
Post Carousel Divi Security & Risk Analysis
wordpress.org/plugins/post-carousel-diviThis plugin add a post carousel module to the Divi theme.
Is Post Carousel Divi Safe to Use in 2026?
Generally Safe
Score 100/100Post Carousel Divi has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "post-carousel-divi" v1.2.4 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is commendable. Furthermore, the presence of a nonce check and the high percentage of properly escaped outputs indicate good development practices to prevent common web vulnerabilities. The total lack of known CVEs, both historical and currently unpatched, is also a significant positive indicator of the plugin's security track record.
However, a key concern is the complete absence of capability checks for its single AJAX entry point. While the analysis states there are 0 unprotected AJAX handlers, this likely means the existing handler has *some* form of authentication, but the lack of explicit capability checks means that even authenticated users might have unintended access or control over this functionality. The bundled Freemius library, though at version 1.0, could also be a potential area of concern if it's an outdated version with known vulnerabilities, though no specific information is provided here. The lack of taint analysis results is noted but doesn't necessarily indicate a problem, as it could simply mean no complex data flows were identified that required it.
In conclusion, the plugin demonstrates solid defensive coding for most common attack vectors. The primary weakness identified is the lack of granular capability checks on its AJAX endpoint. Users should be aware of this potential for privilege escalation if the AJAX handler's authentication is not sufficiently robust. The absence of historical vulnerabilities is a strong positive, but continuous monitoring is always advised.
Key Concerns
- Missing capability checks on AJAX handler
- Bundled library (Freemius v1.0) may be outdated
Post Carousel Divi Security Vulnerabilities
Post Carousel Divi Code Analysis
Bundled Libraries
Output Escaping
Post Carousel Divi Attack Surface
AJAX Handlers 1
WordPress Hooks 4
Maintenance & Trust
Post Carousel Divi Maintenance & Trust
Maintenance Signals
Community Trust
Post Carousel Divi Alternatives
Supreme Modules Lite – Divi Theme, Extra Theme and Divi Builder
supreme-modules-for-divi
Divi Supreme lite plugin enhances the experience and features found on Divi and extend with custom creative modules to help you build amazing websites …
Divi Torque Lite – Divi Theme, Divi Builder & Extra Theme
addons-for-divi
The Divi Torque plugin you install after Divi builder! Packed with 70+ stunning modules like Post Grid, Filterable Gallery, Google Reviews, and more.
Divi Carousel Lite – 17+ Carousel Module
carousels-slider-for-divi
Divi Carousel Lite, the ultimate Divi Builder plugin with 17+ modules like image carousel, testimonial carousel, logo carousel, team carousel, and mor …
Shortcodes for Divi
shortcodes-for-divi
Shortcodes for Divi by WP Zone Allows you to use Divi Shortcodes everywhere where text comes.
Simple Divi Shortcode
simple-divi-shortcode
Insert DIVI Library item inside module content or inside a php template by using a shortcode.
Post Carousel Divi Developer Profile
9 plugins · 31K total installs
How We Detect Post Carousel Divi
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/post-carousel-divi/assets/css/slick.css/wp-content/plugins/post-carousel-divi/assets/css/slick-theme.css/wp-content/plugins/post-carousel-divi/assets/css/post-carousel-divi.css/wp-content/plugins/post-carousel-divi/assets/js/slick.min.js/wp-content/plugins/post-carousel-divi/assets/js/post-carousel-divi.jspost-carousel-divi/assets/css/post-carousel-divi.css?ver=post-carousel-divi/assets/js/slick.min.js?ver=post-carousel-divi/assets/js/post-carousel-divi.js?ver=HTML / DOM Fingerprints
lwp_post_carousel_itemlwp_post_carousel_item_innerlwp_carousel_defaultlwp_post_carousel_imagelwp_carousel_featured_imagelwp_carousel_sidelwp_image_position_leftlwp_image_position_right+12 moredata-lwp_post_carousel_item