Ultimate Carousel For Divi Security & Risk Analysis

wordpress.org/plugins/ultimate-carousel-for-divi

Create stunning, branded carousels with ease. Showcase your products, post types, categories, and images like never before with Ultimate Divi Carousel

800 active installs v5.0.0 PHP 7.4+ WP 4.5+ Updated Dec 12, 2025
divi-carouseldivi-image-carouseldivi-post-type-carouseldivi-sliderdivi-taxonomy-terms-carousel
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Ultimate Carousel For Divi Safe to Use in 2026?

Generally Safe

Score 100/100

Ultimate Carousel For Divi has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The 'ultimate-carousel-for-divi' v5.0.0 plugin exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and critical findings in taint analysis are particularly positive indicators. Furthermore, the plugin demonstrates good practices by using prepared statements for all SQL queries and a high percentage of properly escaped output, which significantly mitigates common web vulnerabilities.

However, there are a few areas that warrant attention. The lack of nonce checks across all identified entry points (REST API routes and AJAX handlers) is a notable concern. While all REST API routes and AJAX handlers have permission callbacks, relying solely on capability checks without nonces can still leave the plugin susceptible to Cross-Site Request Forgery (CSRF) attacks if user interactions are not carefully handled. The presence of bundled libraries, while common, is also a potential area for future concern if these libraries are not kept up-to-date and actively maintained.

Overall, the plugin appears to be built with security in mind, with a clear focus on preventing direct SQL injection and output manipulation. The primary weakness lies in the potential for CSRF due to the absence of nonce checks on its entry points. Continued vigilance regarding bundled library updates and thorough security testing of any future versions will be important for maintaining this good security record.

Key Concerns

  • 0 Nonce checks on entry points
  • Bundled libraries (Freemius)
Vulnerabilities
None known

Ultimate Carousel For Divi Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Ultimate Carousel For Divi Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
3 prepared
Unescaped Output
60
456 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius

