Text Carousel Block Security & Risk Analysis

wordpress.org/plugins/text-carousel-block

Text Carousel Block is a simple plugin that adds a Gutenberg block for inserting Text Content Carousel to your posts and pages.

200 active installs v1.0.1 PHP 5.6.0+ WP 4.9.6+ Updated Dec 10, 2025
blockscarouselcontent-carouselgutenbergtext-carousel
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Text Carousel Block Safe to Use in 2026?

Generally Safe

Score 100/100

Text Carousel Block has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The "text-carousel-block" plugin, in version 1.0.1, exhibits a strong security posture based on the provided static analysis. The complete absence of identified dangerous functions, the exclusive use of prepared statements for SQL queries, and the assurance of proper output escaping indicate robust development practices. Furthermore, the plugin demonstrates a lack of file operations and external HTTP requests, which are common vectors for attacks. The reported zero known CVEs and the absence of any recorded vulnerabilities in its history are positive indicators of ongoing maintenance and security awareness.

While the static analysis reveals a clean codebase with no immediate red flags, the total absence of entry points like AJAX handlers, REST API routes, shortcodes, and cron events is notable. This could be interpreted in two ways: either the plugin's functionality is extremely limited and requires no such interfaces, or it might indicate an incomplete static analysis report that didn't uncover potential, albeit obscure, entry points. The lack of nonce and capability checks on the identified entry points (even though there are none) means that if any were to be introduced in future versions, they would likely be unprotected. However, based solely on the provided data for v1.0.1, there are no direct vulnerabilities to exploit.

Key Concerns

  • No capability checks found
  • No nonce checks found
Vulnerabilities
None known

Text Carousel Block Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Text Carousel Block Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Text Carousel Block Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actioninittext-carousel-block.php:41
actioninittext-carousel-block.php:44
actionplugins_loadedtext-carousel-block.php:117
Maintenance & Trust

Text Carousel Block Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 10, 2025
PHP min version5.6.0
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs200
Developer Profile

Text Carousel Block Developer Profile

tishonator

54 plugins · 3K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Text Carousel Block

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/text-carousel-block/css/font-awesome.min.css/wp-content/plugins/text-carousel-block/css/text-carousel-block.css/wp-content/plugins/text-carousel-block/js/text-carousel-block.js/wp-content/plugins/text-carousel-block/js/text-carousel-item.js
Script Paths
/wp-content/plugins/text-carousel-block/js/text-carousel-block.js/wp-content/plugins/text-carousel-block/js/text-carousel-item.js
Version Parameters
text-carousel-block/css/text-carousel-block.css?ver=text-carousel-block/js/text-carousel-block.js?ver=text-carousel-block/js/text-carousel-item.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Text Carousel Block