Bizzswatches – Variation Swatches for WooCommerce Security & Risk Analysis

wordpress.org/plugins/bizzswatches

Beautiful color, image, and button variation swatches for WooCommerce product attributes. Transform your product variations into stunning swatches.

0 active installs v1.0.1 PHP 8.0+ WP 6.2+ Updated Feb 22, 2026
color-swatchesimage-swatchesproduct-attributesvariation-swatcheswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Bizzswatches – Variation Swatches for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Bizzswatches – Variation Swatches for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "bizzswatches" v1.0.1 plugin exhibits a generally strong security posture based on the provided static analysis. A significant strength is the complete absence of unauthenticated AJAX handlers, as all 8 entry points have capability checks. Furthermore, the plugin demonstrates good practices with a high percentage of properly escaped outputs and the use of prepared statements for the majority of its SQL queries. The lack of known CVEs and recorded vulnerabilities also suggests a history of responsible development or minimal exposure.

Despite the positive indicators, there are areas of concern highlighted by the taint analysis. Specifically, two flows with unsanitized paths were identified as having high severity. This suggests that user-supplied data might be reaching sensitive functions or operations without adequate cleaning, potentially leading to vulnerabilities like path traversal or information disclosure, even if direct SQL injection or cross-site scripting isn't immediately apparent from the provided SQL and output escaping metrics. The presence of external HTTP requests also warrants careful monitoring, as these can sometimes be leveraged in exploits if not properly validated.

Key Concerns

  • High severity unsanitized taint flows
  • External HTTP requests present
Vulnerabilities
None known

Bizzswatches – Variation Swatches for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Bizzswatches – Variation Swatches for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
2 prepared
Unescaped Output
25
765 escaped
Nonce Checks
11
Capability Checks
10
File Operations
0
External Requests
4
Bundled Libraries
0

SQL Query Safety

67% prepared3 total queries

Output Escaping

97% escaped790 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

7 flows2 with unsanitized paths
ajax_save_options (admin\options-framework\class-bizzplugin-framework.php:462)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Bizzswatches – Variation Swatches for WooCommerce Attack Surface

Entry Points8
Unprotected0

AJAX Handlers 8

authwp_ajax_bizzplugin_save_optionsadmin\options-framework\class-bizzplugin-framework.php:116
authwp_ajax_bizzplugin_reset_sectionadmin\options-framework\class-bizzplugin-framework.php:117
authwp_ajax_bizzplugin_reset_alladmin\options-framework\class-bizzplugin-framework.php:118
authwp_ajax_bizzplugin_test_webhookadmin\options-framework\class-bizzplugin-framework.php:119
authwp_ajax_bizzplugin_install_pluginadmin\options-framework\class-bizzplugin-framework.php:120
authwp_ajax_bizzplugin_activate_pluginadmin\options-framework\class-bizzplugin-framework.php:121
authwp_ajax_bizzplugin_generate_api_keyadmin\options-framework\class-bizzplugin-framework.php:122
authwp_ajax_bizzplugin_delete_api_keyadmin\options-framework\class-bizzplugin-framework.php:123
WordPress Hooks 35
actionadmin_enqueue_scriptsadmin\admin-loader.php:58
actionadmin_menuadmin\admin-loader.php:60
filterplugins_api_resultadmin\admin-loader.php:61
actionadmin_menuadmin\class-bizzswatches-admin.php:86
actionadmin_enqueue_scriptsadmin\class-bizzswatches-admin.php:87
filterplugin_row_metaadmin\class-bizzswatches-admin.php:89
filterproduct_attributes_type_selectoradmin\class-bizzswatches-admin.php:90
actionwoocommerce_product_option_termsadmin\class-bizzswatches-admin.php:91
actionwoocommerce_attribute_addedadmin\class-bizzswatches-admin.php:93
actionwoocommerce_attribute_updatedadmin\class-bizzswatches-admin.php:94
actionwoocommerce_attribute_deletedadmin\class-bizzswatches-admin.php:95
actionadmin_initadmin\class-bizzswatches-attribute-meta.php:58
actionadmin_initadmin\class-bizzswatches-getting-started.php:55
filterwoocommerce_product_data_tabsadmin\class-bizzswatches-product-panel.php:55
actionwoocommerce_product_data_panelsadmin\class-bizzswatches-product-panel.php:56
actionwoocommerce_process_product_metaadmin\class-bizzswatches-product-panel.php:57
actioninitadmin\framework-loader.php:66
actionadmin_enqueue_scriptsadmin\options-framework\class-bizzplugin-framework.php:115
actionrest_api_initadmin\options-framework\class-bizzplugin-framework.php:124
actionadd_meta_boxesadmin\options-framework\class-bizzplugin-metabox.php:110
actionsave_postadmin\options-framework\class-bizzplugin-metabox.php:111
actionadmin_enqueue_scriptsadmin\options-framework\class-bizzplugin-metabox.php:112
actionadmin_menuadmin\options-framework\class-bizzplugin-panel.php:189
actionadmin_body_classadmin\options-framework\class-bizzplugin-panel.php:190
actionadmin_enqueue_scriptsadmin\options-framework\includes\class-setup-wizard.php:147
actionadmin_initadmin\options-framework\includes\class-setup-wizard.php:183
actionbizzplugin_options_savedadmin\options-framework\includes\class-webhook-handler.php:46
actionplugins_loadedadmin\options-framework\options-loader.php:36
actionadmin_noticesbizzswatches.php:94
actionplugins_loadedbizzswatches.php:108
actionbefore_woocommerce_initbizzswatches.php:120
actioninitincludes\class-bizzswatches.php:98
actionwp_enqueue_scriptspublic\class-bizzswatches-frontend.php:67
filterbody_classpublic\class-bizzswatches-frontend.php:68
filterwoocommerce_dropdown_variation_attribute_options_htmlpublic\class-bizzswatches-swatches-display.php:56
Maintenance & Trust

Bizzswatches – Variation Swatches for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 22, 2026
PHP min version8.0
Downloads169

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Bizzswatches – Variation Swatches for WooCommerce Developer Profile

Saiful Islam

12 plugins · 20K total installs

75
trust score
Avg Security Score
94/100
Avg Patch Time
116 days
View full developer profile
Detection Fingerprints

How We Detect Bizzswatches – Variation Swatches for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bizzswatches/assets/css/getting-started.css
Version Parameters
bizzswatches/assets/css/getting-started.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Bizzswatches – Variation Swatches for WooCommerce