Shimmer Loading effect for Woocommerce Security & Risk Analysis

wordpress.org/plugins/products-skeleton-loader-free

Products Skeleton Loader Adds a Premium Skeleton Loading Animation to your website to attract your visitros / users. Products Skeleton Loader uses cor …

60 active installs v1.0.0 PHP 7.0+ WP 4.9+ Updated Nov 9, 2022
animationloadingproductsskeletonwoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Shimmer Loading effect for Woocommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Shimmer Loading effect for Woocommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The 'products-skeleton-loader-free' plugin version 1.0.0 demonstrates a mixed security posture. On the positive side, it exhibits excellent practices regarding SQL queries and output escaping, with 100% of both being handled securely. The absence of dangerous functions, file operations, and external HTTP requests is also a strong indicator of good coding hygiene. Furthermore, the plugin has no recorded vulnerability history, suggesting a well-maintained or relatively new codebase with no known exploitable flaws.

However, a significant concern arises from the presence of two AJAX handlers, both of which lack authentication checks. This creates a direct attack surface where any unauthenticated user could potentially trigger these handlers, leading to unintended actions or information disclosure if the handler's functionality is sensitive. While taint analysis shows no current issues, the unprotected AJAX endpoints represent a significant risk that could be exploited if the functionality within them is not properly secured against malicious input.

In conclusion, while the plugin excels in several key security areas like data handling and has a clean vulnerability record, the unprotected AJAX endpoints are a critical weakness. The absence of nonce checks on these entry points leaves them vulnerable to CSRF attacks and unauthorized execution. Addressing these unprotected AJAX handlers should be the highest priority to improve the plugin's overall security.

Key Concerns

  • Unprotected AJAX handlers found
  • Missing nonce checks on AJAX handlers
Vulnerabilities
None known

Shimmer Loading effect for Woocommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Shimmer Loading effect for Woocommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
40 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped40 total outputs
Attack Surface
2 unprotected

Shimmer Loading effect for Woocommerce Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_pslfree_dynaminc_cssincludes\class-pslfree.php:181
noprivwp_ajax_pslfree_dynaminc_cssincludes\class-pslfree.php:182
WordPress Hooks 13
actionplugins_loadedincludes\class-pslfree.php:141
actionadmin_enqueue_scriptsincludes\class-pslfree.php:156
actionadmin_enqueue_scriptsincludes\class-pslfree.php:157
actionadmin_menuincludes\class-pslfree.php:160
actionadmin_initincludes\class-pslfree.php:163
actionwp_enqueue_scriptsincludes\class-pslfree.php:178
actionwp_enqueue_scriptsincludes\class-pslfree.php:179
actionwoocommerce_before_shop_loop_item_titleincludes\custom-products.php:23
filterwoocommerce_post_classincludes\custom-products.php:92
filterplugin_row_metaproducts-skeleton-loader.php:101
filterplugin_action_linksproducts-skeleton-loader.php:103
filternetwork_admin_plugin_action_linksproducts-skeleton-loader.php:104
actionadmin_noticesproducts-skeleton-loader.php:207
Maintenance & Trust

Shimmer Loading effect for Woocommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedNov 9, 2022
PHP min version7.0
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs60
Developer Profile

Shimmer Loading effect for Woocommerce Developer Profile

TechnoDigitz

3 plugins · 190 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Shimmer Loading effect for Woocommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/products-skeleton-loader-free/assets/css/pslfree_style.css/wp-content/plugins/products-skeleton-loader-free/assets/js/pslfree_script.js
Script Paths
/wp-content/plugins/products-skeleton-loader-free/assets/js/pslfree_script.js
Version Parameters
products-skeleton-loader-free/assets/css/pslfree_style.css?ver=products-skeleton-loader-free/assets/js/pslfree_script.js?ver=

HTML / DOM Fingerprints

CSS Classes
pslfree_noticepslfree_btn_secondary
Data Attributes
data-pslfree-settings
JS Globals
pslfree
FAQ

Frequently Asked Questions about Shimmer Loading effect for Woocommerce