PAJ Featured Image Owl Carousel / Slider Security & Risk Analysis

wordpress.org/plugins/paj-featured-image-owl-carousel

Responsive feature image Carousel slider for posts and pages, use with shortcode or SiteOrigin Widgets Bundle by SiteOrigin.

70 active installs v1.2.1 PHP 5.6+ WP 4.0.1+ Updated Apr 6, 2020
carouselfeatured-image-carouselimageresponsive-carouselsiteorigin-widget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is PAJ Featured Image Owl Carousel / Slider Safe to Use in 2026?

Generally Safe

Score 85/100

PAJ Featured Image Owl Carousel / Slider has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The paj-featured-image-owl-carousel plugin version 1.2.1 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, the exclusive use of prepared statements for SQL queries, and a high percentage of properly escaped outputs are commendable practices. Furthermore, the lack of file operations and external HTTP requests reduces the potential for certain classes of vulnerabilities. The plugin also benefits from a clean vulnerability history with no recorded CVEs, indicating a history of secure development or thorough security practices by its maintainers.

However, there are notable areas of concern. The most significant is the complete absence of nonce checks and capability checks across all identified entry points, including its single shortcode. This means that any user, regardless of their role or permissions, could potentially trigger actions associated with this shortcode, opening the door for Cross-Site Request Forgery (CSRF) attacks. While the static analysis did not detect any taint flows or critical/high severity issues, the lack of robust authorization checks on the entry points is a substantial weakness that could be exploited in conjunction with other vulnerabilities or by manipulating the plugin's behavior.

In conclusion, while the plugin demonstrates good coding practices in areas like SQL sanitization and output escaping, the lack of essential security checks like nonces and capability checks on its shortcode is a critical oversight. This creates a significant risk of unauthorized actions and CSRF attacks. The absence of any historical vulnerabilities is a positive indicator but does not negate the immediate risks posed by these missing security controls.

Key Concerns

  • Missing nonce checks on shortcode
  • Missing capability checks on shortcode
Vulnerabilities
None known

PAJ Featured Image Owl Carousel / Slider Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

PAJ Featured Image Owl Carousel / Slider Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

PAJ Featured Image Owl Carousel / Slider Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
23 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

92% escaped25 total outputs
Attack Surface

PAJ Featured Image Owl Carousel / Slider Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[paj-owl-slider] paj-widgets\paj-carousel\shortcode\paj-carousel-shortcode.php:387
WordPress Hooks 4
filtersiteorigin_widgets_widget_folderspaj-carousel-widget.php:29
actionadmin_headpaj-carousel-widget.php:33
actionadmin_headpaj-carousel-widget.php:42
actionwp_enqueue_scriptspaj-widgets\paj-carousel\shortcode\paj-carousel-shortcode.php:22
Maintenance & Trust

PAJ Featured Image Owl Carousel / Slider Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedApr 6, 2020
PHP min version5.6
Downloads4K

Community Trust

Rating100/100
Number of ratings2
Active installs70
Developer Profile

PAJ Featured Image Owl Carousel / Slider Developer Profile

phillip2532

2 plugins · 170 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect PAJ Featured Image Owl Carousel / Slider

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/paj-featured-image-owl-carousel/paj-widgets/paj-carousel/shortcode/js/modernizr-custom.js/wp-content/plugins/paj-featured-image-owl-carousel/paj-widgets/paj-carousel/shortcode/js/owl.carousel.js/wp-content/plugins/paj-featured-image-owl-carousel/paj-widgets/paj-carousel/shortcode/js/owl-settings.js/wp-content/plugins/paj-featured-image-owl-carousel/paj-widgets/paj-carousel/shortcode/css/owl.carousel.css/wp-content/plugins/paj-featured-image-owl-carousel/paj-widgets/paj-carousel/shortcode/css/owl-carousel-style.css
Script Paths
modernizr-custom.jsowl.carousel.jsowl-settings.js
Version Parameters
paj-carousel-owl-carousel/style.css?ver=paj-carousel-owl-carousel/js/modernizr-custom.js?ver=paj-carousel-owl-carousel/js/owl.carousel.js?ver=paj-carousel-owl-carousel/js/owl-settings.js?ver=paj-carousel-owl-carousel/css/owl.carousel.css?ver=paj-carousel-owl-carousel/css/owl-carousel-style.css?ver=

HTML / DOM Fingerprints

CSS Classes
paj-icon-colorsiteorigin-widget-field-paj_heading_sizesiteorigin-widget-field-paj_excerpt_sizesiteorigin-widget-field-paj_meta_sizesiteorigin-widget-field-paj_heading_casesiteorigin-widget-field-paj_heading_weightsiteorigin-widget-field-paj_excerpt_casesiteorigin-widget-field-paj_excerpt_weight+11 more
HTML Comments
<!-- PAJ Featured Image Owl Carousel. -->
JS Globals
pajbooleannumber_rangevalidateWeightvalidateCasevalidateColorvalidateBorderStyle+1 more
FAQ

Frequently Asked Questions about PAJ Featured Image Owl Carousel / Slider