WP Bootstrap Carousel by IT Pixelz Security & Risk Analysis

wordpress.org/plugins/wp-bootstrap-carousel-by-it-pixelz

Bootstrap responsive carousel slider, just install in clicks and get ready your bootstrap slider for your website.

50 active installs v1.0 PHP + WP 3.0.1+ Updated Apr 11, 2023
boostrap-carouselbootstrap-carousel-sliderbootstrap-responsive-sliderbootstrap-slideritpixelz
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Bootstrap Carousel by IT Pixelz Safe to Use in 2026?

Generally Safe

Score 85/100

WP Bootstrap Carousel by IT Pixelz has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The wp-bootstrap-carousel-by-it-pixelz plugin v1.0 exhibits a mixed security posture. On one hand, the static analysis reveals no dangerous functions, no direct SQL queries (all prepared statements), no file operations, and no external HTTP requests, which are all positive indicators. The absence of known CVEs and vulnerability history further suggests a generally clean track record.

However, significant concerns arise from the output escaping and nonce/capability checks. With 100% of outputs unescaped, there is a high risk of Cross-Site Scripting (XSS) vulnerabilities, especially if the shortcode processes user-supplied data. The complete lack of nonce and capability checks across all identified entry points (even though the attack surface is currently small with only one shortcode) is a major security gap. If the shortcode's functionality allows for any state-changing operations or sensitive data display, it could be exploited without proper authorization or integrity checks.

In conclusion, while the plugin has strong foundations in avoiding common pitfalls like raw SQL and dangerous functions, the severe lack of output escaping and authorization mechanisms on its sole entry point presents a critical risk. The small attack surface is a mitigating factor, but the identified weaknesses are fundamental security oversights that need immediate attention.

Key Concerns

  • 0% output escaping
  • 0 capability checks on entry points
  • 0 nonce checks on entry points
Vulnerabilities
None known

WP Bootstrap Carousel by IT Pixelz Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP Bootstrap Carousel by IT Pixelz Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped8 total outputs
Attack Surface

WP Bootstrap Carousel by IT Pixelz Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[show_bootstrap_carousel] wp-bootstrap-carousel-itpixelz.php:231
WordPress Hooks 7
actionwp_enqueue_scriptswp-bootstrap-carousel-itpixelz.php:28
actioninitwp-bootstrap-carousel-itpixelz.php:34
actioninitwp-bootstrap-carousel-itpixelz.php:105
actionadmin_menuwp-bootstrap-carousel-itpixelz.php:107
actionadmin_initwp-bootstrap-carousel-itpixelz.php:117
actionwp_enqueue_scriptswp-bootstrap-carousel-itpixelz.php:128
actionwidgets_initwp-bootstrap-carousel-itpixelz.php:256
Maintenance & Trust

WP Bootstrap Carousel by IT Pixelz Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedApr 11, 2023
PHP min version
Downloads5K

Community Trust

Rating74/100
Number of ratings3
Active installs50
Developer Profile

WP Bootstrap Carousel by IT Pixelz Developer Profile

Umar Draz

4 plugins · 590 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP Bootstrap Carousel by IT Pixelz

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-bootstrap-carousel-by-it-pixelz/css/style.css

HTML / DOM Fingerprints

CSS Classes
wpbc_carousel
Data Attributes
data-ridedata-slide-todata-slide
Shortcode Output
<div class="item"><div class="carousel-caption">
FAQ

Frequently Asked Questions about WP Bootstrap Carousel by IT Pixelz