
Shoppable Images (Lookbook) for WooCommerce Security & Risk Analysis
wordpress.org/plugins/mabel-shoppable-images-liteCreate interactive 'shoppable' images (lookbooks) with click-to-buy tags. Ideal to showcase your products in a different way and drive more traffic.
Is Shoppable Images (Lookbook) for WooCommerce Safe to Use in 2026?
Generally Safe
Score 99/100Shoppable Images (Lookbook) for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of mabel-shoppable-images-lite v1.3 reveals a generally good security posture with a limited attack surface. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, and no direct file operations or external HTTP requests are made. The code exhibits strong adherence to secure coding practices, with 100% of SQL queries using prepared statements and a high percentage (93%) of output properly escaped. Nonce and capability checks are present on all identified entry points. However, the taint analysis indicates one flow with an unsanitized path, which, despite not being classified as critical or high severity, warrants attention as it represents a potential avenue for input manipulation. The vulnerability history is a significant concern. The plugin has two known medium-severity CVEs, one of which was disclosed in February 2023. The common vulnerability types of Cross-site Scripting and Missing Authorization, alongside the presence of historical vulnerabilities, suggest recurring security weaknesses that, even if currently patched, indicate a pattern of potential insecure development. While the current version shows improvements in its attack surface and secure coding practices, the historical pattern of medium-severity vulnerabilities, particularly those related to input handling and authorization, combined with the taint analysis finding, suggests a residual risk that requires careful monitoring and prompt patching of any new disclosures.
Key Concerns
- Flow with unsanitized path
- 2 known medium severity CVEs
Shoppable Images (Lookbook) for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Shoppable Images <= 1.2.3 - Cross Site Request Forgery
Shoppable Images Lite <= 1.2.3 - Missing Authorization
Shoppable Images (Lookbook) for WooCommerce Code Analysis
Output Escaping
Data Flow Analysis
Shoppable Images (Lookbook) for WooCommerce Attack Surface
WordPress Hooks 10
Maintenance & Trust
Shoppable Images (Lookbook) for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Shoppable Images (Lookbook) for WooCommerce Alternatives
Shoppable Images by WP-Plugz – Increase Engagement and Conversions
wpplugz-shoppable-image
Introducing the Shoppable Images plugin for WordPress sites built with WooCommerce! Turn stunning product visuals into interactive experiences that dr …
Image Hotspot – Map Image Annotation
image-map-hotspots
Image hotspot lets you easily add custom tooltips to your images and add hotspot when highlighting them. Furthermore, you have the option of setting c …
WP Image Markers – Easy Hotspot Solution
wp-image-makers-easy-hotspot-solution
Easy way to add markers to an image and drag to reposition them.
WPC Shoppable Images for WooCommerce
wpc-shoppable-images
WPC Shoppable Images is impressively a versatile, multipurpose, and powerful plugin, which helps you increase your sales by creating shoppable images.
WCSpots – image hotspots for WooCommerce
wcspots
Create WooCommerce product showcases with image hotspots in the block editor.
Shoppable Images (Lookbook) for WooCommerce Developer Profile
1 plugin · 7K total installs
How We Detect Shoppable Images (Lookbook) for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mabel-shoppable-images-lite/core/assets/css/mabel-main.css/wp-content/plugins/mabel-shoppable-images-lite/core/assets/js/mabel-main.js/wp-content/plugins/mabel-shoppable-images-lite/core/assets/js/mabel-public.js/wp-content/plugins/mabel-shoppable-images-lite/core/assets/js/mabel-main.js/wp-content/plugins/mabel-shoppable-images-lite/core/assets/js/mabel-public.jsmabel-shoppable-images-lite/core/assets/css/mabel-main.css?ver=mabel-shoppable-images-lite/core/assets/js/mabel-main.js?ver=mabel-shoppable-images-lite/core/assets/js/mabel-public.js?ver=HTML / DOM Fingerprints
mabel-shoppable-images-litedata-mabel-settingsmabel_script_vars