Secondary Product Image for WooCommerce Security & Risk Analysis

wordpress.org/plugins/secondary-product-image-for-woocommerce

Secondary Product Image for WooCommerce adds a hover effect that will reveal a secondary product thumbnail to product images on your WooCommerce produ …

2K active installs v1.0.2 PHP 7.4+ WP 6.0+ Updated Dec 4, 2025
featured-imageflipproductproduct-imagewoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Secondary Product Image for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Secondary Product Image for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The "secondary-product-image-for-woocommerce" plugin v1.0.2 presents a generally strong security posture based on the provided static analysis and vulnerability history. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events, particularly those lacking authentication or permission checks, significantly limits the plugin's attack surface. Furthermore, the code signals indicate good development practices, with no dangerous functions identified, all SQL queries using prepared statements, and a respectable 64% of outputs being properly escaped. The presence of nonce and capability checks, though only one of each, is also a positive sign. The complete lack of vulnerability history, including CVEs and past issues, further suggests a mature and well-maintained codebase.

Despite the positive indicators, a notable concern arises from the output escaping. With 36% of outputs not being properly escaped, there is a potential for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data or plugin-generated content is not correctly sanitized before being displayed. While no taint flows were identified in this analysis, a significant percentage of unescaped output still represents a risk. The limited scope of the static analysis (0 flows analyzed) also means that complex or subtle vulnerabilities might have been missed. Therefore, while the plugin appears robust with no known major flaws, the unescaped output warrants attention for potential improvements.

Key Concerns

  • Unescaped output present (36%)
Vulnerabilities
None known

Secondary Product Image for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Secondary Product Image for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
4
7 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

64% escaped11 total outputs
Attack Surface

Secondary Product Image for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 16
actionwp_enqueue_scriptsincludes\wpzoom-wc-spi-frontend.php:30
actionwoocommerce_before_shop_loop_item_titleincludes\wpzoom-wc-spi-frontend.php:31
filterpost_classincludes\wpzoom-wc-spi-frontend.php:32
filterwpzoom_wc_spi_secondary_product_thumbnailincludes\wpzoom-wc-spi-frontend.php:34
actionadd_meta_boxesincludes\wpzoom-wc-spi-metabox.php:75
filterattachment_fields_to_editincludes\wpzoom-wc-spi-metabox.php:78
actionadmin_enqueue_scriptsincludes\wpzoom-wc-spi-metabox.php:81
actionadmin_print_scripts-post.phpincludes\wpzoom-wc-spi-metabox.php:82
actionadmin_print_scripts-post-new.phpincludes\wpzoom-wc-spi-metabox.php:83
actiondelete_attachmentincludes\wpzoom-wc-spi-metabox.php:87
filteris_protected_metaincludes\wpzoom-wc-spi-metabox.php:88
actionadmin_initsecondary-product-image-for-woocommerce.php:78
actioninitsecondary-product-image-for-woocommerce.php:80
actionplugins_loadedsecondary-product-image-for-woocommerce.php:81
actionplugins_loadedsecondary-product-image-for-woocommerce.php:82
actionadmin_noticessecondary-product-image-for-woocommerce.php:136
Maintenance & Trust

Secondary Product Image for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 4, 2025
PHP min version7.4
Downloads11K

Community Trust

Rating70/100
Number of ratings2
Active installs2K
Developer Profile

Secondary Product Image for WooCommerce Developer Profile

WPZOOM

24 plugins · 337K total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
102 days
View full developer profile
Detection Fingerprints

How We Detect Secondary Product Image for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/secondary-product-image-for-woocommerce/assets/css/secondary-product-image-for-woocommerce.css/wp-content/plugins/secondary-product-image-for-woocommerce/assets/js/secondary-product-image-for-woocommerce.js
Script Paths
wpzoom-wc-spi-script
Version Parameters
secondary-product-image-for-woocommerce/assets/css/secondary-product-image-for-woocommerce.css?ver=secondary-product-image-for-woocommerce/assets/js/secondary-product-image-for-woocommerce.js?ver=

HTML / DOM Fingerprints

CSS Classes
wpzoom-secondary-image-container
FAQ

Frequently Asked Questions about Secondary Product Image for WooCommerce