
WP Carousel Security & Risk Analysis
wordpress.org/plugins/wp-carouselWP Carousel is a plugin that allows you to add a carousel with posts, categories, tags, authors, pages, and much more. It is easy to install and use.
Is WP Carousel Safe to Use in 2026?
Generally Safe
Score 85/100WP Carousel has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
WP Carousel v1.1 presents a mixed security posture. On the positive side, there are no known CVEs associated with this plugin, and the static analysis indicates that the single SQL query uses prepared statements, which is a strong security practice. Furthermore, the plugin's attack surface is limited, with no unprotected AJAX handlers or REST API routes. However, significant concerns arise from the code analysis. The high number of 'dangerous functions' like unserialize and create_function, coupled with a complete lack of output escaping (0% properly escaped), creates a substantial risk. The taint analysis also reveals multiple flows with unsanitized paths, although thankfully, none are classified as critical or high severity. The absence of nonce checks is another critical weakness, especially concerning given the presence of shortcodes, which can be triggered by users and potentially manipulated.
Key Concerns
- No output escaping
- High count of dangerous functions
- Unsanitized paths in taint flows
- No nonce checks
- Bundled library (TinyMCE)
WP Carousel Security Vulnerabilities
WP Carousel Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Carousel Attack Surface
Shortcodes 1
WordPress Hooks 23
Maintenance & Trust
WP Carousel Maintenance & Trust
Maintenance Signals
Community Trust
WP Carousel Alternatives
Newpost Catch
newpost-catch
Thumbnails in new articles setting widget.
Share Theme Plugin
share-theme
This is a extension for Share Theme
WP Shortcodes Plugin — Shortcodes Ultimate
shortcodes-ultimate
A comprehensive collection of visual components for your site
Recent Posts Widget With Thumbnails
recent-posts-widget-with-thumbnails
List the most recent posts with post titles, thumbnails, excerpts, authors, categories, dates and more!
Post Grid
post-grid
Post Grid is a powerful WordPress plugin for creating customizable post grid layouts with advanced query options, allowing users to display posts dyna …
WP Carousel Developer Profile
3 plugins · 100 total installs
How We Detect WP Carousel
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-carousel/css/style.css/wp-content/plugins/wp-carousel/js/jquery.jcarousel.min.js/wp-content/plugins/wp-carousel/js/wp-carousel.js/wp-content/plugins/wp-carousel/js/jquery.jcarousel.min.js/wp-content/plugins/wp-carousel/js/wp-carousel.jswp-carousel/css/style.css?ver=wp-carousel/js/jquery.jcarousel.min.js?ver=wp-carousel/js/wp-carousel.js?ver=HTML / DOM Fingerprints
wp-carousel-containerwp-carousel-items-containerwp-carousel-pagination-container<!-- WP Carousel --><!-- WP Carousel Carousel -->data-wp-carousel-optionswp_carousel_objects[wp_carousel[carousel_wp