Hexa Grid – Product Showcase and Category Display for WooCommerce Security & Risk Analysis

wordpress.org/plugins/hexa-grid-product-showcase

Build a Beautiful WooCommerce Product Showcase and WooCommerce Category Display using responsive grid, slider, list and table layouts.

0 active installs v1.1.0 PHP 7.4+ WP 5.0+ Updated Unknown
product-sliderproduct-tablewoocommerce-category-displaywoocommerce-product-gridwoocommerce-product-showcase
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Hexa Grid – Product Showcase and Category Display for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Hexa Grid – Product Showcase and Category Display for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "hexa-grid-product-showcase" plugin version 1.1.0 exhibits a generally strong security posture based on the provided static analysis. There are no identified dangerous functions, SQL queries are all prepared, file operations and external HTTP requests are absent, and a high percentage of outputs are properly escaped. Furthermore, the plugin implements nonce and capability checks, which are crucial for securing entry points. The absence of any recorded vulnerabilities in its history also suggests a history of secure development practices or effective patching by developers and users.

However, the analysis does reveal a single shortcode as the sole entry point, which, while not explicitly found to be unprotected, warrants careful consideration. The lack of any taint analysis results is noteworthy; while this could indicate a clean codebase, it might also be due to the limitations of the analysis itself or a very simple code structure that doesn't present complex data flows susceptible to taint. The absence of any AJAX handlers or REST API routes further minimizes the attack surface, which is a positive sign.

In conclusion, the plugin appears to be built with good security practices. The primary area for vigilance is the single shortcode entry point. The absence of vulnerabilities and a clean static analysis are significant strengths, but ongoing monitoring and understanding the exact implementation of the shortcode would be prudent for a complete risk assessment.

Key Concerns

  • Single shortcode as sole entry point
Vulnerabilities
None known

Hexa Grid – Product Showcase and Category Display for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Hexa Grid – Product Showcase and Category Display for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
113 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

94% escaped120 total outputs
Attack Surface

Hexa Grid – Product Showcase and Category Display for WooCommerce Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[hexagrid_product_showcase] includes\Shortcode\Shortcode_Handler.php:23
WordPress Hooks 9
filterbefore_woocommerce_inithexa-grid-product-showcase.php:51
actionplugins_loadedhexa-grid-product-showcase.php:61
actionadd_meta_boxesincludes\Admin\Meta_Box.php:23
actionsave_postincludes\Admin\Meta_Box.php:24
actionadmin_enqueue_scriptsincludes\Admin\Meta_Box.php:25
actioninitincludes\Admin\Post_Type.php:18
actionadmin_menuincludes\Admin\Settings_Page.php:18
actionin_admin_headerincludes\Admin\Settings_Page.php:19
actionwp_enqueue_scriptsincludes\Assets\Asset_Manager.php:18
Maintenance & Trust

Hexa Grid – Product Showcase and Category Display for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedUnknown
PHP min version7.4
Downloads148

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Hexa Grid – Product Showcase and Category Display for WooCommerce Developer Profile

Nazmun Sakib

5 plugins · 10 total installs

92
trust score
Avg Security Score
97/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Hexa Grid – Product Showcase and Category Display for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/hexa-grid-product-showcase/assets/admin/css/admin.css/wp-content/plugins/hexa-grid-product-showcase/assets/admin/js/admin.js
Script Paths
/wp-content/plugins/hexa-grid-product-showcase/assets/admin/js/admin.js
Version Parameters
hexa-grid-product-showcase/assets/admin/css/admin.css?ver=hexa-grid-product-showcase/assets/admin/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
hexagrid-settings-meta-box-wrapperhexagrid-settings-meta-box-contenthexagrid-settings-sectionhexagrid-settings-section-headerhexagrid-settings-section-iconhexagrid-settings-section-infohexagrid-settings-section-togglehexagrid-settings-section-body+9 more
HTML Comments
<!-- Section 1: Layout Settings --><!-- Content Type Selector -->
Data Attributes
data-id="content_type"data-type="radio"data-layout="list"data-grid-min-width="300px"
JS Globals
hexagridAdmin
FAQ

Frequently Asked Questions about Hexa Grid – Product Showcase and Category Display for WooCommerce