Shopizi Security & Risk Analysis

wordpress.org/plugins/shopizi

Woocommerce infinity scroll your products at your awesome site!

0 active installs v1.0.0 PHP + WP 5.1+ Updated Dec 2, 2021
inifinity-scrollshopiziwoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Shopizi Safe to Use in 2026?

Generally Safe

Score 85/100

Shopizi has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The "shopizi" v1.0.0 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices in SQL query handling, utilizing prepared statements exclusively, and boasts a high percentage of properly escaped output. The absence of file operations, external HTTP requests, and known historical vulnerabilities is also a strong indicator of a relatively secure codebase. However, significant concerns arise from its attack surface. Two AJAX handlers are present, and critically, both lack authentication checks. This presents a direct pathway for unauthenticated users to potentially interact with sensitive plugin functionalities. The lack of nonce checks further exacerbates this risk, as it allows for potential Cross-Site Request Forgery (CSRF) attacks against these unprotected AJAX endpoints.

Key Concerns

  • Unprotected AJAX handlers
  • Missing nonce checks on AJAX
  • No capability checks
Vulnerabilities
None known

Shopizi Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Shopizi Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
56 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

93% escaped60 total outputs
Attack Surface
2 unprotected

Shopizi Attack Surface

Entry Points3
Unprotected2

AJAX Handlers 2

authwp_ajax_shopizishopizi.php:292
noprivwp_ajax_shopizishopizi.php:294

Shortcodes 1

[shopizi] shopizi.php:17
WordPress Hooks 1
actioninitshopizi.php:186
Maintenance & Trust

Shopizi Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedDec 2, 2021
PHP min version
Downloads763

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Shopizi Developer Profile

Kirill

4 plugins · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Shopizi

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/shopizi/images/loading.gif

HTML / DOM Fingerprints

CSS Classes
shopizi_styleshopizi_link
Data Attributes
data-maxpages
JS Globals
pagenum$shopizi
Shortcode Output
<ul id="prod_list"<a class="shopizi_link" target="_blank" href="/checkout/?add-to-cart=
FAQ

Frequently Asked Questions about Shopizi