Auglio Try-on Mirror Security & Risk Analysis

wordpress.org/plugins/auglio-try-on-mirror

The Virtual mirror allows the shoppers to experience all decorative cosmetics, sunglasses, contact lenses, jewelry, clothing and apparel using their …

50 active installs v1.0.1 PHP 5.4+ WP 4.7+ Updated Mar 27, 2024
blusheseye-shadowseyelinerslipsticksvirtual-mirror
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Auglio Try-on Mirror Safe to Use in 2026?

Generally Safe

Score 85/100

Auglio Try-on Mirror has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "auglio-try-on-mirror" plugin v1.0.1 exhibits a generally good security posture based on the provided static analysis. The plugin has no known vulnerabilities (CVEs), and its code signals indicate a responsible development approach, with all SQL queries using prepared statements and a reasonable percentage of output being properly escaped. The presence of nonce and capability checks suggests an understanding of basic WordPress security mechanisms.

However, there are areas that warrant attention. The static analysis reveals a taint flow with an unsanitized path, which, although not classified as critical or high severity in this report, represents a potential avenue for exploitation. The plugin also makes two external HTTP requests, and without further context, it's difficult to assess the security implications of these calls. The lack of reported vulnerabilities in its history could indicate either a very well-written plugin, or simply a lack of thorough public auditing or exploitation attempts, making it crucial to remain vigilant.

In conclusion, while the plugin demonstrates strengths in its secure handling of SQL and inclusion of basic security checks, the identified unsanitized path in the taint analysis is a specific concern that requires investigation. The external HTTP requests also present a minor point of caution. Overall, the plugin appears to have a relatively low risk profile, but the identified data flow issue should be addressed to further solidify its security.

Key Concerns

  • Flow with unsanitized path detected
  • External HTTP requests made
  • Output escaping not fully implemented
Vulnerabilities
None known

Auglio Try-on Mirror Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Auglio Try-on Mirror Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
34
109 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

76% escaped143 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

3 flows1 with unsanitized paths
product_feed_response (src\class-auglio-try-on-mirror-admin.php:251)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Auglio Try-on Mirror Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 13
actionplugins_loadedauglio-try-on-mirror.php:116
actionadmin_initauglio-try-on-mirror.php:155
actionadmin_noticesauglio-try-on-mirror.php:167
actioninitauglio-try-on-mirror.php:176
actioninitauglio-try-on-mirror.php:193
actionbefore_woocommerce_initauglio-try-on-mirror.php:244
actionadmin_menusrc\class-auglio-try-on-mirror-admin.php:24
actionadd_meta_boxessrc\class-auglio-try-on-mirror-admin.php:26
actionadmin_post_auglio_api_login_responsesrc\class-auglio-try-on-mirror-admin.php:28
actionadmin_post_auglio_api_logout_responsesrc\class-auglio-try-on-mirror-admin.php:29
actionadmin_post_auglio_settings_responsesrc\class-auglio-try-on-mirror-admin.php:30
actionadmin_post_auglio_product_feed_responsesrc\class-auglio-try-on-mirror-admin.php:31
actionwp_enqueue_scriptssrc\class-auglio-try-on-mirror.php:72
Maintenance & Trust

Auglio Try-on Mirror Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedMar 27, 2024
PHP min version5.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs50
Developer Profile

Auglio Try-on Mirror Developer Profile

auglio

1 plugin · 50 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Auglio Try-on Mirror

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/auglio-try-on-mirror/build/auglio-try-on-mirror.js/wp-content/plugins/auglio-try-on-mirror/build/auglio-try-on-mirror.css
Version Parameters
auglio-try-on-mirror/build/auglio-try-on-mirror.js?ver=auglio-try-on-mirror/build/auglio-try-on-mirror.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Auglio Try-on Mirror