Product Views for WooCommerce – Product Slider, Grid, Ticker, List & Masonry Security & Risk Analysis

wordpress.org/plugins/gs-woocommerce-products-slider

Transform Product Displays for Better Sales! Enhance your WooCommerce store with a stunning product slider!

300 active installs v3.0.2 PHP 5.6+ WP 4.3+ Updated Apr 17, 2025
product-gallerywoo-sliderwoocommerce-product-carouselwoocommerce-product-gridwoocommerce-product-slider
100
A · Safe
CVEs total1
Unpatched0
Last CVEJan 30, 2023
Safety Verdict

Is Product Views for WooCommerce – Product Slider, Grid, Ticker, List & Masonry Safe to Use in 2026?

Generally Safe

Score 100/100

Product Views for WooCommerce – Product Slider, Grid, Ticker, List & Masonry has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jan 30, 2023Updated 11mo ago
Risk Assessment

The plugin "gs-woocommerce-products-slider" v3.0.2 exhibits a mixed security posture. While it demonstrates good practices in avoiding dangerous functions and file operations, and a significant portion of its SQL queries use prepared statements and outputs are properly escaped, several concerning areas are highlighted by the static analysis. The presence of 7 AJAX handlers without authentication checks represents a significant attack surface that could be exploited by unauthenticated users. Furthermore, the taint analysis revealed 3 high-severity flows with unsanitized paths, indicating potential vulnerabilities for sensitive data manipulation or code execution. The vulnerability history shows a past medium severity Cross-Site Scripting (XSS) vulnerability, though it is currently patched. This suggests a potential for input sanitization issues. Overall, the plugin has strengths in its handling of common security pitfalls like dangerous functions and SQL injection via prepared statements, but the unprotected entry points and high-severity taint flows are significant weaknesses that require attention.

Key Concerns

  • Unprotected AJAX handlers
  • High severity unsanitized paths in taint analysis
  • Medium severity vulnerability history (XSS)
Vulnerabilities
1

Product Views for WooCommerce – Product Slider, Grid, Ticker, List & Masonry Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2023-0492medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

GS Products Slider for WooCommerce <= 1.5.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

Jan 30, 2023 Patched in 1.5.9 (358d)
Code Analysis
Analyzed Mar 16, 2026

Product Views for WooCommerce – Product Slider, Grid, Ticker, List & Masonry Code Analysis

Dangerous Functions
0
Raw SQL Queries
5
10 prepared
Unescaped Output
50
181 escaped
Nonce Checks
14
Capability Checks
17
File Operations
0
External Requests
4
Bundled Libraries
0

SQL Query Safety

67% prepared15 total queries

Output Escaping

78% escaped231 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

8 flows3 with unsanitized paths
review_notice_message (includes\hooks.php:108)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
7 unprotected

Product Views for WooCommerce – Product Slider, Grid, Ticker, List & Masonry Attack Surface

Entry Points14
Unprotected7

AJAX Handlers 13

authwp_ajax_gswps_import_shortcode_dataincludes\demo-data\dummy-data.php:19
authwp_ajax_gswps_remove_shortcode_dataincludes\demo-data\dummy-data.php:21
authwp_ajax_gswoo_create_shortcodeincludes\shortcode-builder\builder.php:21
authwp_ajax_gswoo_clone_shortcodeincludes\shortcode-builder\builder.php:22
authwp_ajax_gswoo_get_shortcodeincludes\shortcode-builder\builder.php:23
authwp_ajax_gswoo_update_shortcodeincludes\shortcode-builder\builder.php:24
authwp_ajax_gswoo_delete_shortcodesincludes\shortcode-builder\builder.php:25
authwp_ajax_gswoo_temp_save_shortcode_settingsincludes\shortcode-builder\builder.php:26
authwp_ajax_gswoo_get_shortcodesincludes\shortcode-builder\builder.php:27
authwp_ajax_gswoo_get_shortcode_prefincludes\shortcode-builder\builder.php:29
authwp_ajax_gswoo_save_shortcode_prefincludes\shortcode-builder\builder.php:30
authwp_ajax_gswoo_get_layout_configincludes\shortcode-builder\builder.php:32
authwp_ajax_gswoo_save_layout_configincludes\shortcode-builder\builder.php:33

