Post Slider For WPBakery Page Builder Security & Risk Analysis

wordpress.org/plugins/post-carousel-slider-for-visual-composer

Drag & touch Post Carousel anything at any position (row / column) in VC

1K active installs v1.1 PHP + WP 3.5+ Updated Sep 27, 2022
all-in-one-pluginpost-slider-for-visual-composerpost-slider-for-wpbakery-page-buildervisual-composervisual-composer-extension
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Post Slider For WPBakery Page Builder Safe to Use in 2026?

Generally Safe

Score 85/100

Post Slider For WPBakery Page Builder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The static analysis of "post-carousel-slider-for-visual-composer" v1.1 indicates a generally positive security posture, with no immediately apparent critical vulnerabilities identified in the provided data. The absence of dangerous functions, raw SQL queries, file operations, external HTTP requests, and taint analysis findings suggests careful coding practices in these areas. The plugin also demonstrates good use of prepared statements for its SQL queries.

However, a significant concern is the extremely low percentage (5%) of properly escaped output. With 150 total outputs analyzed, this implies that a substantial number of user-provided or dynamic data points are not being properly sanitized before being displayed, creating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The lack of any capability checks or nonce checks on entry points is also a major weakness, as it means any unauthenticated or low-privileged user could potentially interact with parts of the plugin that were intended to be protected, opening the door for privilege escalation or unauthorized actions. The plugin's vulnerability history being clean is a positive sign, but the identified weaknesses in output escaping and authorization checks are serious and should be addressed proactively.

In conclusion, while the plugin avoids common pitfalls like raw SQL and dangerous functions, the severe lack of output escaping and missing authorization checks presents a significant security risk. The clean vulnerability history is encouraging, but it does not mitigate the inherent dangers revealed by the static analysis. Addressing these core weaknesses is crucial for improving the plugin's overall security.

Key Concerns

  • Low output escaping percentage (5%)
  • No capability checks on entry points
  • No nonce checks on entry points
Vulnerabilities
None known

Post Slider For WPBakery Page Builder Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Post Slider For WPBakery Page Builder Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
142
8 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

5% escaped150 total outputs
Attack Surface

Post Slider For WPBakery Page Builder Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionvc_before_initmain.php:7
actionwp_enqueue_scriptsmain.php:8
actioninitmain.php:9
actionadmin_noticesmain.php:27
Maintenance & Trust

Post Slider For WPBakery Page Builder Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedSep 27, 2022
PHP min version
Downloads25K

Community Trust

Rating80/100
Number of ratings9
Active installs1K
Developer Profile

Post Slider For WPBakery Page Builder Developer Profile

nasir179125

3 plugins · 32K total installs

58
trust score
Avg Security Score
70/100
Avg Patch Time
281 days
View full developer profile
Detection Fingerprints

How We Detect Post Slider For WPBakery Page Builder

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/post-carousel-slider-for-visual-composer/css/css/font-awesome.min.css/wp-content/plugins/post-carousel-slider-for-visual-composer/css/post-design.css/wp-content/plugins/post-carousel-slider-for-visual-composer/css/simplegrid.css/wp-content/plugins/post-carousel-slider-for-visual-composer/js/jquery.matchHeight-min.js
Script Paths
/wp-content/plugins/post-carousel-slider-for-visual-composer/js/jquery.matchHeight-min.js
Version Parameters
post-carousel-slider-for-visual-composer/css/css/font-awesome.min.css?ver=post-carousel-slider-for-visual-composer/css/post-design.css?ver=post-carousel-slider-for-visual-composer/css/simplegrid.css?ver=post-carousel-slider-for-visual-composer/js/jquery.matchHeight-min.js?ver=

HTML / DOM Fingerprints

CSS Classes
na-prefixgridgrid-pad
HTML Comments
<!-- Copyright (C) 2017 Nasir nasirahmad2010@hotmail.com This program is free software; you can redistribute it and/or modify it under the terms of the GNU General Public License, version 2, as published by the Free Software Foundation. This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details. You should have received a copy of the GNU General Public License along with this program; if not, write to the Free Software Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA --><!-- Please install <a href="https://1.envato.market/A1QAx">WPBakery Page Builder</a> to use Post Carousel. -->
Data Attributes
data-vc-shortcode="na_posts_grid"
Shortcode Output
<div class="na-prefix"><div class="grid grid-pad">
FAQ

Frequently Asked Questions about Post Slider For WPBakery Page Builder