NEO Bootstrap Carousel Security & Risk Analysis

wordpress.org/plugins/neo-bootstrap-carousel

A clean, simple & robust implementation of the Twitter Bootstrap Carousel in WordPress site in elegant way.

40 active installs v1.4.3 PHP 7.0+ WP 4.8+ Updated Apr 30, 2020
responsive-sliderresponsive-content-slideshowwordpress-horizontal-sliderwordpress-responsive-bootstrap-carousel
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is NEO Bootstrap Carousel Safe to Use in 2026?

Generally Safe

Score 85/100

NEO Bootstrap Carousel has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "neo-bootstrap-carousel" plugin, version 1.4.3, exhibits a generally strong security posture based on the provided static analysis. The plugin demonstrates good practices by implementing nonce checks and capability checks for its entry points, and importantly, all SQL queries are performed using prepared statements, mitigating the risk of SQL injection. The limited attack surface, with only one shortcode and no AJAX handlers or REST API routes, further contributes to its security. The absence of known CVEs and a clean vulnerability history also suggests a well-maintained codebase.

However, there are minor areas for improvement. The plugin makes one external HTTP request, which, if not handled securely, could potentially be a vector for certain attacks. Additionally, while the vast majority of output is properly escaped (93%), the remaining 7% that is not escaped could still pose a risk if it involves user-supplied data, potentially leading to cross-site scripting (XSS) vulnerabilities. The analysis of taint flows yielded no critical or high severity issues, reinforcing the overall positive security assessment, but the remaining unescaped outputs warrant attention.

In conclusion, "neo-bootstrap-carousel" v1.4.3 appears to be a relatively secure plugin, with a history of no known vulnerabilities and good implementation of fundamental security checks. The primary concerns revolve around the single external HTTP request and the small percentage of unescaped output. Addressing these minor issues would further strengthen the plugin's security.

Key Concerns

  • External HTTP requests found
  • Minor unescaped output detected
Vulnerabilities
None known

NEO Bootstrap Carousel Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

NEO Bootstrap Carousel Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
14
178 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
1
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

93% escaped192 total outputs
Attack Surface

NEO Bootstrap Carousel Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[neo_carousel_shortcode] includes\class-neo-bootstrap-carousel-shortcode.php:34
WordPress Hooks 33
actionadmin_initadmin\class-neo-bootstrap-carousel-admin.php:59
filterplugin_row_metaadmin\class-neo-bootstrap-carousel-admin.php:69
actionadmin_menuincludes\admin\class-neo-bootstrap-carousel-changelog.php:34
actionadmin_menuincludes\admin\class-neo-bootstrap-carousel-help.php:34
actionadmin_menuincludes\admin\class-neo-bootstrap-carousel-settings.php:34
actionadmin_noticesincludes\admin\class-neo-bootstrap-carousel-settings.php:48
actionadmin_menuincludes\admin\class-neo-bootstrap-carousel-system-requirements.php:34
actionadmin_menuincludes\admin\class-neo-bootstrap-carousel-welcome.php:34
filternbc_settings_tab_menusincludes\admin\settings\class-neo-bootstrap-carousel-advanced.php:34
actionnbc_settings_tab_sectionincludes\admin\settings\class-neo-bootstrap-carousel-advanced.php:37
actionnbc_save_setting_sectionsincludes\admin\settings\class-neo-bootstrap-carousel-advanced.php:40
filternbc_settings_tab_menusincludes\admin\settings\class-neo-bootstrap-carousel-design.php:44
actionnbc_settings_tab_sectionincludes\admin\settings\class-neo-bootstrap-carousel-design.php:47
actionnbc_save_setting_sectionsincludes\admin\settings\class-neo-bootstrap-carousel-design.php:50
filternbc_settings_tab_menusincludes\admin\settings\class-neo-bootstrap-carousel-general.php:34
actionnbc_settings_tab_sectionincludes\admin\settings\class-neo-bootstrap-carousel-general.php:37
actionnbc_save_setting_sectionsincludes\admin\settings\class-neo-bootstrap-carousel-general.php:40
actioninitincludes\class-neo-bootstrap-carousel-gutenberg.php:33
actionadd_meta_boxesincludes\class-neo-bootstrap-carousel-meta-box.php:131
actionsave_postincludes\class-neo-bootstrap-carousel-meta-box.php:132
actioninitincludes\class-neo-bootstrap-carousel-post-type.php:33
actionadmin_initincludes\class-neo-bootstrap-carousel-post-type.php:36
filtermanage_neo_carousel_posts_columnsincludes\class-neo-bootstrap-carousel-post-type.php:173
actionmanage_neo_carousel_posts_custom_columnincludes\class-neo-bootstrap-carousel-post-type.php:176
actionadd_meta_boxesincludes\class-neo-bootstrap-carousel-shortcode.php:37
filterthe_contentincludes\class-neo-bootstrap-carousel-shortcode.php:39
actionplugins_loadedincludes\class-neo-bootstrap-carousel.php:149
actionadmin_enqueue_scriptsincludes\class-neo-bootstrap-carousel.php:162
actionadmin_enqueue_scriptsincludes\class-neo-bootstrap-carousel.php:163
actionwp_enqueue_scriptsincludes\class-neo-bootstrap-carousel.php:176
actionwp_enqueue_scriptsincludes\class-neo-bootstrap-carousel.php:177
filterwidget_textincludes\functions\neo-bootstrap-carousel-formatting-functions.php:90
actionnbc_default_configurationspublic\class-neo-bootstrap-carousel-public.php:57
Maintenance & Trust

NEO Bootstrap Carousel Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedApr 30, 2020
PHP min version7.0
Downloads6K

Community Trust

Rating80/100
Number of ratings3
Active installs40
Developer Profile

NEO Bootstrap Carousel Developer Profile

PixelsPress

1 plugin · 40 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect NEO Bootstrap Carousel

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/neo-bootstrap-carousel/admin/css/neo-bootstrap-carousel-admin.css/wp-content/plugins/neo-bootstrap-carousel/admin/js/select2.js/wp-content/plugins/neo-bootstrap-carousel/admin/js/neo-bootstrap-carousel-admin.js
Script Paths
/wp-content/plugins/neo-bootstrap-carousel/admin/js/select2.js/wp-content/plugins/neo-bootstrap-carousel/admin/js/neo-bootstrap-carousel-admin.js
Version Parameters
neo-bootstrap-carousel/admin/css/neo-bootstrap-carousel-admin.css?ver=neo-bootstrap-carousel/admin/js/select2.js?ver=neo-bootstrap-carousel/admin/js/neo-bootstrap-carousel-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
neo-bootstrap-carouselneo-bootstrap-carousel-star-rating
Data Attributes
data-toggle="tooltip"data-original-title="Download Theme"
JS Globals
nbc
FAQ

Frequently Asked Questions about NEO Bootstrap Carousel