Free WooCommerce Products Slider/Carousel Pro Security & Risk Analysis

wordpress.org/plugins/woo-products-slider-pro

Display WooCommerce Products in a Carousel / Slider. Show Top Rated, Best Selling, ON Sale, Featured, Recently Viewed Products With Category Filter.

2K active installs v2.0.1 PHP 8.0+ WP 5.6+ Updated Dec 16, 2025
advanced-sliderproduct-carouselresponsive-product-sliderslick-sliderwoo-product-carousel
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Free WooCommerce Products Slider/Carousel Pro Safe to Use in 2026?

Generally Safe

Score 100/100

Free WooCommerce Products Slider/Carousel Pro has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The plugin "woo-products-slider-pro" v2.0.1 presents a mixed security posture. On the positive side, the plugin demonstrates excellent security practices by utilizing prepared statements for all SQL queries and ensuring a high percentage of output is properly escaped. Furthermore, the absence of known vulnerabilities in its history and a lack of dangerous functions or file operations are strong indicators of good development hygiene. However, a significant concern arises from the attack surface, specifically the presence of three AJAX handlers that lack authentication checks. This creates a direct entry point for unauthenticated users to interact with potentially sensitive functionality, which is a notable weakness.

The taint analysis shows no identified vulnerabilities, which is a positive sign, but this is also based on zero flows analyzed, making it a less robust indicator. The lack of capability checks on the AJAX handlers, coupled with the absence of nonce checks on these same handlers, exacerbates the risk associated with the exposed AJAX endpoints. While the plugin is free of known CVEs, the unauthenticated AJAX handlers represent a significant potential vulnerability that could be exploited if the functionality they expose is not inherently benign.

In conclusion, "woo-products-slider-pro" v2.0.1 has several strong security features, particularly in its handling of SQL and output. However, the presence of unprotected AJAX endpoints is a critical flaw that significantly elevates the risk profile. This needs immediate attention to ensure the plugin's security is robust against potential unauthenticated attacks.

Key Concerns

  • AJAX handlers without auth checks
  • AJAX handlers without nonce checks
  • AJAX handlers without capability checks
Vulnerabilities
None known

Free WooCommerce Products Slider/Carousel Pro Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Free WooCommerce Products Slider/Carousel Pro Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
209 escaped
Nonce Checks
3
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

98% escaped213 total outputs
Attack Surface
3 unprotected

Free WooCommerce Products Slider/Carousel Pro Attack Surface

Entry Points3
Unprotected3

AJAX Handlers 3

authwp_ajax_woopspro_get_woo_products_option_htmlincludes\class-woo-products-slider-pro.php:123
authwp_ajax_woopspro_get_woo_skus_option_htmlincludes\class-woo-products-slider-pro.php:124
authwp_ajax_woopspro_get_product_attributes_termsincludes\class-woo-products-slider-pro.php:125
WordPress Hooks 8
actionadmin_enqueue_scriptsincludes\class-woo-products-slider-pro.php:115
actionadmin_enqueue_scriptsincludes\class-woo-products-slider-pro.php:116
actionadmin_menuincludes\class-woo-products-slider-pro.php:120
actionadmin_noticesincludes\class-woo-products-slider-pro.php:121
actionbefore_woocommerce_initincludes\class-woo-products-slider-pro.php:127
actionwp_enqueue_scriptsincludes\class-woo-products-slider-pro.php:140
actionwp_enqueue_scriptsincludes\class-woo-products-slider-pro.php:141
actiontemplate_redirectincludes\class-woo-products-slider-pro.php:143
Maintenance & Trust

Free WooCommerce Products Slider/Carousel Pro Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 16, 2025
PHP min version8.0
Downloads55K

Community Trust

Rating94/100
Number of ratings17
Active installs2K
Developer Profile

Free WooCommerce Products Slider/Carousel Pro Developer Profile

Sajjad Hossain Sagor

32 plugins · 10K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
139 days
View full developer profile
Detection Fingerprints

How We Detect Free WooCommerce Products Slider/Carousel Pro

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woo-products-slider-pro/admin/css/admin.css/wp-content/plugins/woo-products-slider-pro/admin/js/admin.js
Script Paths
/wp-content/plugins/woo-products-slider-pro/admin/js/admin.js
Version Parameters
woo-products-slider-pro/admin/css/admin.css?ver=woo-products-slider-pro/admin/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
woopspro-slider-carouselwoopspro-container
Data Attributes
data-woopspro-iddata-woopspro-settings
JS Globals
WooProductsSliderPro
REST Endpoints
/wp-json/woopspro/v1/get_products
Shortcode Output
[woopspro_products_slider]
FAQ

Frequently Asked Questions about Free WooCommerce Products Slider/Carousel Pro