SQL Query Safety

100% prepared3 total queries

Output Escaping

88% escaped516 total outputs
Attack Surface

Ultimate Carousel For Divi Attack Surface

Entry Points8
Unprotected0

REST API Routes 8

GET/wp-json/wpt-divi-post-type-query-builder/v1/get_categories_by_rest_apiincludes\classes\Divi\PostTypeQueryBuilder.php:165
GET/wp-json/wpt-divi-post-type-query-builder/v1/get_tags_by_rest_apiincludes\classes\Divi\PostTypeQueryBuilder.php:176
GET/wp-json/wpt-divi-ultimate-carousel/v1/product-categories-and-tagsincludes\classes\Loader.php:161
GET/wp-json/wpt-divi-ultimate-carousel/v1/post-typesincludes\classes\Loader.php:174
GET/wp-json/wpt-divi-ultimate-carousel/v1/post-type-taxonomiesincludes\classes\Loader.php:187
GET/wp-json/wpt-divi-ultimate-carousel/v1/post-type-categoriesincludes\classes\Loader.php:200
GET/wp-json/wpt-divi-ultimate-carousel/v1/post-type-tagsincludes\classes\Loader.php:213
GET/wp-json/wpt-divi-ultimate-carousel/v1/post-statusesincludes\classes\Loader.php:226
WordPress Hooks 30
actiondivi_visual_builder_assets_before_enqueue_scriptsdivi-5\divi-5.php:67
actioninitdivi-5\divi-5.php:68
actioninitincludes\classes\Divi5\Modules\FullwidthImageCarouselItemModule\FullwidthImageCarouselItemModule.php:29
actioninitincludes\classes\Divi5\Modules\FullwidthImageCarouselModule\FullwidthImageCarouselModule.php:29
actioninitincludes\classes\Divi5\Modules\FullwidthPostTypeCarouselModule\FullwidthPostTypeCarouselModule.php:29
actioninitincludes\classes\Divi5\Modules\FullwidthTaxonomyCarouselModule\FullwidthTaxonomyCarouselModule.php:29
actioninitincludes\classes\Divi5\Modules\FullwidthWooProductCarouselModule\FullwidthWooProductCarouselModule.php:29
actioninitincludes\classes\Divi5\Modules\ImageCarouselItemModule\ImageCarouselItemModule.php:29
actioninitincludes\classes\Divi5\Modules\ImageCarouselModule\ImageCarouselModule.php:29
actiondivi_module_library_modules_dependency_treeincludes\classes\Divi5\Modules\Modules.php:21
actioninitincludes\classes\Divi5\Modules\PostTypeCarouselModule\PostTypeCarouselModule.php:29
actioninitincludes\classes\Divi5\Modules\TaxonomyCarouselModule\TaxonomyCarouselModule.php:29
actioninitincludes\classes\Divi5\Modules\WooProductCarouselModule\WooProductCarouselModule.php:29
actionet_builder_readyincludes\classes\Loader.php:123
actiondivi_extensions_initincludes\classes\Loader.php:124
actionwp_enqueue_scriptsincludes\classes\Loader.php:126
actionwp_print_stylesincludes\classes\Loader.php:128
actionrest_api_initincludes\classes\Loader.php:134
actionadmin_initincludes\classes\Loader.php:137
actionadmin_enqueue_scriptsincludes\classes\Loader.php:147
actionplugins_loadedincludes\classes\Loader.php:151
actionrest_api_initincludes\classes\Loader.php:158
actioninitincludes\classes\Loader.php:241
actionafter_license_changeincludes\classes\Loader.php:321
actioncreated_termincludes\classes\TaxonomyCategory\FormFields.php:32
actionedit_termincludes\classes\TaxonomyCategory\FormFields.php:33
filterregister_post_type_argsincludes\classes\WP\PostTypes.php:24
actionregistered_taxonomyincludes\classes\WP\Taxonomies.php:21
filteret_builder_processed_range_valueincludes\modules\ImageCardCarouselItem\ImageCardCarouselItem.php:37
filtershow_first_trial_after_n_secultimate-carousel-for-divi.php:19
Maintenance & Trust

Ultimate Carousel For Divi Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 12, 2025
PHP min version7.4
Downloads14K

Community Trust

Rating68/100
Number of ratings5
Active installs800
Developer Profile

Ultimate Carousel For Divi Developer Profile

wptools

15 plugins · 6K total installs

93
trust score
Avg Security Score
99/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Ultimate Carousel For Divi

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ultimate-carousel-for-divi/divi-5/visual-builder/styles/bundle.css/wp-content/plugins/ultimate-carousel-for-divi/js/swiper/swiper-bundle.min.js/wp-content/plugins/ultimate-carousel-for-divi/js/swiper/script-v2.js/wp-content/plugins/ultimate-carousel-for-divi/css/swiper/swiper-bundle.min.css/wp-content/plugins/ultimate-carousel-for-divi/css/swiper/style.css/wp-content/plugins/ultimate-carousel-for-divi/styles/backend-style.min.css
Script Paths
/wp-content/plugins/ultimate-carousel-for-divi/divi-5/visual-builder/build/d5-wpt-ultimate-carousel.js
Version Parameters
/wp-content/plugins/ultimate-carousel-for-divi/js/swiper/swiper-bundle.min.js?ver=/wp-content/plugins/ultimate-carousel-for-divi/js/swiper/script-v2.js?ver=/wp-content/plugins/ultimate-carousel-for-divi/css/swiper/swiper-bundle.min.css?ver=/wp-content/plugins/ultimate-carousel-for-divi/css/swiper/style.css?ver=/wp-content/plugins/ultimate-carousel-for-divi/divi-5/visual-builder/styles/bundle.css?ver=

HTML / DOM Fingerprints

CSS Classes
d5-wpt-ultimate-carousel
JS Globals
window.q1z9x7r4a
FAQ

Frequently Asked Questions about Ultimate Carousel For Divi