
Live Preview – Product Options – Lite Security & Risk Analysis
wordpress.org/plugins/live-preview-product-options-liteProduct Options for WooCommerce with Live Preview.
Is Live Preview – Product Options – Lite Safe to Use in 2026?
Generally Safe
Score 85/100Live Preview – Product Options – Lite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'live-preview-product-options-lite' plugin, version 1.1.2, presents a mixed security posture. While the static analysis indicates a very small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events that lack authentication, this is overshadowed by significant code-level concerns. A critical issue is the complete lack of output escaping, with 0% of 37 total outputs being properly escaped. This means any data processed or displayed by the plugin is highly susceptible to cross-site scripting (XSS) vulnerabilities. Additionally, the single SQL query identified is not using prepared statements, posing a risk of SQL injection if user-supplied data is incorporated into it without proper sanitization.
The plugin's vulnerability history is clean, with no known CVEs, which is a positive indicator. However, the absence of historical vulnerabilities does not negate the immediate risks identified in the current code analysis. The lack of capability checks and nonce checks on potential entry points, although currently minimal, also represents potential weaknesses if the attack surface were to expand in future versions or if certain functions are called in an unauthenticated context. The plugin's strengths lie in its limited attack surface and clean historical record, but its weaknesses, particularly the rampant unescaped output and raw SQL query, create significant immediate security risks that require remediation.
Key Concerns
- 0% of outputs properly escaped
- SQL query not using prepared statements
- 0 Nonce checks
- 0 Capability checks
Live Preview – Product Options – Lite Security Vulnerabilities
Live Preview – Product Options – Lite Code Analysis
SQL Query Safety
Output Escaping
Live Preview – Product Options – Lite Attack Surface
WordPress Hooks 13
Maintenance & Trust
Live Preview – Product Options – Lite Maintenance & Trust
Maintenance Signals
Community Trust
Live Preview – Product Options – Lite Alternatives
Extra Product Options Builder for WooCommerce
additional-product-fields-for-woocommerce
The most customizable extra product options builder for WooCommerce. You will love how many fields and features the free version has.
QODE Product Extra Options for WooCommerce
qode-product-extra-options-for-woocommerce
QODE Product Extra Options for WooCommerce elevates the eCommerce experience by providing your shoppers with selectable advanced product options.
Live Preview – Product Options – Lite Developer Profile
4 plugins · 1K total installs
How We Detect Live Preview – Product Options – Lite
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/live-preview-product-options-lite/css/grav.css/wp-content/plugins/live-preview-product-options-lite/js/custom_script.js/wp-content/plugins/live-preview-product-options-lite/js/custom_script.jslive-preview-product-options-lite/css/grav.css?ver=1.1live-preview-product-options-lite/js/custom_script.js?ver=HTML / DOM Fingerprints
gravurmodultextlimittextlimit_actualtextlimit_maxid="gravurfont"name="gfont"id="gravurtext"name="gravurtext"class="marked"id="gravurtext2"+1 more<div class="gravurmodul"><label for="gravurfont">Schriftart</label><select id="gravurfont" name="gfont"><div class="cell" id="gravur1">