Widgets Avalanche for Ecwid Security & Risk Analysis

wordpress.org/plugins/ecwid-widgets-avalanche

Grab your Ecwid products and categories into a variety of WordPress widgets, including a slider, a popup, an accordion, an autosuggest, a sortable tab …

30 active installs v1.6.1 PHP + WP 4.1+ Updated Dec 1, 2015
e-commerceecommerceecwidecwid-slideronline-store
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Widgets Avalanche for Ecwid Safe to Use in 2026?

Generally Safe

Score 85/100

Widgets Avalanche for Ecwid has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The "ecwid-widgets-avalanche" plugin v1.6.1 exhibits a strong security posture based on the provided static analysis. The absence of identified AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface. Furthermore, the code demonstrates good practices by using prepared statements for all SQL queries and implementing a nonce check. The presence of capability checks also suggests an effort to control access to certain functionalities. There are no known vulnerabilities (CVEs) associated with this plugin, which further reinforces its current security standing.

Key Concerns

  • Output escaping is only 55% proper
  • Capability checks are only 2
Vulnerabilities
None known

Widgets Avalanche for Ecwid Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Widgets Avalanche for Ecwid Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
82
102 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
4
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

55% escaped184 total outputs
Attack Surface

Widgets Avalanche for Ecwid Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 29
actionadmin_footeradmin\authentication.php:19
actionadmin_enqueue_scriptsadmin\enqueue.php:14
actioninitadmin\notices.php:14
actionadmin_noticesadmin\notices.php:19
actioninitadmin\settings.php:16
actionadmin_menuadmin\settings.php:26
actionadmin_initadmin\settings.php:29
actionsjf_et_admin_noticesadmin\settings.php:32
actionadmin_footeradmin\settings.php:35
actionplugins_loadedinc\ajax.php:16
actioninitinc\ajax.php:30
actionwp_enqueue_scriptsinc\enqueue.php:14
actionplugins_loadedinc\feed.php:16
actionwp_headersinc\feed.php:53
actioninitinc\feed.php:56
actionwidgets_initinc\widgets\accordion.php:14
filterSJF_Ecwid_Admin_Documentation_get_docsinc\widgets\accordion.php:30
actionwidgets_initinc\widgets\autosuggest.php:14
filterSJF_Ecwid_Admin_Documentation_get_docsinc\widgets\autosuggest.php:30
actionwidgets_initinc\widgets\popup.php:14
filterSJF_Ecwid_Admin_Documentation_get_docsinc\widgets\popup.php:33
actionwidgets_initinc\widgets\rss.php:14
filterSJF_Ecwid_Admin_Documentation_get_docsinc\widgets\rss.php:30
actionwidgets_initinc\widgets\slider.php:14
actionwp_enqueue_scriptsinc\widgets\slider.php:28
filterSJF_Ecwid_Admin_Documentation_get_docsinc\widgets\slider.php:30
actionwp_footerinc\widgets\slider.php:317
actionwidgets_initinc\widgets\sortable.php:14
filterSJF_Ecwid_Admin_Documentation_get_docsinc\widgets\sortable.php:28
Maintenance & Trust

Widgets Avalanche for Ecwid Maintenance & Trust

Maintenance Signals

WordPress version tested4.3.34
Last updatedDec 1, 2015
PHP min version
Downloads6K

Community Trust

Rating40/100
Number of ratings4
Active installs30
Developer Profile

Widgets Avalanche for Ecwid Developer Profile

Scott Fennell

4 plugins · 120 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Widgets Avalanche for Ecwid

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ecwid-widgets-avalanche/inc/css/styles.css/wp-content/plugins/ecwid-widgets-avalanche/admin/css/styles.css/wp-content/plugins/ecwid-widgets-avalanche/inc/js/scripts.js/wp-content/plugins/ecwid-widgets-avalanche/inc/js/jquery.bxslider.min.js/wp-content/plugins/ecwid-widgets-avalanche/inc/js/jquery.tablesorter.min.js
Script Paths
/wp-content/plugins/ecwid-widgets-avalanche/inc/js/scripts.js/wp-content/plugins/ecwid-widgets-avalanche/inc/js/jquery.bxslider.min.js/wp-content/plugins/ecwid-widgets-avalanche/inc/js/jquery.tablesorter.min.js
Version Parameters
ecwid-widgets-avalanche/inc/css/styles.css?ver=ecwid-widgets-avalanche/admin/css/styles.css?ver=ecwid-widgets-avalanche/inc/js/scripts.js?ver=ecwid-widgets-avalanche/inc/js/jquery.bxslider.min.js?ver=ecwid-widgets-avalanche/inc/js/jquery.tablesorter.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
sjf-et-accordion-titlesjf-et-accordion-wrapper
Data Attributes
data-ecwid-id
JS Globals
SJF_Ecwid_HelpersSJF_ET_Accordion
Shortcode Output
[sjf_et_accordion]
FAQ

Frequently Asked Questions about Widgets Avalanche for Ecwid