Unlimited Logo Carousel Security & Risk Analysis

wordpress.org/plugins/unlimited-logo-carousel

Unlimited Logo Carousel allows you to easily create logo carousel/slider to display logos of clients, partners, sponsors, affiliates etc.

600 active installs v1.3 PHP + WP 3.5+ Updated Oct 15, 2019
logologo-carousellogo-carousel-sliderlogo-showcaselogo-slider
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Unlimited Logo Carousel Safe to Use in 2026?

Generally Safe

Score 85/100

Unlimited Logo Carousel has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The "unlimited-logo-carousel" v1.3 plugin exhibits a generally good security posture based on the provided static analysis. It demonstrates a commitment to secure coding practices with the absence of dangerous functions, SQL queries utilizing prepared statements, and a history free of known vulnerabilities. The presence of nonce and capability checks, despite a relatively small attack surface, further strengthens its defenses.

However, a significant concern arises from the output escaping, where only 24% of outputs are properly escaped. This indicates a potential risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not adequately sanitized before being displayed. While taint analysis found no issues, this could be due to the limited scope of the analysis or the absence of complex data flows susceptible to taint. The low number of entry points (1 shortcode) and the absence of unprotected ones are positive, but the unescaped output remains a notable weakness.

In conclusion, while the plugin avoids common critical vulnerabilities and has a clean history, the insufficient output escaping presents a tangible risk. Developers should prioritize addressing this issue to prevent potential XSS attacks. The plugin's strengths lie in its robust handling of SQL and its vulnerability-free past, but the output sanitization needs significant improvement to achieve a truly secure state.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

Unlimited Logo Carousel Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Unlimited Logo Carousel Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
37
12 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

24% escaped49 total outputs
Attack Surface

Unlimited Logo Carousel Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[ed-logo] inc\views.php:72
WordPress Hooks 16
actionadmin_enqueue_scriptsinc\logo-metabox.php:10
actionadd_meta_boxesinc\logo-metabox.php:28
actionsave_postinc\logo-metabox.php:126
actionadd_meta_boxesinc\meta-settings.php:17
actionadd_meta_boxesinc\meta-settings.php:118
actionadd_meta_boxesinc\meta-settings.php:300
actionadd_meta_boxesinc\meta-settings.php:340
actionadmin_initinc\options.php:4
actionadmin_menuinc\options.php:10
actioninitinc\unlimited-logo-carousel.php:56
filtermanage_edit-ed_logo_columnsinc\unlimited-logo-carousel.php:63
actionmanage_ed_logo_posts_custom_columninc\unlimited-logo-carousel.php:76
actionwp_enqueue_scriptsinc\views.php:3
actionwp_footerinc\views.php:103
actionadmin_enqueue_scriptsunlimited-logo-carousel.php:74
actionadmin_headunlimited-logo-carousel.php:78
Maintenance & Trust

Unlimited Logo Carousel Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedOct 15, 2019
PHP min version
Downloads22K

Community Trust

Rating60/100
Number of ratings4
Active installs600
Developer Profile

Unlimited Logo Carousel Developer Profile

aThemeArt Translations

4 plugins · 2K total installs

74
trust score
Avg Security Score
71/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Unlimited Logo Carousel

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/unlimited-logo-carousel/inc/css/logo_carousel-metabox.css/wp-content/plugins/unlimited-logo-carousel/inc/js/logo_carousel-metabox.js

HTML / DOM Fingerprints

CSS Classes
ed-logo-carousel-added-logo-carousel-metabox-listimage-previewed-pull-rightwdith-70wdith-30change-imageremove-image
Data Attributes
data-uploader-titledata-uploader-button-text
FAQ

Frequently Asked Questions about Unlimited Logo Carousel