Logo Carousel – Display Brand or Client Logos in Slider Security & Risk Analysis

wordpress.org/plugins/responsive-client-logo-carousel-slider

Responsive Client Logo Carousel Slider Is a nice WordPress plugin which can be used to showcase your client logo in a professional way.

800 active installs v1.3.0 PHP 7.1+ WP 4.8+ Updated Dec 9, 2025
carouselclient-logo-carouselclient-logo-sliderlogo-slideshowslider
99
A · Safe
CVEs total1
Unpatched0
Last CVESep 30, 2024
Safety Verdict

Is Logo Carousel – Display Brand or Client Logos in Slider Safe to Use in 2026?

Generally Safe

Score 99/100

Logo Carousel – Display Brand or Client Logos in Slider has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Sep 30, 2024Updated 3mo ago
Risk Assessment

The "responsive-client-logo-carousel-slider" plugin v1.3.0 presents a generally good security posture, with several strong defensive mechanisms in place. The absence of critical or high-severity taint flows, along with the use of prepared statements for all SQL queries, are positive indicators. Nonce and capability checks are also present, and there are no external HTTP requests or file operations that could introduce common vulnerabilities. The lack of unprotected entry points is commendable, suggesting thoughtful development regarding access control.

However, a concerning aspect is the presence of a past medium-severity Cross-Site Scripting (XSS) vulnerability. While currently patched, this indicates a historical weakness in input sanitization or output escaping that could potentially resurface if not thoroughly addressed in subsequent updates. The 71% proper output escaping, while relatively high, still leaves room for potential issues, as even a small percentage of unescaped output can be exploited in certain contexts.

In conclusion, the plugin demonstrates a commitment to secure coding practices, particularly in data handling and entry point protection. The past XSS vulnerability warrants vigilance, and the remaining percentage of unescaped output should be reviewed. Overall, the plugin is in a reasonably secure state, but continuous monitoring and thorough code reviews for potential future vulnerabilities remain essential.

Key Concerns

  • Past medium severity XSS vulnerability
  • 29% of output potentially unescaped
Vulnerabilities
1

Logo Carousel – Display Brand or Client Logos in Slider Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-47631medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Logo Carousel – Clients logo carousel for WP <= 1.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Sep 30, 2024 Patched in 1.3.0 (11d)
Code Analysis
Analyzed Mar 16, 2026

Logo Carousel – Display Brand or Client Logos in Slider Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
229
555 escaped
Nonce Checks
12
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

71% escaped784 total outputs
Data Flows
All sanitized

Data Flow Analysis

3 flows
csf_export (metabox\csf\functions\actions.php:62)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Logo Carousel – Display Brand or Client Logos in Slider Attack Surface

Entry Points6
Unprotected0

AJAX Handlers 5

authwp_ajax_csf-get-iconsmetabox\csf\functions\actions.php:50
authwp_ajax_csf-exportmetabox\csf\functions\actions.php:87
authwp_ajax_csf-importmetabox\csf\functions\actions.php:123
authwp_ajax_csf-resetmetabox\csf\functions\actions.php:150
authwp_ajax_csf-chosenmetabox\csf\functions\actions.php:189

