins/logo-showcase-ultimate/assets/css/vendor/tooltip.css/wp-content/plugins/logo-showcase-ultimate/assets/js/vendor/popper.min.js/wp-content/plugins/logo-showcase-ultimate/assets/js/vendor/tooltip.js/wp-content/plugins/logo-showcase-ultimate/assets/js/vendor/swiper-bundle.min.js/wp-content/plugins/logo-showcase-ultimate/assets/js/main.js
Version Parameters
logo-showcase-ultimate/assets/css/style.css?ver=logo-showcase-ultimate/assets/css/vendor/swiper-bundle.min.css?ver=logo-showcase-ultimate/assets/css/vendor/tooltip.css?ver=logo-showcase-ultimate/assets/js/vendor/popper.min.js?ver=logo-showcase-ultimate/assets/js/vendor/tooltip.js?ver=logo-showcase-ultimate/assets/js/vendor/swiper-bundle.min.js?ver=logo-showcase-ultimate/assets/js/main.js?ver=

HTML / DOM Fingerprints

CSS Classes
lcg-logo-showcase-containerlcg-tooltip-wraplcg-tooltip
Data Attributes
data-lcg-iddata-lcg-optionsdata-lcg-id
JS Globals
lcg_data
Shortcode Output
[logo-showcase[logo_showcase
FAQ

Frequently Asked Questions about Logo Showcase Ultimate – Logo Carousel, Logo Slider & Logo Grid