Post Carousel Divi Security & Risk Analysis

wordpress.org/plugins/post-carousel-divi

This plugin add a post carousel module to the Divi theme.

2K active installs v1.2.4 PHP 7.0+ WP 5.0+ Updated Sep 20, 2025
dividivi-moduledivi-post-carouselpost-carousel
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Post Carousel Divi Safe to Use in 2026?

Generally Safe

Score 100/100

Post Carousel Divi has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The "post-carousel-divi" v1.2.4 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is commendable. Furthermore, the presence of a nonce check and the high percentage of properly escaped outputs indicate good development practices to prevent common web vulnerabilities. The total lack of known CVEs, both historical and currently unpatched, is also a significant positive indicator of the plugin's security track record.

However, a key concern is the complete absence of capability checks for its single AJAX entry point. While the analysis states there are 0 unprotected AJAX handlers, this likely means the existing handler has *some* form of authentication, but the lack of explicit capability checks means that even authenticated users might have unintended access or control over this functionality. The bundled Freemius library, though at version 1.0, could also be a potential area of concern if it's an outdated version with known vulnerabilities, though no specific information is provided here. The lack of taint analysis results is noted but doesn't necessarily indicate a problem, as it could simply mean no complex data flows were identified that required it.

In conclusion, the plugin demonstrates solid defensive coding for most common attack vectors. The primary weakness identified is the lack of granular capability checks on its AJAX endpoint. Users should be aware of this potential for privilege escalation if the AJAX handler's authentication is not sufficiently robust. The absence of historical vulnerabilities is a strong positive, but continuous monitoring is always advised.

Key Concerns

  • Missing capability checks on AJAX handler
  • Bundled library (Freemius v1.0) may be outdated
Vulnerabilities
None known

Post Carousel Divi Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Post Carousel Divi Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
14 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

Output Escaping

93% escaped15 total outputs
Attack Surface

Post Carousel Divi Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_lwp_get_carousel_postspost-carousel.php:195
WordPress Hooks 4
actionadmin_menuincludes\class-lwp-pc-settings-page.php:22
filterpricing/show_annual_in_monthlypost-carousel.php:62
actionplugins_loadedpost-carousel.php:67
actiondivi_extensions_initpost-carousel.php:83
Maintenance & Trust

Post Carousel Divi Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 20, 2025
PHP min version7.0
Downloads25K

Community Trust

Rating98/100
Number of ratings12
Active installs2K
Developer Profile

Post Carousel Divi Developer Profile

learnhowwp

9 plugins · 31K total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Post Carousel Divi

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/post-carousel-divi/assets/css/slick.css/wp-content/plugins/post-carousel-divi/assets/css/slick-theme.css/wp-content/plugins/post-carousel-divi/assets/css/post-carousel-divi.css/wp-content/plugins/post-carousel-divi/assets/js/slick.min.js/wp-content/plugins/post-carousel-divi/assets/js/post-carousel-divi.js
Version Parameters
post-carousel-divi/assets/css/post-carousel-divi.css?ver=post-carousel-divi/assets/js/slick.min.js?ver=post-carousel-divi/assets/js/post-carousel-divi.js?ver=

HTML / DOM Fingerprints

CSS Classes
lwp_post_carousel_itemlwp_post_carousel_item_innerlwp_carousel_defaultlwp_post_carousel_imagelwp_carousel_featured_imagelwp_carousel_sidelwp_image_position_leftlwp_image_position_right+12 more
Data Attributes
data-lwp_post_carousel_item
FAQ

Frequently Asked Questions about Post Carousel Divi