Product carousel for visual composer Security & Risk Analysis

wordpress.org/plugins/woo-product-carousel-2

Woocommerce product slider Addons for Visual Composer. To create amazing product carousel/slider this plugin will help you.

0 active installs v1.0.0 PHP + WP 3.0.1+ Updated Jul 18, 2017
vc-addonsvc-extensionsvisual-composervisual-composer-addonswoocommerce-product-slider
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Product carousel for visual composer Safe to Use in 2026?

Generally Safe

Score 85/100

Product carousel for visual composer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The "woo-product-carousel-2" v1.0.0 plugin exhibits a mixed security posture. On the positive side, it has no recorded vulnerabilities in its history and demonstrates good practice by using prepared statements for all SQL queries. The attack surface is also relatively small, with only two shortcodes identified as entry points and no unprotected handlers or routes. The absence of dangerous functions, file operations, and external HTTP requests (beyond one noted, which could be benign) further suggests a cautious approach to code development.

However, significant concerns arise from the static analysis. The most glaring issue is that 100% of the nine identified output locations are not properly escaped. This presents a high risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious code could be injected and executed in the user's browser. Additionally, the plugin lacks nonce checks and capability checks, meaning that actions triggered by its entry points might not be sufficiently authenticated or authorized, potentially allowing unauthorized users to perform actions or access sensitive data.

Given the lack of historical vulnerabilities, it's possible that the current version has remained undetected or that the identified code issues haven't been exploited in practice. However, the unescaped output and lack of authentication checks are fundamental security flaws that create a significant risk. While the plugin has strengths in its SQL handling and lack of historical issues, the critical weaknesses in output escaping and authentication necessitate caution.

Key Concerns

  • 100% of outputs not properly escaped
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

Product carousel for visual composer Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Product carousel for visual composer Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
9
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

0% escaped9 total outputs
Attack Surface

Product carousel for visual composer Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[d_category_slider] includes\shortcode\category_carousel.php:22
[d_featured_slider] includes\shortcode\featured_product.php:32
WordPress Hooks 13
actionadmin_menuadmin\class-wc_product_carousel-admin.php:106
actionadmin_initadmin\class-wc_product_carousel-admin.php:114
actionadmin_menuadmin\class-wp-license-manager-client.php:88
actionadmin_initadmin\class-wp-license-manager-client.php:89
actionadmin_noticesadmin\class-wp-license-manager-client.php:91
filterpre_set_site_transient_update_themesadmin\class-wp-license-manager-client.php:94
filterpre_set_site_transient_update_pluginsadmin\class-wp-license-manager-client.php:97
filterplugins_apiadmin\class-wp-license-manager-client.php:99
actionplugins_loadedincludes\class-wc_product_carousel.php:142
actionadmin_enqueue_scriptsincludes\class-wc_product_carousel.php:157
actionadmin_enqueue_scriptsincludes\class-wc_product_carousel.php:158
actionwp_enqueue_scriptsincludes\class-wc_product_carousel.php:173
actionwp_enqueue_scriptsincludes\class-wc_product_carousel.php:174
Maintenance & Trust

Product carousel for visual composer Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.0
Last updatedJul 18, 2017
PHP min version
Downloads2K

Community Trust

Rating20/100
Number of ratings1
Active installs0
Developer Profile

Product carousel for visual composer Developer Profile

designas

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Product carousel for visual composer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woo-product-carousel-2/admin/css/wc_product_carousel-admin.css/wp-content/plugins/woo-product-carousel-2/admin/js/wc_product_carousel-admin.js
Version Parameters
wc_product_carousel-adminwc_product_carousel-admin

HTML / DOM Fingerprints

CSS Classes
wc-product-carousel-admin-wrap
FAQ

Frequently Asked Questions about Product carousel for visual composer