NS Custom Placeholder Image for WooCommerce Security & Risk Analysis

wordpress.org/plugins/ns-custom-placeholder-image-for-woocommerce

With this plugin you can change WooCommerce image placeholder with no code required!

100 active installs v1.3.6 PHP + WP 4.5+ Updated Mar 24, 2023
default-imageimageplaceholder-imagewoocommerce-placeholderwoocommerce-placeholder-image
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is NS Custom Placeholder Image for WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

NS Custom Placeholder Image for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The plugin exhibits a mixed security posture, with some positive attributes but significant areas of concern. While the plugin avoids dangerous functions and uses prepared statements for all SQL queries, the lack of proper output escaping is a notable weakness. This, combined with a small but entirely unprotected attack surface consisting of two AJAX handlers, presents a potential avenue for cross-site scripting (XSS) vulnerabilities. The taint analysis, although limited in scope, identified two flows with unsanitized paths, which reinforces the risk of handling user-supplied data without adequate validation and sanitization. The plugin's history of zero known vulnerabilities is a positive indicator of past secure development, but this cannot outweigh the immediate risks identified in the current static analysis. The absence of any vulnerability history could also indicate limited historical scrutiny or a lack of reporting, rather than guaranteed ongoing security. Therefore, while the plugin has some strengths, the identified vulnerabilities in its attack surface and output handling warrant caution.

Key Concerns

  • AJAX handlers without authentication
  • Unsanitized paths in taint flows
  • Insufficient output escaping
  • AJAX handlers without capability checks
Vulnerabilities
None known

NS Custom Placeholder Image for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

NS Custom Placeholder Image for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
26
7 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
3
Bundled Libraries
0

Output Escaping

21% escaped33 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
pe_deactivation_ajax_function (plugineye\plugineye-ajax\plugineye_on_deactivation_function.php:5)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

NS Custom Placeholder Image for WooCommerce Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_pe_deactivation_ajax_functionplugineye\plugineye-ajax\plugineye_on_deactivation_function.php:2
noprivwp_ajax_pe_deactivation_ajax_functionplugineye\plugineye-ajax\plugineye_on_deactivation_function.php:3
WordPress Hooks 15
actionadmin_menuns-admin-options\ns-admin-options-setup.php:7
actionadmin_enqueue_scriptsns-admin-options\ns-admin-options-setup.php:13
actionadmin_initns-custom-placeholder-image-options.php:22
actioninitns-custom-placeholder-image-page.php:64
filterwoocommerce_placeholder_img_srcns-custom-placeholder-image-page.php:67
filterwoocommerce_placeholder_imgns-custom-placeholder-image-page.php:80
actionadmin_enqueue_scriptsns-custom-placeholder-image-page.php:96
actionplugins_loadedns-custom-placeholder-image-page.php:98
filterplugin_action_linksplugineye\plugineye-class.php:96
actionadmin_menuplugineye\plugineye-class.php:113
actionadmin_enqueue_scriptsplugineye\plugineye-class.php:125
actionadmin_enqueue_scriptsplugineye\plugineye-class.php:136
actionactivated_pluginplugineye\plugineye-class.php:147
actionin_admin_footerplugineye\plugineye-class.php:401
actionactivated_pluginplugineye\plugineye-class.php:440
Maintenance & Trust

NS Custom Placeholder Image for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedMar 24, 2023
PHP min version
Downloads6K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

NS Custom Placeholder Image for WooCommerce Developer Profile

NsThemes

24 plugins · 4K total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect NS Custom Placeholder Image for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ns-custom-placeholder-image-for-woocommerce/css/ns-option-css-page.css/wp-content/plugins/ns-custom-placeholder-image-for-woocommerce/css/ns-option-css-custom-page.css/wp-content/plugins/ns-custom-placeholder-image-for-woocommerce/js/ns-option-js-page.js
Script Paths
/wp-content/plugins/ns-custom-placeholder-image-for-woocommerce/js/ns-option-js-page.js
Version Parameters
ns-custom-placeholder-image-for-woocommerce/css/ns-option-css-page.css?ver=ns-custom-placeholder-image-for-woocommerce/css/ns-option-css-custom-page.css?ver=ns-custom-placeholder-image-for-woocommerce/js/ns-option-js-page.js?ver=

HTML / DOM Fingerprints

CSS Classes
attachment-woocommerce_thumbnailsize-woocommerce_thumbnail
Data Attributes
id="nsplaceholderlinkpremium"
FAQ

Frequently Asked Questions about NS Custom Placeholder Image for WooCommerce