Slider Bootstrap Carousel Security & Risk Analysis

wordpress.org/plugins/slider-bootstrap-carousel

Slider Bootstrap Carousel 4 for WordPress with image link and categories.

20 active installs v1.0.7 PHP + WP 3.0.1+ Updated Jan 16, 2019
boostrapboostrap-carouselbootstrap-sliderresponsive-bannerresponsive-slider
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Slider Bootstrap Carousel Safe to Use in 2026?

Generally Safe

Score 85/100

Slider Bootstrap Carousel has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "slider-bootstrap-carousel" plugin v1.0.7 exhibits a generally positive security posture based on the provided static analysis. The absence of known CVEs and no recorded vulnerabilities in its history are strong indicators of responsible development and maintenance. Furthermore, the lack of dangerous functions, file operations, external HTTP requests, and the use of prepared statements for all SQL queries are commendable security practices.

However, a significant concern arises from the output escaping. With a substantial number of outputs (36 total), only 17% are properly escaped. This represents a considerable risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected into the WordPress site via user-submitted data that is later displayed by the plugin. While the attack surface is limited to two shortcodes and no AJAX/REST API routes are exposed without authentication, the unescaped output remains a critical weakness that could be exploited. The absence of nonce and capability checks, while not directly evidenced as exploitable due to the limited attack surface, does indicate potential for future vulnerabilities if the plugin's entry points were to expand.

In conclusion, the plugin demonstrates strengths in its lack of known vulnerabilities and secure handling of database queries. Nevertheless, the poor output escaping practices are a significant security flaw that requires immediate attention to prevent potential XSS attacks. The plugin is otherwise well-coded in terms of its attack surface and data handling.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

Slider Bootstrap Carousel Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Slider Bootstrap Carousel Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
30
6 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

17% escaped36 total outputs
Attack Surface

Slider Bootstrap Carousel Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[slider_bootstrap_carousel] includes\bcfw-shortcode.php:103
[slider_bootstrap_carousel] includes\sbc-shortcode.php:126
WordPress Hooks 12
actionadd_meta_boxesincludes\bcfw-meta-box.php:16
actionsave_postincludes\bcfw-meta-box.php:89
actionadd_meta_boxesincludes\bcfw-meta-box.php:104
actionwp_enqueue_scriptsincludes\bcfw-plugin-scripts.php:13
actioninitincludes\bcfw-taxonomy-category.php:41
actionadd_meta_boxesincludes\sbc-meta-box.php:16
actionsave_postincludes\sbc-meta-box.php:90
actionadd_meta_boxesincludes\sbc-meta-box.php:105
actionwp_enqueue_scriptsincludes\sbc-plugin-scripts.php:13
actioninitincludes\sbc-taxonomy-category.php:41
actioninitslider-bootstrap-carousel.php:27
actionplugins_loadedslider-bootstrap-carousel.php:95
Maintenance & Trust

Slider Bootstrap Carousel Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedJan 16, 2019
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Slider Bootstrap Carousel Developer Profile

felipermendes

1 plugin · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Slider Bootstrap Carousel

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/slider-bootstrap-carousel/assets/bootstrap.min.js/wp-content/plugins/slider-bootstrap-carousel/assets/bootstrap.min.css
Script Paths
/wp-content/plugins/slider-bootstrap-carousel/assets/bootstrap.min.js/wp-content/plugins/slider-bootstrap-carousel/assets/bootstrap.min.css
Version Parameters
slider-bootstrap-carousel/assets/bootstrap.min.js?ver=slider-bootstrap-carousel/assets/bootstrap.min.css?ver=

HTML / DOM Fingerprints

CSS Classes
carouselslidecarousel-indicatorsactivecarousel-innercarousel-itemimg-fluidcarousel-caption+7 more
Data Attributes
data-ride="carousel"data-target="#slider-bootstrap-carousel-data-slide-to="data-slide="prev"role="button"aria-hidden="true"
Shortcode Output
<div id="slider-bootstrap-carousel-class="carousel slide" data-ride="carousel"<ol class="carousel-indicators"<li data-target="#slider-bootstrap-carousel-
FAQ

Frequently Asked Questions about Slider Bootstrap Carousel