Immersive Shopping and Videos Security & Risk Analysis

wordpress.org/plugins/immersive-shopping-and-videos

Turn browsers into buyers with idiot-proof technology.

0 active installs v1.16 PHP 7.4+ WP 4.7+ Updated Dec 12, 2025
interactive-videolive-shoppingproduct-videosshopping-assistantvideo-commerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Immersive Shopping and Videos Safe to Use in 2026?

Generally Safe

Score 100/100

Immersive Shopping and Videos has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The "immersive-shopping-and-videos" plugin v1.16 exhibits a generally strong security posture based on the provided static analysis. There are no identified entry points (AJAX, REST API, shortcodes, cron) that are unprotected, which is a significant positive. The plugin also demonstrates good practices by using prepared statements for all SQL queries and ensuring a high percentage of output is properly escaped. The absence of dangerous functions and file operations further contributes to its secure design. Furthermore, the plugin has no recorded vulnerabilities (CVEs) and no history of past security issues, suggesting consistent attention to security or a lack of past discovery, which is favorable.

Despite the strengths, there are a few areas that warrant consideration. The complete lack of nonce checks and capability checks across all code signals is a notable concern. While the static analysis reports zero unprotected entry points, it's crucial to understand the context of these checks. If there are internal mechanisms or chained calls that indirectly provide security, that's one thing, but a complete absence raises a red flag for potential future vulnerabilities if the code evolves or new entry points are inadvertently introduced. The two external HTTP requests, while not inherently insecure, are also points to monitor for any potential vulnerabilities if the external services are compromised or if the data sent/received is not handled securely.

In conclusion, the "immersive-shopping-and-videos" plugin v1.16 is commendably secure in many aspects, particularly regarding its lack of exposed attack vectors and responsible handling of database operations and output. However, the complete absence of nonce and capability checks represents a significant potential weakness that, while not immediately exploitable based on the current analysis, should be addressed to harden the plugin's security posture against future threats.

Key Concerns

  • Missing Nonce Checks
  • Missing Capability Checks
  • External HTTP Requests Present
Vulnerabilities
None known

Immersive Shopping and Videos Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Immersive Shopping and Videos Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
8 prepared
Unescaped Output
1
39 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

SQL Query Safety

100% prepared8 total queries

Output Escaping

98% escaped40 total outputs
Attack Surface

Immersive Shopping and Videos Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 20
filterwoocommerce_settings_savedinc\isv_catalog_hook_handler.php:16
actionwoocommerce_update_productinc\isv_catalog_hook_handler.php:19
actionwp_trash_postinc\isv_catalog_hook_handler.php:20
actionuntrash_postinc\isv_catalog_hook_handler.php:21
actiondelete_postinc\isv_catalog_hook_handler.php:22
actionsaved_product_catinc\isv_catalog_hook_handler.php:25
actiondelete_product_catinc\isv_catalog_hook_handler.php:26
actionpre_delete_terminc\isv_catalog_hook_handler.php:27
actionwoocommerce_after_order_object_saveinc\isv_catalog_hook_handler.php:30
filtercron_schedulesinc\isv_cron.php:26
filtercron_schedulesinc\isv_cron.php:27
actionwp_enqueue_scriptsinc\isv_scripts_inserter.php:16
actionwp_enqueue_scriptsinc\isv_scripts_inserter.php:17
actionwp_footerinc\isv_scripts_inserter.php:18
actionwoocommerce_thankyouinc\isv_scripts_inserter.php:19
actionwp_footerinc\isv_scripts_inserter.php:20
actionwoocommerce_after_single_productinc\isv_scripts_inserter.php:21
actionadmin_initinc\isv_settings.php:11
actionadmin_menuinc\isv_settings.php:12
actionadded_optioninc\isv_settings.php:13
Maintenance & Trust

Immersive Shopping and Videos Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedDec 12, 2025
PHP min version7.4
Downloads257

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Immersive Shopping and Videos Developer Profile

aveytsman

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Immersive Shopping and Videos

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/immersive-shopping-and-videos/inc/js/widget.js/wp-content/plugins/immersive-shopping-and-videos/inc/js/order-tracking.js/wp-content/plugins/immersive-shopping-and-videos/inc/js/visit-tracking.js
Script Paths
immeshan-visit-trackingimmeshan-widgetimmeshan-order-tracking-js
Version Parameters
immersive-shopping-and-videos/style.css?ver=1.16/wp-content/plugins/immersive-shopping-and-videos/inc/js/order-tracking.js?ver=1.16

HTML / DOM Fingerprints

Data Attributes
id="immeshan-widget-config"id="immerss-order-tracking-config"
JS Globals
window.Immerssvar imrs = new Imrs()
FAQ

Frequently Asked Questions about Immersive Shopping and Videos