Shortcodes 1

[gswoo] includes\shortcode.php:12
WordPress Hooks 46
actionswitch_themeincludes\appsero\Insights.php:133
actionswitch_themeincludes\appsero\Insights.php:134
actionadmin_footerincludes\appsero\Insights.php:147
actionadmin_noticesincludes\appsero\Insights.php:164
actionadmin_initincludes\appsero\Insights.php:167
filtercron_schedulesincludes\appsero\Insights.php:173
actionwp_footerincludes\asset-generator\gs-asset-generator-base.php:26
filterpost_updatedincludes\asset-generator\gs-asset-generator-base.php:27
filterwidget_update_callbackincludes\asset-generator\gs-asset-generator-base.php:28
actionupdate_option_sidebars_widgetsincludes\asset-generator\gs-asset-generator-base.php:29
actiongsp_shortcode_updatedincludes\asset-generator\gs-asset-generator-base.php:30
actiongsp_preference_updateincludes\asset-generator\gs-asset-generator-base.php:31
actiongswps_dummy_shortcodes_process_startincludes\demo-data\dummy-data.php:24
actiongswps_dummy_shortcodes_process_finishedincludes\demo-data\dummy-data.php:36
actionplugins_loadedincludes\demo-data\dummy-data.php:48
actionadmin_noticesincludes\functions.php:365
actionadmin_noticesincludes\functions.php:378
actionadmin_menuincludes\gs-common-pages\gs-plugins-common-pages.php:16
actionadmin_enqueue_scriptsincludes\gs-common-pages\gs-plugins-common-pages.php:17
actionplugins_loadedincludes\hooks.php:8
actioninitincludes\hooks.php:9
actionadmin_initincludes\hooks.php:10
actionadmin_initincludes\hooks.php:11
filtermanage_edit-gs_wps_cpt_columnsincludes\hooks.php:12
actionmanage_gs_wps_cpt_posts_custom_columnincludes\hooks.php:13
filterplugin_row_metaincludes\hooks.php:14
actionadmin_initincludes\hooks.php:15
actionin_admin_headerincludes\hooks.php:16
actionwoocommerce_product_options_general_product_dataincludes\hooks.php:19
actionwoocommerce_product_options_inventory_product_dataincludes\hooks.php:20
actionwoocommerce_process_product_metaincludes\hooks.php:22
actionadmin_noticesincludes\hooks.php:101
actionadmin_noticesincludes\hooks.php:348
actionplugins_loadedincludes\init.php:9
actioninitincludes\init.php:44
actionplugins_loadedincludes\scripts.php:38
actionadmin_enqueue_scriptsincludes\scripts.php:39
actionwp_enqueue_scriptsincludes\scripts.php:40
actionadmin_headincludes\scripts.php:41
actionwp_footerincludes\scripts.php:364
actionadmin_menuincludes\shortcode-builder\builder.php:17
actionadmin_enqueue_scriptsincludes\shortcode-builder\builder.php:18
actionwp_enqueue_scriptsincludes\shortcode-builder\builder.php:19
actiontemplate_includeincludes\shortcode-builder\builder.php:35
actionshow_admin_barincludes\shortcode-builder\builder.php:36
actioninitincludes\template-loader.php:27
Maintenance & Trust

Product Views for WooCommerce – Product Slider, Grid, Ticker, List & Masonry Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 17, 2025
PHP min version5.6
Downloads28K

Community Trust

Rating80/100
Number of ratings8
Active installs300
Developer Profile

Product Views for WooCommerce – Product Slider, Grid, Ticker, List & Masonry Developer Profile

GS Plugins

19 plugins · 41K total installs

78
trust score
Avg Security Score
98/100
Avg Patch Time
173 days
View full developer profile
Detection Fingerprints

How We Detect Product Views for WooCommerce – Product Slider, Grid, Ticker, List & Masonry

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gs-woocommerce-products-slider/assets/css/gs-wps-public.css/wp-content/plugins/gs-woocommerce-products-slider/assets/css/gs-wps-admin.css/wp-content/plugins/gs-woocommerce-products-slider/assets/js/gs-wps-public.js/wp-content/plugins/gs-woocommerce-products-slider/assets/js/gs-wps-admin.js
Script Paths
/wp-content/plugins/gs-woocommerce-products-slider/assets/js/gs-wps-public.js/wp-content/plugins/gs-woocommerce-products-slider/assets/js/gs-wps-admin.js
Version Parameters
gs-woocommerce-products-slider/assets/css/gs-wps-public.css?ver=gs-woocommerce-products-slider/assets/css/gs-wps-admin.css?ver=gs-woocommerce-products-slider/assets/js/gs-wps-public.js?ver=gs-woocommerce-products-slider/assets/js/gs-wps-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
gs-wps-product-slidergs-wps-slider-wrappergswps-product-itemgs-wps-product-image-wrapgs-wps-product-titlegs-wps-product-pricegs-wps-add-to-cart-buttongs-wps-nav-next+3 more
Data Attributes
data-settings
JS Globals
GSWPS_PUBLICGSWPS_ADMIN
Shortcode Output
[gswoo id=
FAQ

Frequently Asked Questions about Product Views for WooCommerce – Product Slider, Grid, Ticker, List & Masonry