Shortcodes 1

[carousel] shortcode.php:60
WordPress Hooks 55
actionwp_enqueue_scriptsmetabox\csf\classes\abstract.class.php:20
actionadmin_menumetabox\csf\classes\admin-options.class.php:107
actionadmin_bar_menumetabox\csf\classes\admin-options.class.php:108
actionnetwork_admin_menumetabox\csf\classes\admin-options.class.php:112
filteradmin_footer_textmetabox\csf\classes\admin-options.class.php:432
actionadd_meta_boxes_commentmetabox\csf\classes\comment-options.class.php:38
actionedit_commentmetabox\csf\classes\comment-options.class.php:39
actioncustomize_registermetabox\csf\classes\customize-options.class.php:44
actioncustomize_save_aftermetabox\csf\classes\customize-options.class.php:45
actionwp_enqueue_scriptsmetabox\csf\classes\customize-options.class.php:49
actionadd_meta_boxesmetabox\csf\classes\metabox-options.class.php:52
actionsave_postmetabox\csf\classes\metabox-options.class.php:53
actionedit_attachmentmetabox\csf\classes\metabox-options.class.php:54
actionwp_nav_menu_item_custom_fieldsmetabox\csf\classes\nav-menu-options.class.php:32
actionwp_update_nav_menu_itemmetabox\csf\classes\nav-menu-options.class.php:33
filterwp_edit_nav_menu_walkermetabox\csf\classes\nav-menu-options.class.php:35
actionadmin_initmetabox\csf\classes\profile-options.class.php:32
actionshow_user_profilemetabox\csf\classes\profile-options.class.php:44
actionedit_user_profilemetabox\csf\classes\profile-options.class.php:45
actionpersonal_options_updatemetabox\csf\classes\profile-options.class.php:47
actionedit_user_profile_updatemetabox\csf\classes\profile-options.class.php:48
actionafter_setup_thememetabox\csf\classes\setup.class.php:73
actioninitmetabox\csf\classes\setup.class.php:74
actionswitch_thememetabox\csf\classes\setup.class.php:75
actionadmin_enqueue_scriptsmetabox\csf\classes\setup.class.php:76
actionwp_enqueue_scriptsmetabox\csf\classes\setup.class.php:77
actionwp_headmetabox\csf\classes\setup.class.php:78
filteradmin_body_classmetabox\csf\classes\setup.class.php:79
actionadmin_footermetabox\csf\classes\shortcode-options.class.php:47
actioncustomize_controls_print_footer_scriptsmetabox\csf\classes\shortcode-options.class.php:48
actionelementor/editor/before_enqueue_scriptsmetabox\csf\classes\shortcode-options.class.php:59
actionelementor/editor/footermetabox\csf\classes\shortcode-options.class.php:60
actionelementor/editor/footermetabox\csf\classes\shortcode-options.class.php:61
actionenqueue_block_editor_assetsmetabox\csf\classes\shortcode-options.class.php:258
actionmedia_buttonsmetabox\csf\classes\shortcode-options.class.php:262
actionadmin_initmetabox\csf\classes\taxonomy-options.class.php:41
actionadmin_footermetabox\csf\fields\icon\icon.php:41
actioncustomize_controls_print_footer_scriptsmetabox\csf\fields\icon\icon.php:42
actionadmin_print_footer_scriptsmetabox\csf\fields\link\link.php:65
actionprint_default_editor_scriptsmetabox\csf\fields\wp_editor\wp_editor.php:62
actionadmin_menumetabox\csf\views\welcome.php:19
filterplugin_action_linksmetabox\csf\views\welcome.php:20
filterplugin_row_metametabox\csf\views\welcome.php:21
actioninitpost_type.php:6
filterpost_updated_messagespost_type.php:8
actionadmin_head-post.phppost_type.php:10
actionadmin_head-post-new.phppost_type.php:11
filtermanage_scrollingcarousel_posts_columnspost_type.php:15
actionmanage_scrollingcarousel_posts_custom_columnpost_type.php:16
actionadmin_initpost_type.php:18
actionedit_form_after_titlepost_type.php:20
actioninitscrolling-logo-carosel.php:26
actionwp_enqueue_scriptsscrolling-logo-carosel.php:35
filteradmin_footer_textscrolling-logo-carosel.php:56
actionadmin_initscrolling-logo-carosel.php:82
Maintenance & Trust

Logo Carousel – Display Brand or Client Logos in Slider Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 9, 2025
PHP min version7.1
Downloads13K

Community Trust

Rating80/100
Number of ratings2
Active installs800
Developer Profile

Logo Carousel – Display Brand or Client Logos in Slider Developer Profile

colorlibplugins

120 plugins · 738K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
140 days
View full developer profile
Detection Fingerprints

How We Detect Logo Carousel – Display Brand or Client Logos in Slider

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/responsive-client-logo-carousel-slider/js/crawler.js
Script Paths
js/crawler.js

HTML / DOM Fingerprints

CSS Classes
bafg-clients-logo-carousel
HTML Comments
<!-- Logo Carousel Elementor Widget --><!-- Responsive Client Logo Carousel -->
Data Attributes
data-carousel-options
JS Globals
jQuerybafgClientsCarousel
Shortcode Output
[logo-carousel-slider
FAQ

Frequently Asked Questions about Logo Carousel – Display Brand or Client Logos in Slider