
Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts Security & Risk Analysis
wordpress.org/plugins/post-carouselDisplay posts, pages, and taxonomies in beautiful carousel, slider, and grid layouts with advanced filtering. Customizable, Developer-friendly.
Is Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts Safe to Use in 2026?
Generally Safe
Score 90/100Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The post-carousel plugin version 3.0.12 presents a mixed security posture. While it demonstrates good practices such as using prepared statements for all SQL queries and a high percentage of properly escaped outputs, there are notable areas of concern. The presence of two AJAX handlers without authentication checks represents a direct attack vector that could be exploited by unauthenticated users. Furthermore, the static analysis flagged the use of the 'unserialize' function, which can be dangerous if used with untrusted input, though no critical or high severity taint flows were identified in the provided data. The plugin's vulnerability history, with a total of four known CVEs including one high-severity vulnerability in the past, indicates a pattern of past security weaknesses. This suggests that while the current version might have addressed previous issues, the historical trend warrants caution and diligent monitoring for future updates. Overall, the plugin has strengths in its handling of database queries and output sanitization but weaknesses in its access control for AJAX endpoints and past security incidents that require attention.
Key Concerns
- Unprotected AJAX handlers
- Use of unserialize function
- History of high severity vulnerability
- History of medium severity vulnerabilities
Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts <= 3.0.12 - Authenticated (Administrator+) PHP Object Injection
Smart Post Show <= 3.0.0 - Authenticated (Editor+) Stored Cross-Site Scripting via Pagination Color
Post Grid, Post Carousel, & List Category Posts <= 2.4.27 - Authenticated (Editor+) Stored Cross-Site Scripting
Post Grid, Post Carousel, & List Category Posts <= 2.4.18 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Post Carousel < 2.3.5 - Missing Capabilities Check
Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts Release Timeline
Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts Attack Surface
AJAX Handlers 8
Shortcodes 3
WordPress Hooks 48
Maintenance & Trust
Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts Maintenance & Trust
Maintenance Signals
Community Trust
Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts Alternatives
GS Posts Grid – Recent Posts, Category Posts, Post Filter, Slider & List
posts-grid
GS Posts Grid – A flexible plugin to display posts in Grid, Masonry, Slider, Popup, List, Card, Table, Filter & Justified Gallery views.
Content Views – Post Grid & Filter, Recent Posts, Category Posts … (Shortcode, Gutenberg Blocks, and Widgets for Elementor)
content-views-query-and-display-post-page
Easy to show posts, pages, custom posts in customizable grid, list, slider, accordion... Available as Widgets (for Elementor), Shortcode, and Blocks.
Smart Recent Posts Widget
smart-recent-posts-widget
Provides advanced recent posts widget,you can display it with thumbnails, excerpt, date, author, comment count and more.
Custom Layouts – Post + Product grids made easy
custom-layouts
Build a list or grid layout of any post type (posts, products, pages + more).
PE Recent Posts
pe-recent-posts
The simple plugin that allows you to display image slides with title, description and read more linked to posts from selected category.
Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts Developer Profile
18 plugins · 315K total installs
How We Detect Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/post-carousel/admin/css/sp-pcp-admin.css/wp-content/plugins/post-carousel/public/css/swiper.min.css/wp-content/plugins/post-carousel/public/css/post-carousel.css/wp-content/plugins/post-carousel/admin/js/sp-pcp-admin.js/wp-content/plugins/post-carousel/public/js/swiper.min.js/wp-content/plugins/post-carousel/public/js/post-carousel.js/wp-content/plugins/post-carousel/admin/js/sp-pcp-admin.js/wp-content/plugins/post-carousel/public/js/swiper.min.js/wp-content/plugins/post-carousel/public/js/post-carousel.jspost-carousel/admin/css/sp-pcp-admin.css?ver=post-carousel/public/css/swiper.min.css?ver=post-carousel/public/css/post-carousel.css?ver=post-carousel/admin/js/sp-pcp-admin.js?ver=post-carousel/public/js/swiper.min.js?ver=post-carousel/public/js/post-carousel.js?ver=HTML / DOM Fingerprints
sp-pcp-wrappersp-pcp-slidersp-pcp-itemsp-pcp-contentsp-pcp-titlesp-pcp-excerptsp-pcp-readmoresp-pcp-meta+4 moredata-sp-pcp-optionssp_pcp_params[post_carousel]