Shoppable Images (Lookbook) for WooCommerce Security & Risk Analysis

wordpress.org/plugins/mabel-shoppable-images-lite

Create interactive 'shoppable' images (lookbooks) with click-to-buy tags. Ideal to showcase your products in a different way and drive more traffic.

6K active installs v1.3.1 PHP + WP 3.7+ Updated Jun 25, 2026
clickable-imagehotspotsimage-hotspotsshoppable-imagewoocommerce
96
A · Safe
CVEs total3
Unpatched0
Last CVEJun 26, 2026
Safety Verdict

Is Shoppable Images (Lookbook) for WooCommerce Safe to Use in 2026?

Generally Safe

Score 96/100

Shoppable Images (Lookbook) for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

3 known CVEsLast CVE: Jun 26, 2026Updated 2mo ago
Risk Assessment

The static analysis of mabel-shoppable-images-lite v1.3 reveals a generally good security posture with a limited attack surface. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, and no direct file operations or external HTTP requests are made. The code exhibits strong adherence to secure coding practices, with 100% of SQL queries using prepared statements and a high percentage (93%) of output properly escaped. Nonce and capability checks are present on all identified entry points. However, the taint analysis indicates one flow with an unsanitized path, which, despite not being classified as critical or high severity, warrants attention as it represents a potential avenue for input manipulation. The vulnerability history is a significant concern. The plugin has two known medium-severity CVEs, one of which was disclosed in February 2023. The common vulnerability types of Cross-site Scripting and Missing Authorization, alongside the presence of historical vulnerabilities, suggest recurring security weaknesses that, even if currently patched, indicate a pattern of potential insecure development. While the current version shows improvements in its attack surface and secure coding practices, the historical pattern of medium-severity vulnerabilities, particularly those related to input handling and authorization, combined with the taint analysis finding, suggests a residual risk that requires careful monitoring and prompt patching of any new disclosures.

Key Concerns

  • Flow with unsanitized path
  • 2 known medium severity CVEs
Vulnerabilities
3 published

Shoppable Images (Lookbook) for WooCommerce Security Vulnerabilities

CVEs by Year

2 CVEs in 2023
2023
1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

Medium
3

3 total CVEs

CVE-2026-57649medium · 4.3Missing Authorization

Shoppable Images (Lookbook) for WooCommerce <= 1.3 - Missing Authorization

Jun 26, 2026 Patched in 1.3.1 (4d)
CVE-2023-25698medium · 5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Shoppable Images <= 1.2.3 - Cross Site Request Forgery

Feb 13, 2023 Patched in 1.2.4 (344d)

Shoppable Images Lite <= 1.2.3 - Missing Authorization

Feb 13, 2023 Patched in 1.2.4 (344d)
Version History

Shoppable Images (Lookbook) for WooCommerce Release Timeline

v1.3.1Current
v1.31 CVE
v1.2.61 CVE
v1.2.51 CVE
v1.2.41 CVE
Code Analysis
Analyzed Mar 16, 2026

Shoppable Images (Lookbook) for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
9
124 escaped
Nonce Checks
5
Capability Checks
5
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

93% escaped133 total outputs
Data Flows · Security
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
get_wc_product_by_id (code\controllers\class-admin-controller.php:89)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Shoppable Images (Lookbook) for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actioninitclass-shoppable-images.php:64
actionadmin_menucore\common\class-admin.php:27
actionadmin_initcore\common\class-admin.php:30
actionadmin_enqueue_scriptscore\common\class-admin.php:34
actionadmin_enqueue_scriptscore\common\class-admin.php:35
actionadmin_initcore\common\class-admin.php:36
actionwp_enqueue_scriptscore\common\class-frontend.php:12
actionwp_enqueue_scriptscore\common\class-frontend.php:13
actionplugins_loadedcore\common\managers\class-language-manager.php:19
actionbefore_woocommerce_initmabel-shoppable-images-lite.php:61
Maintenance & Trust

Shoppable Images (Lookbook) for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested7.0.2
Last updatedJun 25, 2026
PHP min version
Downloads129K

Community Trust

Rating86/100
Number of ratings12
Active installs6K
Developer Profile

Shoppable Images (Lookbook) for WooCommerce Developer Profile

studiowombat

1 plugin · 6K total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
231 days
View full developer profile
Detection Fingerprints

How We Detect Shoppable Images (Lookbook) for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mabel-shoppable-images-lite/core/assets/css/mabel-main.css/wp-content/plugins/mabel-shoppable-images-lite/core/assets/js/mabel-main.js/wp-content/plugins/mabel-shoppable-images-lite/core/assets/js/mabel-public.js
Script Paths
/wp-content/plugins/mabel-shoppable-images-lite/core/assets/js/mabel-main.js/wp-content/plugins/mabel-shoppable-images-lite/core/assets/js/mabel-public.js
Version Parameters
mabel-shoppable-images-lite/core/assets/css/mabel-main.css?ver=mabel-shoppable-images-lite/core/assets/js/mabel-main.js?ver=mabel-shoppable-images-lite/core/assets/js/mabel-public.js?ver=

HTML / DOM Fingerprints

CSS Classes
mabel-shoppable-images-lite
Data Attributes
data-mabel-settings
JS Globals
mabel_script_vars
FAQ

Frequently Asked Questions about Shoppable Images (Lookbook) for WooCommerce