WP Bootstrap Carousel by IT Pixelz Security & Risk Analysis
wordpress.org/plugins/wp-bootstrap-carousel-by-it-pixelzBootstrap responsive carousel slider, just install in clicks and get ready your bootstrap slider for your website.
Is WP Bootstrap Carousel by IT Pixelz Safe to Use in 2026?
Generally Safe
Score 85/100WP Bootstrap Carousel by IT Pixelz has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-bootstrap-carousel-by-it-pixelz plugin v1.0 exhibits a mixed security posture. On one hand, the static analysis reveals no dangerous functions, no direct SQL queries (all prepared statements), no file operations, and no external HTTP requests, which are all positive indicators. The absence of known CVEs and vulnerability history further suggests a generally clean track record.
However, significant concerns arise from the output escaping and nonce/capability checks. With 100% of outputs unescaped, there is a high risk of Cross-Site Scripting (XSS) vulnerabilities, especially if the shortcode processes user-supplied data. The complete lack of nonce and capability checks across all identified entry points (even though the attack surface is currently small with only one shortcode) is a major security gap. If the shortcode's functionality allows for any state-changing operations or sensitive data display, it could be exploited without proper authorization or integrity checks.
In conclusion, while the plugin has strong foundations in avoiding common pitfalls like raw SQL and dangerous functions, the severe lack of output escaping and authorization mechanisms on its sole entry point presents a critical risk. The small attack surface is a mitigating factor, but the identified weaknesses are fundamental security oversights that need immediate attention.
Key Concerns
- 0% output escaping
- 0 capability checks on entry points
- 0 nonce checks on entry points
WP Bootstrap Carousel by IT Pixelz Security Vulnerabilities
WP Bootstrap Carousel by IT Pixelz Code Analysis
Output Escaping
WP Bootstrap Carousel by IT Pixelz Attack Surface
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
WP Bootstrap Carousel by IT Pixelz Maintenance & Trust
Maintenance Signals
Community Trust
WP Bootstrap Carousel by IT Pixelz Alternatives
Bootstrap Slider By themescode
bootstrap-slider-by-themescode
Twitter Bootstrap based professional WordPress carousel slider plugin on click installation.use the shortcode where want to use
TC Bootstrap Carousel
tc-bootstrap-carousel
Twitter Bootstrap based professional WordPress carousel plugin on click installation.use the shortcode where want to use
Slider Bootstrap Carousel
slider-bootstrap-carousel
Slider Bootstrap Carousel 4 for WordPress with image link and categories.
Advanced Bootstrap Carousel
advanced-bootstrap-carousel
Advanced Bootstrap Carousel is a light weighted responsive slider plugin.
Fade Slider
fade-slider
A modern, responsive Bootstrap 5.3 carousel slider plugin with smooth fade/slide animations, works perfectly on all devices and themes.
WP Bootstrap Carousel by IT Pixelz Developer Profile
4 plugins · 590 total installs
How We Detect WP Bootstrap Carousel by IT Pixelz
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-bootstrap-carousel-by-it-pixelz/css/style.cssHTML / DOM Fingerprints
wpbc_carouseldata-ridedata-slide-todata-slide<div class="item"><div class="carousel-caption">