
360 Spin For Woocommerce Security & Risk Analysis
wordpress.org/plugins/glo3dapp-woospinWith a push of a button of any smartphone or professional camera, capture, edit, share and embed 360° photo of any product to your woocommerce online …
Is 360 Spin For Woocommerce Safe to Use in 2026?
Generally Safe
Score 85/100360 Spin For Woocommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The glo3dapp-woospin plugin v1.2.0 exhibits a generally good security posture based on the provided static analysis. It has a limited attack surface with only two AJAX handlers, and importantly, these entry points appear to be protected by nonces and capability checks, indicating good practice in preventing unauthorized access and CSRF attacks. The complete absence of raw SQL queries and the use of prepared statements for all database interactions is a significant strength, mitigating SQL injection risks. Taint analysis also shows no critical or high severity vulnerabilities, suggesting that user-supplied data is not being mishandled in ways that could lead to serious security issues.
However, a notable concern is the output escaping. With 47% of outputs properly escaped, a significant portion (53%) remains unescaped. This could open the door to Cross-Site Scripting (XSS) vulnerabilities if user-controlled data is reflected directly in the output without proper sanitization. While the vulnerability history shows no known CVEs, which is positive, the lack of historical data could also mean this plugin hasn't been extensively scrutinized or tested in the past. The presence of file operations without specific details is also a minor point of interest that warrants further investigation in a real-world scenario, though it's not flagged as inherently dangerous here.
In conclusion, the plugin demonstrates strong foundational security practices, particularly concerning SQL injection and access control. The primary area of concern is the incomplete output escaping, which presents a potential XSS risk. The absence of past vulnerabilities is a good sign, but it's crucial to ensure ongoing security diligence, especially regarding the identified output escaping deficiency. The plugin's overall risk is assessed as moderate due to the potential for XSS.
Key Concerns
- Output escaping is only 47% proper
360 Spin For Woocommerce Security Vulnerabilities
360 Spin For Woocommerce Code Analysis
Output Escaping
Data Flow Analysis
360 Spin For Woocommerce Attack Surface
AJAX Handlers 2
WordPress Hooks 5
Maintenance & Trust
360 Spin For Woocommerce Maintenance & Trust
Maintenance Signals
Community Trust
360 Spin For Woocommerce Alternatives
Glo3D
glo3d
With a push of a button of any smartphone or professional camera, capture, edit, share and embed 360° photo of any product to your online store or web …
Imajize
imajize
Imajize enables you to easily embed a 360° product spin into any Wordpress post or WooCommerce product by simply pasting an embed link.
360 Generator
pg-360-generator
Easy way to make interactive 360° from set of photos ,also provides many options like size control , color /light control and filters, custom cursor s …
360 Spin For Woocommerce Developer Profile
2 plugins · 20 total installs
How We Detect 360 Spin For Woocommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/glo3dapp-woospin/assets/jquery.modal.min.css/wp-content/plugins/glo3dapp-woospin/assets/glo3d.css/wp-content/plugins/glo3dapp-woospin/assets/jquery.modal.min.js/wp-content/plugins/glo3dapp-woospin/functions.js/wp-content/plugins/glo3dapp-woospin/assets/glo3d_site.js/wp-content/plugins/glo3dapp-woospin/assets/360-spin.svg/wp-content/plugins/glo3dapp-woospin/assets/jquery.modal.min.js/wp-content/plugins/glo3dapp-woospin/functions.js/wp-content/plugins/glo3dapp-woospin/assets/glo3d_site.jsglo3dapp-woospin/assets/jquery.modal.min.css?ver=glo3dapp-woospin/assets/glo3d.css?ver=glo3dapp-woospin/assets/jquery.modal.min.js?ver=glo3dapp-woospin/functions.js?ver=glo3dapp-woospin/assets/glo3d_site.js?ver=HTML / DOM Fingerprints
modal<!--GLO3DIMAGE--><!--GLO3DURL--><!--GLO3DWIDTH--><!--GLO3DHEIGHT-->id="glo3d-add-link"rel="modal:open"id="removeGlo3d"id="glo3d-image-container"id="glo3d-image"id="glo3d-modal"+6 moreglo3d/wp-json/