
iThemes Exchange – Custom Loop Add-on Security & Risk Analysis
wordpress.org/plugins/exchange-addon-custom-loopCreate a custom loop for your product store pages, add selections, grid/list view and more.
Is iThemes Exchange – Custom Loop Add-on Safe to Use in 2026?
Generally Safe
Score 85/100iThemes Exchange – Custom Loop Add-on has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "exchange-addon-custom-loop" v1.0.14 exhibits a strong security posture based on the provided static analysis. There are no identified entry points such as AJAX handlers, REST API routes, shortcodes, or cron events that are accessible without authentication checks, significantly reducing the potential attack surface. Furthermore, the absence of dangerous functions, file operations, external HTTP requests, and known vulnerability history suggests diligent development practices and a lack of historically exploited weaknesses.
However, a significant concern arises from the low percentage of properly escaped output (8%). This indicates a potential risk of cross-site scripting (XSS) vulnerabilities, as user-supplied data may not be adequately sanitized before being displayed to users. While no taint analysis flows with unsanitized paths were detected, the low output escaping rate warrants caution. The lack of nonce and capability checks, while not directly exploited in this analysis, could become a vector if new entry points were introduced or if the existing code is extended without proper security considerations.
In conclusion, the plugin demonstrates excellent foundational security with a minimal attack surface and a clean vulnerability history. The primary weakness lies in the insufficient output escaping, which needs immediate attention to mitigate XSS risks. The absence of other common vulnerability types is a positive sign, but the identified output escaping issue prevents a perfect score.
Key Concerns
- Low output escaping percentage
iThemes Exchange – Custom Loop Add-on Security Vulnerabilities
iThemes Exchange – Custom Loop Add-on Code Analysis
Output Escaping
iThemes Exchange – Custom Loop Add-on Attack Surface
WordPress Hooks 11
Maintenance & Trust
iThemes Exchange – Custom Loop Add-on Maintenance & Trust
Maintenance Signals
Community Trust
iThemes Exchange – Custom Loop Add-on Alternatives
YITH WooCommerce Product Add-Ons
yith-woocommerce-product-add-ons
Increase average order value by letting your customers purchase additional options on your products.
PowerPack Lite for Beaver Builder
powerpack-addon-for-beaver-builder
PowerPack Lite for Beaver Builder extends Beaver Builder with custom options, unique modules and templates.
Xpro Addons For Beaver Builder – Lite
xpro-addons-beaver-builder-elementor
Xpro Addons for Beaver Builder – Lite is a simple drag-and-drop creative module pack that lets you create stunning websites.
Conditional Logic for Woo Product Add-ons
conditional-logic-for-woo-product-add-ons
Show or hide certain fields of the WooCommerce Product Addons based on other fields' values or states (eg, show field X when option Y is selected …
Image Carousel Addon for Beaver Builder
image-carousel-addon-for-beaver-builder
A quick and easy responsive image carousel module for Beaver Builder.
iThemes Exchange – Custom Loop Add-on Developer Profile
1 plugin · 10 total installs
How We Detect iThemes Exchange – Custom Loop Add-on
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/exchange-addon-custom-loop/lib/assets/custom-loop50px.png/wp-content/plugins/exchange-addon-custom-loop/js/admin_scripts.jsexchange-addon-custom-loop/js/admin_scripts.js?ver=exchange-addon-custom-loop/css/admin_style.css?ver=HTML / DOM Fingerprints
exchange-custom-loop-gridexchange-custom-loop-listdata-custom-loop-viewdata-custom-loop-columnsdata-custom-loop-paddingdata-custom-loop-viewportit_custom_loop_admin_params[it_exchange_custom_loop][it-exchange-custom-loop]