
Reviews Carousel Security & Risk Analysis
wordpress.org/plugins/reviews-carouselReviews Carousel is a free and powerful plugin that lets you create and showcase customer reviews in a dynamic carousel format.
Is Reviews Carousel Safe to Use in 2026?
Generally Safe
Score 100/100Reviews Carousel has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The reviews-carousel plugin v1.1.0 exhibits a generally good security posture based on the provided static analysis and vulnerability history. The plugin demonstrates strong adherence to WordPress security best practices, with a significant majority of outputs properly escaped and a single nonce and capability check in place, indicating an effort to secure its entry points. The absence of dangerous functions, file operations, and external HTTP requests further strengthens its security profile. The taint analysis shows no identified vulnerabilities, and the lack of any recorded CVEs or past vulnerabilities is a very positive indicator. However, a notable concern arises from the single SQL query, which is not using prepared statements. This could be a potential vulnerability point, especially if user-supplied data influences the query without proper sanitization beyond the basic escaping already in place.
While the plugin's attack surface is minimal and appears to be protected, the unescaped SQL query represents a weakness. The absence of any past vulnerabilities could be due to thorough development practices or simply a lack of targeted exploitation attempts. Nevertheless, the potential for SQL injection, however small it may seem with only one query, should not be overlooked. The overall conclusion is that the plugin is relatively secure, with its main weakness being the lack of prepared statements for its SQL query. Developers should prioritize addressing this to further enhance its security.
Key Concerns
- SQL query not using prepared statements
Reviews Carousel Security Vulnerabilities
Reviews Carousel Code Analysis
SQL Query Safety
Output Escaping
Reviews Carousel Attack Surface
Shortcodes 1
WordPress Hooks 10
Maintenance & Trust
Reviews Carousel Maintenance & Trust
Maintenance Signals
Community Trust
Reviews Carousel Alternatives
Devgirl Reviews Slider
devgirl-reviews-slider
A slider to show the reviews from your customer. Autoplay, style options, easy to add and use the shortcode anywhere.
WP Google Review Slider
wp-google-places-review-slider
Display Google reviews on your site and even show user images! No address, no problem! Also works with Service Area Businesses and Products! Lightwei …
WP TripAdvisor Review Slider
wp-tripadvisor-review-slider
Create a TripAdvisor review slider! Now with User Images! Easily display your TripAdvisor reviews in your Posts, Pages, and Widget areas!
WP Review Slider
wp-facebook-reviews
Use the official Facebook API to show off your review and recommendations in a slider or grid! A simple and easy way to display your Twitter and Faceb …
Solid Testimonials – Testimonial Slider, Video Testimonials & Customer Reviews
gs-testimonial
Showcase and automate customer reviews with ease - sliders, grids, filters, and more to boost trust and sales.
Reviews Carousel Developer Profile
2 plugins · 10 total installs
How We Detect Reviews Carousel
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/reviews-carousel/assets/css/slick.css/wp-content/plugins/reviews-carousel/assets/js/slick.min.js/wp-content/plugins/reviews-carousel/assets/js/revica.js/wp-content/plugins/reviews-carousel/assets/js/revica.jsslick.min.js?ver=1.8.1revica.js?ver=1.0HTML / DOM Fingerprints
slick-trackslick-slideslick-listslick-arrowrevica-review-itemdata-revica-itemsdata-revica-autoplaydata-revica-arrowsreviewsCarouselSettings[reviews_carousel]