
Live Shopping & Shoppable Videos For WooCommerce Security & Risk Analysis
wordpress.org/plugins/live-shopping-video-streamsEasy-to-install Plugin that adds Live Shopping, Shoppable Videos & Live Commerce as Sales Channels to WooCommerce Stores to Sell & Promote Products
Is Live Shopping & Shoppable Videos For WooCommerce Safe to Use in 2026?
Use With Caution
Score 56/100Live Shopping & Shoppable Videos For WooCommerce has 2 unpatched vulnerabilities. Evaluate alternatives or apply available mitigations.
The "live-shopping-video-streams" v2.2.0 plugin exhibits significant security concerns despite some positive indicators. The static analysis reveals a concerningly small attack surface, but critically, one of the entry points, a REST API route, lacks proper permission callbacks. Furthermore, the presence of the `exec` function, a dangerous function, is a red flag, indicating potential for arbitrary code execution if exploited through an insecure input. The taint analysis shows one flow with an unsanitized path, which could lead to unintended behavior or vulnerabilities. While the plugin demonstrates good practice with 100% of its SQL queries using prepared statements, this is overshadowed by the lack of proper authorization checks and the dangerous function. The vulnerability history, with two medium severity CVEs, both currently unpatched and including common types like Missing Authorization, strongly suggests a recurring pattern of insecure development practices. The most recent vulnerability being "unpatched" as of December 31, 2025, is also a serious indicator of ongoing neglect.
In conclusion, while the plugin utilizes prepared statements for SQL, its security posture is poor due to a lack of authorization checks on its REST API, the use of a dangerous function (`exec`), and a history of unpatched vulnerabilities. The unsanitized path in taint analysis further compounds these risks. This plugin should be considered high-risk and requires immediate attention to address the identified vulnerabilities and implement robust security checks.
Key Concerns
- Unpatched CVEs (2x Medium)
- REST API route without permission callbacks
- Dangerous function: exec
- Flows with unsanitized paths (1)
- No nonce checks
- No capability checks
- Low output escaping percentage (71%)
Live Shopping & Shoppable Videos For WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Live Shopping & Shoppable Videos For WooCommerce <= 2.2.0 - Cross-Site Request Forgery
Live Shopping & Shoppable Videos For WooCommerce <= 2.2.0 - Missing Authorization
Live Shopping & Shoppable Videos For WooCommerce Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Live Shopping & Shoppable Videos For WooCommerce Attack Surface
REST API Routes 1
WordPress Hooks 17
Maintenance & Trust
Live Shopping & Shoppable Videos For WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Live Shopping & Shoppable Videos For WooCommerce Alternatives
VidShop – Shoppable Videos for WooCommerce
vidshop-for-woocommerce
Engage customers with swipeable shoppable videos, seamless checkout, and powerful analytics for WooCommerce.
Immersive Shopping and Videos
immersive-shopping-and-videos
Turn browsers into buyers with idiot-proof technology.
Live Sales for WooCommerce
live-sales-for-woocommerce
Experience future of interactive commerce. Enjoy ultra-low latency interactive live sales with chat feature for faster and effective live commerce.
SaleAssist Live Video Engagements
saleassist
The best Live Video Engagement solution for your website. The most trusted Live Video solution for WordPress and WooCommerce.
WpStream – Live Streaming, Video on Demand, Pay Per View
wpstream
WpStream is a Video Streaming Plugin that lets you broadcast live events and helps you sell tickets or recordings via WooCommerce.
Live Shopping & Shoppable Videos For WooCommerce Developer Profile
2 plugins · 620 total installs
How We Detect Live Shopping & Shoppable Videos For WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/live-shopping-video-streams/assets/css/style.css/wp-content/plugins/live-shopping-video-streams/assets/js/main.js/wp-content/plugins/live-shopping-video-streams/assets/js/main.jslive-shopping-video-streams/assets/css/style.css?ver=live-shopping-video-streams/assets/js/main.js?ver=HTML / DOM Fingerprints
chls-admin-pagechannelize-live-shopdata-channelize-live-shopCHLS_API_URLChannelizeLiveShop[channelize_live_shop]