360 Spin For Woocommerce Security & Risk Analysis

wordpress.org/plugins/glo3dapp-woospin

With a push of a button of any smartphone or professional camera, capture, edit, share and embed 360° photo of any product to your woocommerce online …

10 active installs v1.2.0 PHP 5.2.4+ WP 3.1+ Updated May 21, 2020
360-product-photography360-spin360-spin-app360-spin-pluginwoocommerce-easy-360
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is 360 Spin For Woocommerce Safe to Use in 2026?

Generally Safe

Score 85/100

360 Spin For Woocommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The glo3dapp-woospin plugin v1.2.0 exhibits a generally good security posture based on the provided static analysis. It has a limited attack surface with only two AJAX handlers, and importantly, these entry points appear to be protected by nonces and capability checks, indicating good practice in preventing unauthorized access and CSRF attacks. The complete absence of raw SQL queries and the use of prepared statements for all database interactions is a significant strength, mitigating SQL injection risks. Taint analysis also shows no critical or high severity vulnerabilities, suggesting that user-supplied data is not being mishandled in ways that could lead to serious security issues.

However, a notable concern is the output escaping. With 47% of outputs properly escaped, a significant portion (53%) remains unescaped. This could open the door to Cross-Site Scripting (XSS) vulnerabilities if user-controlled data is reflected directly in the output without proper sanitization. While the vulnerability history shows no known CVEs, which is positive, the lack of historical data could also mean this plugin hasn't been extensively scrutinized or tested in the past. The presence of file operations without specific details is also a minor point of interest that warrants further investigation in a real-world scenario, though it's not flagged as inherently dangerous here.

In conclusion, the plugin demonstrates strong foundational security practices, particularly concerning SQL injection and access control. The primary area of concern is the incomplete output escaping, which presents a potential XSS risk. The absence of past vulnerabilities is a good sign, but it's crucial to ensure ongoing security diligence, especially regarding the identified output escaping deficiency. The plugin's overall risk is assessed as moderate due to the potential for XSS.

Key Concerns

  • Output escaping is only 47% proper
Vulnerabilities
None known

360 Spin For Woocommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

360 Spin For Woocommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
7 escaped
Nonce Checks
2
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

47% escaped15 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
sfw360_doGlo3dSubmit (360-spin-for-woocommerce.php:73)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

360 Spin For Woocommerce Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_glo3d_submit360-spin-for-woocommerce.php:44
authwp_ajax_glo3d_delete360-spin-for-woocommerce.php:45
WordPress Hooks 5
actionadmin_enqueue_scripts360-spin-for-woocommerce.php:25
actionwp_enqueue_scripts360-spin-for-woocommerce.php:35
actionadd_meta_boxes360-spin-for-woocommerce.php:43
filterwoocommerce_single_product_zoom_enabled360-spin-for-woocommerce.php:46
filterwoocommerce_single_product_image_thumbnail_html360-spin-for-woocommerce.php:47
Maintenance & Trust

360 Spin For Woocommerce Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedMay 21, 2020
PHP min version5.2.4
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

360 Spin For Woocommerce Developer Profile

glo3d

2 plugins · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect 360 Spin For Woocommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/glo3dapp-woospin/assets/jquery.modal.min.css/wp-content/plugins/glo3dapp-woospin/assets/glo3d.css/wp-content/plugins/glo3dapp-woospin/assets/jquery.modal.min.js/wp-content/plugins/glo3dapp-woospin/functions.js/wp-content/plugins/glo3dapp-woospin/assets/glo3d_site.js/wp-content/plugins/glo3dapp-woospin/assets/360-spin.svg
Script Paths
/wp-content/plugins/glo3dapp-woospin/assets/jquery.modal.min.js/wp-content/plugins/glo3dapp-woospin/functions.js/wp-content/plugins/glo3dapp-woospin/assets/glo3d_site.js
Version Parameters
glo3dapp-woospin/assets/jquery.modal.min.css?ver=glo3dapp-woospin/assets/glo3d.css?ver=glo3dapp-woospin/assets/jquery.modal.min.js?ver=glo3dapp-woospin/functions.js?ver=glo3dapp-woospin/assets/glo3d_site.js?ver=

HTML / DOM Fingerprints

CSS Classes
modal
HTML Comments
<!--GLO3DIMAGE--><!--GLO3DURL--><!--GLO3DWIDTH--><!--GLO3DHEIGHT-->
Data Attributes
id="glo3d-add-link"rel="modal:open"id="removeGlo3d"id="glo3d-image-container"id="glo3d-image"id="glo3d-modal"+6 more
JS Globals
glo3d
REST Endpoints
/wp-json/
FAQ

Frequently Asked Questions about 360 Spin For Woocommerce