Ultimate WooCommerce CloudZoom for Product Images Security & Risk Analysis

wordpress.org/plugins/product-cloudzoom-ultimate-for-woocommerce-product-images

Add Cloud Zoom effect to WooCommerce product photos on single product pages. Adjust settings. Work with ANY theme.

10 active installs v1.2 PHP + WP 3.5+ Updated Apr 24, 2019
accordioncloudzoomproduct-zoomwoocommercezoom
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Ultimate WooCommerce CloudZoom for Product Images Safe to Use in 2026?

Generally Safe

Score 85/100

Ultimate WooCommerce CloudZoom for Product Images has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The 'product-cloudzoom-ultimate-for-woocommerce-product-images' plugin version 1.2 exhibits a mixed security posture. The static analysis reveals an extremely small attack surface, with no identified AJAX handlers, REST API routes, shortcodes, or cron events. This indicates a deliberate effort to minimize potential entry points for attackers. Furthermore, the absence of dangerous functions and file operations is a positive sign. However, a significant concern arises from the complete lack of output escaping, meaning any data rendered by the plugin is potentially vulnerable to cross-site scripting (XSS) attacks. The absence of nonce and capability checks also implies that even if interactions were present, they might not be properly secured against unauthorized access or manipulation. The vulnerability history is clean, with no recorded CVEs, which is reassuring but doesn't negate the identified risks within the code itself.

While the lack of known vulnerabilities and a minimal attack surface are strengths, the critical absence of output escaping presents a direct and high-risk vulnerability. The plugin needs immediate attention to address the unescaped output to prevent potential XSS attacks. The absence of capability and nonce checks, while not directly creating an attack vector in this specific analysis due to the lack of entry points, suggests a potential for future vulnerabilities if new entry points are introduced without proper security controls. The clean vulnerability history is a positive indicator of past development practices, but the current code analysis highlights an area requiring urgent remediation.

Key Concerns

  • Output escaping is not implemented
  • No nonce checks found
  • No capability checks found
Vulnerabilities
None known

Ultimate WooCommerce CloudZoom for Product Images Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Ultimate WooCommerce CloudZoom for Product Images Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped6 total outputs
Attack Surface

Ultimate WooCommerce CloudZoom for Product Images Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_initmgwoocommercecloudzoom.php:26
actionwp_enqueue_scriptsmgwoocommercecloudzoom.php:27
actionwp_footermgwoocommercecloudzoom.php:28
actionplugins_loadedmgwoocommercecloudzoom.php:31
filterplugin_row_metamgwoocommercecloudzoom.php:33
filtersingle_product_small_thumbnail_sizemgwoocommercecloudzoom.php:35
actionadmin_noticesmgwoocommercecloudzoom.php:37
Maintenance & Trust

Ultimate WooCommerce CloudZoom for Product Images Maintenance & Trust

Maintenance Signals

WordPress version tested5.1.22
Last updatedApr 24, 2019
PHP min version
Downloads9K

Community Trust

Rating64/100
Number of ratings5
Active installs10
Developer Profile

Ultimate WooCommerce CloudZoom for Product Images Developer Profile

MagniumThemes

8 plugins · 810 total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Ultimate WooCommerce CloudZoom for Product Images

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/product-cloudzoom-ultimate-for-woocommerce-product-images/css/mgwoocommercecloudzoom-admin.css/wp-content/plugins/product-cloudzoom-ultimate-for-woocommerce-product-images/js/mgwoocommercecloudzoom-admin.js/wp-content/plugins/product-cloudzoom-ultimate-for-woocommerce-product-images/css/mgwoocommercecloudzoom.css/wp-content/plugins/product-cloudzoom-ultimate-for-woocommerce-product-images/js/mgwoocommercecloudzoom.js
Script Paths
/wp-content/plugins/product-cloudzoom-ultimate-for-woocommerce-product-images/js/mgwoocommercecloudzoom-admin.js/wp-content/plugins/product-cloudzoom-ultimate-for-woocommerce-product-images/js/mgwoocommercecloudzoom.js

HTML / DOM Fingerprints

CSS Classes
mgwcz-message
JS Globals
MGWCZ
FAQ

Frequently Asked Questions about Ultimate WooCommerce CloudZoom for Product Images