Magni Image Flip For WooCommerce Security & Risk Analysis

wordpress.org/plugins/magni-image-flip-for-woocommerce

Magni Image Flip adds a flip effect on your WooCommerce product thumbnail images.

800 active installs v1.3.1 PHP 5.4+ WP 4.0+ Updated Dec 13, 2025
ecommerceimage-flipimage-rotatewoocommerce-gallerywoocommerce-image-flip
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Magni Image Flip For WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Magni Image Flip For WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The security posture of the "magni-image-flip-for-woocommerce" v1.3.1 plugin appears to be a mixed bag, leaning towards a cautious but not entirely secure state. On the positive side, the plugin exhibits a clean slate regarding known vulnerabilities (CVEs) and presents no obvious critical flaws such as raw SQL queries, dangerous function usage, or external HTTP requests. The absence of any taint flow issues and a lack of file operations further contribute to a reduced attack surface in those specific areas.

However, significant concerns arise from the complete lack of output escaping and the absence of nonce and capability checks on its entry points, which are non-existent. While there are no explicit entry points to exploit currently, the lack of fundamental security checks like output escaping is a critical oversight. If any functionality were to be added or implicitly exposed, the lack of escaping would immediately present a cross-site scripting (XSS) vulnerability. The presence of the Select2 library, while bundled, also warrants attention as it could be a vector for vulnerabilities if outdated or if the plugin hasn't ensured its secure integration.

Overall, the plugin's current state with zero CVEs and no taint issues is a positive indicator, suggesting good development practices in certain areas. Nevertheless, the fundamental absence of output escaping on all outputs and the lack of any form of authentication/authorization checks on the (currently empty) attack surface represent significant weaknesses. A strong emphasis on securing any future additions and addressing the output escaping is paramount.

Key Concerns

  • No output escaping
  • Bundled outdated library: Select2
Vulnerabilities
None known

Magni Image Flip For WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Magni Image Flip For WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

0% escaped4 total outputs
Attack Surface

Magni Image Flip For WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
filterwoocommerce_settings_tabs_arrayincludes\magni-image-flipper-settings.php:25
actionadmin_noticesincludes\magni-image-flipper.php:17
filterwoocommerce_get_settings_pagesincludes\magni-image-flipper.php:23
actionwp_enqueue_scriptsincludes\magni-image-flipper.php:31
actionwoocommerce_before_shop_loop_item_titleincludes\magni-image-flipper.php:34
actionwoocommerce_before_shop_loop_item_titleincludes\magni-image-flipper.php:37
filterpost_classincludes\magni-image-flipper.php:40
actionadmin_enqueue_scriptsincludes\magni-image-flipper.php:43
actionplugins_loadedmagni-image.php:22
Maintenance & Trust

Magni Image Flip For WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 13, 2025
PHP min version5.4
Downloads23K

Community Trust

Rating68/100
Number of ratings5
Active installs800
Developer Profile

Magni Image Flip For WooCommerce Developer Profile

Magnigenie

8 plugins · 2K total installs

71
trust score
Avg Security Score
88/100
Avg Patch Time
320 days
View full developer profile
Detection Fingerprints

How We Detect Magni Image Flip For WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/magni-image-flip-for-woocommerce/assets/css/magniimage.css/wp-content/plugins/magni-image-flip-for-woocommerce/assets/js/magniimage.js/wp-content/plugins/magni-image-flip-for-woocommerce/assets/js/jquery.cycle2.js/wp-content/plugins/magni-image-flip-for-woocommerce/assets/js/jquery.cycle2.scrollVert.js/wp-content/plugins/magni-image-flip-for-woocommerce/assets/js/jquery.cycle2.flip.js/wp-content/plugins/magni-image-flip-for-woocommerce/assets/js/select2.js/wp-content/plugins/magni-image-flip-for-woocommerce/assets/css/select2.css/wp-content/plugins/magni-image-flip-for-woocommerce/assets/js/custom.js
Script Paths
/wp-content/plugins/magni-image-flip-for-woocommerce/assets/js/magniimage.js/wp-content/plugins/magni-image-flip-for-woocommerce/assets/js/jquery.cycle2.js/wp-content/plugins/magni-image-flip-for-woocommerce/assets/js/jquery.cycle2.scrollVert.js/wp-content/plugins/magni-image-flip-for-woocommerce/assets/js/jquery.cycle2.flip.js/wp-content/plugins/magni-image-flip-for-woocommerce/assets/js/select2.js/wp-content/plugins/magni-image-flip-for-woocommerce/assets/js/custom.js
Version Parameters
magni-image-flip-for-woocommerce/assets/js/magniimage.js?ver=magni-image-flip-for-woocommerce/assets/js/jquery.cycle2.js?ver=magni-image-flip-for-woocommerce/assets/js/jquery.cycle2.scrollVert.js?ver=magni-image-flip-for-woocommerce/assets/js/jquery.cycle2.flip.js?ver=magni-image-flip-for-woocommerce/assets/js/select2.js?ver=magni-image-flip-for-woocommerce/assets/js/custom.js?ver=magni-image-flip-for-woocommerce/assets/css/magniimage.css?ver=magni-image-flip-for-woocommerce/assets/css/select2.css?ver=

HTML / DOM Fingerprints

CSS Classes
wcmi-has-gallery
Data Attributes
data-cycle-center-formdata-cycle-slidesdata-cycle-fxdata-cycle-speeddata-cycle-timeoutdata-cycle-pause-on-hover+5 more
JS Globals
magniimage_vars
FAQ

Frequently Asked Questions about Magni Image Flip For WooCommerce