
Media Carousel – Video, Logo and Image Slider for Elementor Security & Risk Analysis
wordpress.org/plugins/media-carousel-video-logo-and-image-slider-for-elementorMedia Carousel for Elementor lets you add Image, Logo, Video with Elementor Page Builder. You can display your images, logo, videos with this slider a …
Is Media Carousel – Video, Logo and Image Slider for Elementor Safe to Use in 2026?
Generally Safe
Score 85/100Media Carousel – Video, Logo and Image Slider for Elementor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
This plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries, exclusively using prepared statements, and has no recorded vulnerability history, suggesting a generally well-maintained codebase. However, significant concerns arise from its attack surface. The presence of two AJAX handlers without any authentication or capability checks presents a clear risk. Furthermore, the taint analysis revealed two flows with unsanitized paths, although these did not escalate to critical or high severity in this analysis. The lack of any nonce checks on these unprotected AJAX endpoints is a notable oversight that could be exploited.
Despite the absence of documented CVEs, the identified unprotected entry points and unsanitized paths in the taint analysis are direct security risks that should be addressed. The plugin's strengths lie in its SQL handling and historical lack of vulnerabilities, but these are overshadowed by the critical need for robust authentication and input sanitization on its AJAX handlers. A balanced conclusion would be that while the plugin has a clean history and good SQL practices, its current implementation of its attack surface introduces significant potential vulnerabilities.
Key Concerns
- Unprotected AJAX handlers
- Taint flows with unsanitized paths
- Missing nonce checks on AJAX
- Unescaped output (22% of outputs)
Media Carousel – Video, Logo and Image Slider for Elementor Security Vulnerabilities
Media Carousel – Video, Logo and Image Slider for Elementor Code Analysis
Output Escaping
Data Flow Analysis
Media Carousel – Video, Logo and Image Slider for Elementor Attack Surface
AJAX Handlers 2
WordPress Hooks 22
Maintenance & Trust
Media Carousel – Video, Logo and Image Slider for Elementor Maintenance & Trust
Maintenance Signals
Community Trust
Media Carousel – Video, Logo and Image Slider for Elementor Alternatives
No alternatives data available yet.
Media Carousel – Video, Logo and Image Slider for Elementor Developer Profile
14 plugins · 18K total installs
How We Detect Media Carousel – Video, Logo and Image Slider for Elementor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/media-carousel-video-logo-and-image-slider-for-elementor/admin/media-carousel-utils.php/wp-content/plugins/media-carousel-video-logo-and-image-slider-for-elementor/functions.php/wp-content/plugins/media-carousel-video-logo-and-image-slider-for-elementor/class-plugin-deactivate-feedback.php/wp-content/plugins/media-carousel-video-logo-and-image-slider-for-elementor/support-page/class-support-page.phpHTML / DOM Fingerprints
wb_mc-up-pro-link/*
Welcome to the Custom CSS editor!
Please add all your custom CSS here and avoid modifying the core plugin files. Don't use <style> tag
*//*
Welcome to the Custom JS editor!
Please add all your custom JS here and avoid modifying the core plugin files. Don't use <script> tag
*//* Custom CSS *//* Custom JS */id="wb_mc_custom_css"name="wb_mc_custom_js"id="wb_mc_custom_js"