Lore Owl SubCat for WC Security & Risk Analysis

wordpress.org/plugins/lore-owl-subcat-for-wc

Add a simple Owl Carousel of WooCommerce product subcategories on top of the parent category pages, outside product loop.

0 active installs v1.0.1 PHP 5.6+ WP 4.9+ Updated Jun 3, 2020
carouselcategoriesowlsubcategorieswoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Lore Owl SubCat for WC Safe to Use in 2026?

Generally Safe

Score 85/100

Lore Owl SubCat for WC has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The plugin "lore-owl-subcat-for-wc" v1.0.1 demonstrates a generally good security posture in several key areas. The static analysis reveals a complete absence of SQL queries that are not properly prepared, indicating a strong defense against SQL injection. Furthermore, there are no file operations, external HTTP requests, or bundled libraries that could introduce vulnerabilities. The plugin also has no recorded vulnerability history, which is a positive indicator of its stability and secure development practices.

However, there are significant concerns regarding the lack of proper output escaping. With 19 total outputs analyzed, only 5% are properly escaped. This indicates a high likelihood of cross-site scripting (XSS) vulnerabilities, as user-supplied data could be rendered directly in the browser without sufficient sanitization. Additionally, the complete absence of nonce checks and capability checks across the identified entry points (though limited) suggests that authenticated actions within the plugin may not be adequately protected against unauthorized execution or CSRF attacks.

In conclusion, while the plugin excels in preventing common database and file-related vulnerabilities, the significant unescaped output and lack of critical authentication/authorization checks present substantial risks. The absence of historical vulnerabilities is a strength, but it does not mitigate the immediate risks identified in the static analysis. A more robust approach to output escaping and the implementation of proper security checks for all entry points are strongly recommended.

Key Concerns

  • Low output escaping percentage
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Lore Owl SubCat for WC Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Lore Owl SubCat for WC Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
18
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

5% escaped19 total outputs
Attack Surface

Lore Owl SubCat for WC Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_menulore-owl-subcat-for-wc.php:26
actionadmin_initlore-owl-subcat-for-wc.php:120
actionwp_enqueue_scriptslore-owl-subcat-for-wc.php:195
actionwoocommerce_before_shop_looplore-owl-subcat-for-wc.php:314
Maintenance & Trust

Lore Owl SubCat for WC Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedJun 3, 2020
PHP min version5.6
Downloads959

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Lore Owl SubCat for WC Developer Profile

Lorenzo Moio

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Lore Owl SubCat for WC

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/lore-owl-subcat-for-wc/assets/css/owl.theme.default.min.css/wp-content/plugins/lore-owl-subcat-for-wc/assets/css/owl.carousel.min.css/wp-content/plugins/lore-owl-subcat-for-wc/assets/js/owl.carousel.min.js/wp-content/plugins/lore-owl-subcat-for-wc/assets/js/losw-script.js
Script Paths
/wp-content/plugins/lore-owl-subcat-for-wc/assets/js/owl.carousel.min.js/wp-content/plugins/lore-owl-subcat-for-wc/assets/js/losw-script.js
Version Parameters
lore-owl-subcat-for-wc/assets/css/owl.theme.default.min.css?ver=lore-owl-subcat-for-wc/assets/css/owl.carousel.min.css?ver=lore-owl-subcat-for-wc/assets/js/owl.carousel.min.js?ver=lore-owl-subcat-for-wc/assets/js/losw-script.js?ver=

HTML / DOM Fingerprints

CSS Classes
losw-carousel-wrapper
Data Attributes
data-mobile_noidata-tablet_noidata-desktop_noidata-ch_arrowsdata-ch_dotsdata-font_size+2 more
JS Globals
losw_carousel_options
FAQ

Frequently Asked Questions about Lore Owl SubCat for WC