Imajize Security & Risk Analysis

wordpress.org/plugins/imajize

Imajize enables you to easily embed a 360° product spin into any Wordpress post or WooCommerce product by simply pasting an embed link.

80 active installs v1.0.10 PHP + WP 3.0.1+ Updated Mar 16, 2023
360-product-photography360-product-spin360-product-viewer360-product-viewswoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Imajize Safe to Use in 2026?

Generally Safe

Score 85/100

Imajize has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The imajize plugin version 1.0.10 demonstrates a strong security posture based on the provided static analysis. The absence of any detected AJAX handlers, REST API routes, shortcodes, or cron events, coupled with zero known CVEs and a lack of reported vulnerabilities, suggests a minimal attack surface and a history of secure development. The code also shows good practices by not utilizing dangerous functions, performing file operations, or making external HTTP requests, and all SQL queries are properly prepared.

However, there are areas for improvement. The most significant concern is the low percentage of properly escaped output (20%). This indicates that sensitive data might be susceptible to cross-site scripting (XSS) vulnerabilities if user-supplied data is not adequately sanitized before being displayed. Furthermore, the complete absence of nonce checks and capability checks, while not directly exploitable given the current attack surface, represents a potential weakness. If new entry points are added in future versions, these security mechanisms would be crucial for preventing unauthorized actions. The lack of taint analysis results is also notable; while it could mean no issues were found, it might also indicate limitations in the analysis performed. Overall, the plugin is currently secure due to its limited functionality, but the unescaped output is a significant concern that needs addressing.

Key Concerns

  • Insufficient output escaping
  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

Imajize Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Imajize Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

20% escaped5 total outputs
Attack Surface

Imajize Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actioninitimajize.php:71
actionplugins_loadedincludes\class-imajize.php:140
actionadmin_enqueue_scriptsincludes\class-imajize.php:155
actionadmin_enqueue_scriptsincludes\class-imajize.php:156
actionwoocommerce_product_options_general_product_dataincludes\class-imajize.php:159
actionwoocommerce_process_product_metaincludes\class-imajize.php:160
actionwp_enqueue_scriptsincludes\class-imajize.php:175
actionwp_enqueue_scriptsincludes\class-imajize.php:176
filterwoocommerce_single_product_image_thumbnail_htmlincludes\class-imajize.php:178
actionwp_enqueue_scriptsincludes\class-imajize.php:180
actionwp_headincludes\class-imajize.php:181
Maintenance & Trust

Imajize Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedMar 16, 2023
PHP min version
Downloads7K

Community Trust

Rating80/100
Number of ratings4
Active installs80
Developer Profile

Imajize Developer Profile

imajize

1 plugin · 80 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Imajize

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/imajize/js/imajize-public.js/wp-content/plugins/imajize/css/imajize-public.css/wp-content/plugins/imajize/css/imajize-admin.css/wp-content/plugins/imajize/js/imajize-admin.js
Script Paths
/wp-content/plugins/imajize/js/imajize-public.js/wp-content/plugins/imajize/js/imajize-admin.js
Version Parameters
imajize-public?ver=imajize-admin?ver=

HTML / DOM Fingerprints

Data Attributes
data-imajize-url
JS Globals
ImajizePublic
REST Endpoints
/wp-json/imajize/v1/get_url
FAQ

Frequently Asked Questions about Imajize