Logo Slider , Logo Carousel , Logo showcase , Client Logo Security & Risk Analysis

wordpress.org/plugins/tc-logo-slider

Logo Slider Carousel is an easy plugin to display logo carousel slider of clients, business partners or affiliates along with title, URL on your websi …

1K active installs v1.8.1 PHP 5.4+ WP + Updated Dec 15, 2024
carousellogologo-carousellogo-sliderslider
70
B · Generally Safe
CVEs total1
Unpatched1
Last CVEDec 31, 2025
Safety Verdict

Is Logo Slider , Logo Carousel , Logo showcase , Client Logo Safe to Use in 2026?

Mostly Safe

Score 70/100

Logo Slider , Logo Carousel , Logo showcase , Client Logo is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved.

1 known CVE 1 unpatched Last CVE: Dec 31, 2025Updated 1yr ago
Risk Assessment

The 'tc-logo-slider' plugin version 1.8.1 exhibits a concerning security posture despite some positive indicators. While the attack surface appears limited with no unprotected AJAX handlers or REST API routes, the plugin's handling of output is a significant weakness. With 100% of its 23 output operations unescaped, this presents a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into web pages. This is further amplified by the plugin's history, which shows a known medium severity CVE related to XSS, indicating a recurring issue in how user-supplied data is rendered. The absence of nonce checks and capability checks on its entry points, though currently not exploited by the limited attack surface, could become a problem if new entry points are introduced or existing ones are modified without proper security considerations. The lack of any identified taint flows or dangerous functions is a positive, but it does not negate the critical risk posed by the unescaped output and the historical vulnerability.

Key Concerns

  • Unpatched CVE
  • All output unescaped
  • Medium severity CVE history (XSS)
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
1 published

Logo Slider , Logo Carousel , Logo showcase , Client Logo Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-62121medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Logo Slider , Logo Carousel , Logo showcase , Client Logo <= 1.8.1 - Authenticated (Editor+) Stored Cross-Site Scripting

Dec 31, 2025Unpatched
Version History

Logo Slider , Logo Carousel , Logo showcase , Client Logo Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

Logo Slider , Logo Carousel , Logo showcase , Client Logo Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
23
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped23 total outputs
Attack Surface

Logo Slider , Logo Carousel , Logo showcase , Client Logo Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[tc-logo-slider] public\tc-logo-view.php:170
WordPress Hooks 6
actionwp_footerpublic\tc-logo-view.php:93
actionwp_enqueue_scriptstc-logo-slider.php:36
actionadmin_enqueue_scriptstc-logo-slider.php:43
actionadmin_menutc-logo-slider.php:52
actiondo_meta_boxestc-logo-slider.php:77
actionactivated_plugintc-logo-slider.php:89
Maintenance & Trust

Logo Slider , Logo Carousel , Logo showcase , Client Logo Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedDec 15, 2024
PHP min version5.4
Downloads43K

Community Trust

Rating74/100
Number of ratings3
Active installs1K
Developer Profile

Logo Slider , Logo Carousel , Logo showcase , Client Logo Developer Profile

Imran Emu

7 plugins · 3K total installs

81
trust score
Avg Security Score
81/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Logo Slider , Logo Carousel , Logo showcase , Client Logo

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tc-logo-slider/assets/css/tcls.css/wp-content/plugins/tc-logo-slider/assets/css/tc-logo-admin.css/wp-content/plugins/tc-logo-slider/vendors/owl-carousel-2/assets/owl.carousel.css
Script Paths
/wp-content/plugins/tc-logo-slider/vendors/owl-carousel-2/owl.carousel.min.js
Version Parameters
tc-logo-slider/assets/css/tcls.css?ver=tc-logo-slider/vendors/owl-carousel-2/owl.carousel.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
tcls-wraptcls-titletc-owl-carouseltc-logo-admin
Data Attributes
tc_crop_imgtc_crop_img_widthtc_crop_img_height
JS Globals
tc_logo_trigger
Shortcode Output
<div class="tcls-wrap"><div id="tc-logo" class="owl-carousel owl-th
FAQ

Frequently Asked Questions about Logo Slider , Logo Carousel , Logo showcase , Client Logo