Product Rotate 360 Security & Risk Analysis

wordpress.org/plugins/product-rotate-360

360 degree rotational view of product image or other image

20 active installs v1.0.0 PHP + WP 4.7+ Updated Unknown
product-360-degree-viewproduct-360-viewproduct-rotate-360product-view-360web-rotate-360
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Product Rotate 360 Safe to Use in 2026?

Generally Safe

Score 100/100

Product Rotate 360 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The 'product-rotate-360' v1.0.0 plugin presents a generally good security posture based on the provided static analysis. It demonstrates strong adherence to secure coding practices by utilizing prepared statements for all SQL queries and ensuring 100% of its outputs are properly escaped, which significantly mitigates common vulnerabilities like SQL injection and Cross-Site Scripting (XSS). The plugin also has a remarkably small attack surface with no AJAX handlers, REST API routes, cron events, or file operations identified, further limiting potential entry points for attackers. The absence of any recorded vulnerabilities in its history also contributes to a positive security impression, suggesting a well-maintained and secure codebase.

However, a notable concern is the complete lack of nonce checks and capability checks across its code. While the current entry points are limited, this absence means that even for the single shortcode identified, there are no built-in mechanisms to verify user permissions or prevent CSRF attacks if it were to be exploited in a context where unauthorized access is a risk. This reliance on the WordPress core for all authorization is a potential weakness, as any future expansion of the plugin's functionality or changes in WordPress core security handling could introduce vulnerabilities. The taint analysis showing zero flows is positive, but it's important to remember this is based on the current code and doesn't preclude future vulnerabilities if the code evolves without proper security considerations.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Product Rotate 360 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Product Rotate 360 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
40 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped40 total outputs
Attack Surface

Product Rotate 360 Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[product_rotate_360] product-rotate-360.php:26
WordPress Hooks 3
actionadmin_menuproduct-rotate-360.php:23
actionadmin_initproduct-rotate-360.php:24
actionwp_enqueue_scriptsproduct-rotate-360.php:25
Maintenance & Trust

Product Rotate 360 Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedUnknown
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Product Rotate 360 Developer Profile

deb17276

1 plugin · 20 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Product Rotate 360

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/product-rotate-360/assets/js/rotate360-min.js
Script Paths
/wp-content/plugins/product-rotate-360/assets/js/rotate360-min.js
Version Parameters
product-rotate-360/assets/js/rotate360-min.js?ver=

HTML / DOM Fingerprints

CSS Classes
webrorate_wrapperspritespin
Data Attributes
id="webrorate-data-viewid=data-frametime=data-width=data-height=data-imgdir=+4 more
JS Globals
webRotateFree
Shortcode Output
<div id="webrorate-class="webrorate_wrapper"<div class="spritespin"></div>
FAQ

Frequently Asked Questions about Product Rotate 360