Field notes
What happened to WP Logo Showcase Responsive Slider and Carousel?
WP Logo Showcase Responsive Slider and Carousel was removed from the WordPress.org directory in April 2026. Here's what's documented, what's separate from what, and what it means if your site still has its content.
If you're seeing [logoshowcase] on your WordPress site, or you remember installing WP Logo Showcase Responsive Slider and Carousel and can no longer find it on WordPress.org, this note lays out what's documented about the plugin's removal, without speculating about anything that isn't.
What happened?
WP Logo Showcase Responsive Slider and Carousel (plugin slug wp-logo-showcase-responsive-slider-slider) was removed from the WordPress.org Plugin Directory. According to WP Beacon's plugin record, the plugin was closed on WordPress.org on April 7, 2026, with the closure reason recorded as a security issue. Wordfence's plugin vulnerability record separately lists the plugin's software status as “Removed,” with approximately 30,000 active installs and 1,466,521 total downloads recorded.
WP Beacon's incident audit describes a broader incident involving multiple related plugins, with WP Logo Showcase Responsive Slider and Carousel listed among the affected plugins. On the underlying security issue: Patchstack's database records plugin versions 3.8.7 and earlier as vulnerable to an injected backdoor, with version 3.8.7.1 listed as the patched release, disclosed April 14, 2026. Wordfence's detailed record for the same issue identifies version 3.8.7 as affected and 3.8.7.1 as patched.
None of the source records establish who inserted the code, when it was first introduced, or why the directory removal happened on the specific date it did. This article does not speculate on any of that, and doesn't attempt to reconstruct the incident beyond what these four sources document; it reports what the cited records say and nothing more.
This was not the same vulnerability reported in 2023
It's worth being precise here, because the plugin also has an unrelated, earlier security record. Patchstack's 2023 database entry describes a separate Broken Access Control vulnerability affecting plugin versions 3.6 and earlier, with version 3.7 listed as the patched release. A historical WordPress.org support thread from around that time shows users reporting the issue and the developer stating it had been fixed.
That 2023 issue and the 2026 backdoor issue are documented as two separate, unrelated security records, affecting different version ranges, three years apart. The available sources do not establish any connection between them, and this article makes none. If your site only ever ran a version from 3.7 onward, the 2023 record does not describe that installation history. For the 2026 issue, Patchstack records versions 3.8.7 and earlier as vulnerable, while Wordfence identifies 3.8.7 as affected and 3.8.7.1 as patched.
Why removing a plugin can still leave a WordPress problem
Removing a plugin from the WordPress.org directory stops new installs and updates from that source. It does not reach into existing WordPress sites and remove anything. On a site where WP Logo Showcase was previously active, the legacy logo records, categories, media relationships, and any [logoshowcase] shortcodes it created can still be present in that site's database after the plugin is no longer being used, whether because it was deactivated, removed, or is simply no longer installable from the directory.
That's the continuity problem WP Logo Showcase's removal created for sites that had it: the plugin that knew how to read and render that content may no longer be available from the directory, but on a site where that content exists, it and the shortcode references pointing at it don't go anywhere on their own.
What happens to existing [logoshowcase] content
What a given site sees depends on its own history with the plugin, and not every outcome below will apply to every site. If the plugin is still installed and active, the display may still work, though unsupported. If the plugin has been deactivated or removed, a page that still contains the [logoshowcase] shortcode may show the raw shortcode text instead of a rendered display, since nothing is left to interpret it, though whether that happens depends on the specific page and theme. And in some cases, logo records and media may simply sit unused in the database with no active shortcode rendering them at all.
If you're trying to recreate that display manually, or you're evaluating what a replacement plugin would need to support, more detail is available in this site's replacement guide: WP Logo Showcase replacement guide
Where Logo Rescue fits
Plugin Lifeboat's Logo Rescue is built around read-only compatibility: it reads existing legacy logo records, their featured images, destination links, and category relationships directly, and displays them through the existing [logoshowcase] shortcode, without copying, rewriting, migrating, or deleting the original content. That design principle is shared across all of Plugin Lifeboat's products, not just this one, and is covered in more depth here: What does read-only compatibility mean?
In practice, that means a site that still has WP Logo Showcase content doesn't need to recreate its logo carousels by hand, and doesn't need to reactivate the original discontinued plugin to keep displaying that content: Logo Rescue
What Logo Rescue does NOT do
Logo Rescue is a compatibility and rescue tool, not a malware scanner or compromised-site cleanup utility. It does not clean, secure, or certify a site as free of the issues described in the security records above, and installing it does not tell you anything about whether a given site was affected by the 2026 incident or the unrelated 2023 issue. If you have reason to believe a site was compromised, that requires separate, dedicated security remediation, not a compatibility plugin, and not this one specifically.
What site owners should verify
Given what's documented, a site owner who used this plugin may want to independently check: whether the plugin is still installed and, if so, which version; whether that version falls in the affected range described by Patchstack and Wordfence for the 2026 backdoor issue (3.8.7 and earlier) or the unrelated 2023 issue (3.6 and earlier); and, if there's any concern about site security, working with a security professional or scanner rather than relying on a compatibility tool to answer that question. None of this article's sources, and nothing in Logo Rescue, substitutes for that kind of direct check.
Sources
- WP Beacon plugin record (closure date and reason)
- WP Beacon incident audit (broader multi-plugin incident)
- Wordfence plugin vulnerability record (removed status, install/download counts, 2026 affected/patched versions)
- Patchstack, 2026 backdoor vulnerability (≤ 3.8.7, patched 3.8.7.1, disclosed April 14, 2026)
- Patchstack, 2023 Broken Access Control vulnerability (≤ 3.6, patched 3.7)
- Historical WordPress.org support thread
