
Slider-Carousel-Shortcodes-WC-Product Security & Risk Analysis
wordpress.org/plugins/slider-carousel-shortcodes-wc-productSlider-Carousel-Shortcodes-WC-Product
Is Slider-Carousel-Shortcodes-WC-Product Safe to Use in 2026?
Generally Safe
Score 85/100Slider-Carousel-Shortcodes-WC-Product has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "slider-carousel-shortcodes-wc-product" v1.0.2 exhibits a generally positive security posture based on the provided static analysis and vulnerability history. The plugin has a small attack surface consisting of only two shortcodes, and critically, none of these entry points are exposed without proper authentication checks. The code also demonstrates good practices by exclusively using prepared statements for SQL queries, eliminating the risk of SQL injection vulnerabilities through this common vector. There are no indications of dangerous function usage, file operations, or external HTTP requests, further bolstering its secure design.
However, the analysis does reveal areas for improvement. The plugin has an output escaping rate of only 50%, meaning half of its outputs are not properly escaped. This presents a risk of Cross-Site Scripting (XSS) vulnerabilities, as unescaped data could be rendered directly in the browser, allowing attackers to inject malicious scripts. Furthermore, the absence of any nonce checks is a significant concern. Nonces are crucial for verifying the origin of requests and preventing Cross-Site Request Forgery (CSRF) attacks. The lack of capability checks also means that access to certain functionalities might not be adequately restricted based on user roles.
The plugin's vulnerability history is exceptionally clean, with zero recorded CVEs across all severities and no recent vulnerabilities. This strong track record suggests a commitment to security by the developers or that the plugin has not been a target for exploit attempts. Despite the positive history, the identified weaknesses in output escaping and the complete lack of nonce and capability checks warrant attention to prevent potential security incidents.
Key Concerns
- Unescaped output
- Missing nonce checks
- Missing capability checks
Slider-Carousel-Shortcodes-WC-Product Security Vulnerabilities
Slider-Carousel-Shortcodes-WC-Product Code Analysis
Output Escaping
Slider-Carousel-Shortcodes-WC-Product Attack Surface
Shortcodes 2
WordPress Hooks 1
Maintenance & Trust
Slider-Carousel-Shortcodes-WC-Product Maintenance & Trust
Maintenance Signals
Community Trust
Slider-Carousel-Shortcodes-WC-Product Alternatives
Carousel Slider
carousel-slider
Create SEO friendly Image, Logo, Video, Post, WooCommerce Product Carousel, and Slider.
Slider by Soliloquy – Responsive Image Slider for WordPress
soliloquy-lite
The best WordPress slider plugin. Drag & Drop responsive slider builder that helps you create a beautiful image slideshows with just a few clicks.
Product Slider, Product Carousel and Product Grid Gallery for WooCommerce – WooProduct Slider
woo-product-slider
Display your WooCommerce products in a responsive Product Slider, Product Carousel, or Product Grid Gallery with easy customization.
Product Carousel Slider & Grid Ultimate for WooCommerce
woo-product-carousel-slider-and-grid-ultimate
The most intuitive solution to make your eCommerce site visually appealing. Create & customize WooCommerce product carousel, sliders, or grids easily
WPB Product Slider for WooCommerce
wpb-woocommerce-product-slider
Display WooCommerce products in a responsive slider or carousel with customizable layouts to boost engagement and improve product browsing.
Slider-Carousel-Shortcodes-WC-Product Developer Profile
3 plugins · 470 total installs
How We Detect Slider-Carousel-Shortcodes-WC-Product
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/slider-carousel-shortcodes-wc-product/style-wc-carousel-product.css/wp-content/plugins/slider-carousel-shortcodes-wc-product/owl.carousel.min.jsHTML / DOM Fingerprints
wc-carousel-marcowc-carousel-marco-bza-owl-carouselmarcob-owl-carouseldata-positionwcsmelementowcsmelementobwcsmautoanimazionewcsmnumerocolonnewcwcsmautoanimazione-bwcsmnumerocolonnewc-b<div class="wc-carousel-marco"><div class="wc-carousel-marco-b">