Step Kit OS Security & Risk Analysis

wordpress.org/plugins/step-kit-os

A powerful WooCommerce plugin that enables 3D product customization and strengthens the connection with customers.

0 active installs v1.1.23 PHP 7.4+ WP 5.0+ Updated Jan 29, 2026
3dcustomizationecommerceproduct-customizerwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Step Kit OS Safe to Use in 2026?

Generally Safe

Score 100/100

Step Kit OS has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "step-kit-os" v1.1.23 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and has no recorded vulnerabilities or CVEs. The absence of dangerous functions, external HTTP requests, and bundled libraries further contributes to a generally secure foundation. However, significant concerns arise from its attack surface. With 4 out of 7 entry points lacking authentication checks, there's a substantial risk of unauthorized access or actions being performed within the plugin.

The static analysis highlights that these unprotected entry points are AJAX handlers. While the taint analysis shows no flows with unsanitized paths, the sheer number of unprotected AJAX handlers represents a direct pathway for potential exploitation if an attacker can trigger them. The moderate percentage of properly escaped outputs (74%) also indicates a potential for Cross-Site Scripting (XSS) vulnerabilities, though the absence of critical taint flows suggests these might be less severe or more difficult to exploit.

The plugin's vulnerability history is clean, which is a strong indicator of past security diligence. This, coupled with the sound handling of SQL and lack of dangerous functions, suggests a development team that is at least somewhat security-aware. However, the current static analysis findings, particularly the unprotected AJAX endpoints, present a clear and present danger that needs immediate attention to mitigate the risk of unauthorized access and potential data manipulation.

Key Concerns

  • Unprotected AJAX handlers
  • Unescaped output detected
Vulnerabilities
None known

Step Kit OS Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Step Kit OS Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
68
192 escaped
Nonce Checks
5
Capability Checks
4
File Operations
6
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

74% escaped260 total outputs
Attack Surface
4 unprotected

Step Kit OS Attack Surface

Entry Points7
Unprotected4

AJAX Handlers 4

authwp_ajax_add_to_cartincludes\class-step-kit-os.php:168
noprivwp_ajax_add_to_cartincludes\class-step-kit-os.php:169
authwp_ajax_get_fresh_settingsincludes\class-step-kit-os.php:170
noprivwp_ajax_get_fresh_settingsincludes\class-step-kit-os.php:171

Shortcodes 3

[custom_iframe] includes\class-step-kit-os-shortcodes.php:79
[simulator_button] includes\class-step-kit-os-shortcodes.php:82
[test_div] includes\class-step-kit-os-shortcodes.php:85
WordPress Hooks 29
actionadmin_menuincludes\class-step-kit-os-settings.php:106
actionadmin_initincludes\class-step-kit-os-settings.php:107
actionadmin_noticesincludes\class-step-kit-os-settings.php:1878
actionadmin_noticesincludes\class-step-kit-os-settings.php:1892
actionadmin_noticesincludes\class-step-kit-os-settings.php:1929
actionadmin_noticesincludes\class-step-kit-os-settings.php:1965
actionadmin_noticesincludes\class-step-kit-os-settings.php:1979
actionwoocommerce_after_add_to_cart_buttonincludes\class-step-kit-os-shortcodes.php:98
actioninitincludes\class-step-kit-os.php:146
actionwp_loadedincludes\class-step-kit-os.php:147
actionwp_loginincludes\class-step-kit-os.php:148
actionwp_loadedincludes\class-step-kit-os.php:149
actionlogin_enqueue_scriptsincludes\class-step-kit-os.php:150
actionwp_enqueue_scriptsincludes\class-step-kit-os.php:152
actionwp_enqueue_scriptsincludes\class-step-kit-os.php:153
actionlogin_enqueue_scriptsincludes\class-step-kit-os.php:154
actionwoocommerce_add_to_cartincludes\class-step-kit-os.php:157
filterwoocommerce_get_item_dataincludes\class-step-kit-os.php:158
actionwoocommerce_add_order_item_metaincludes\class-step-kit-os.php:159
filterwoocommerce_order_item_display_meta_keyincludes\class-step-kit-os.php:160
filterwoocommerce_cart_loaded_from_sessionincludes\class-step-kit-os.php:161
filterwoocommerce_update_order_review_fragmentsincludes\class-step-kit-os.php:162
filterwoocommerce_add_to_cart_fragmentsincludes\class-step-kit-os.php:163
filterwoocommerce_get_cart_item_from_sessionincludes\class-step-kit-os.php:164
filterwoocommerce_add_cart_itemincludes\class-step-kit-os.php:165
actionsend_headersincludes\class-step-kit-os.php:173
actionadmin_noticesstep-kit-os.php:73
actionplugins_loadedstep-kit-os.php:127
actionadmin_initstep-kit-os.php:197
Maintenance & Trust

Step Kit OS Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 29, 2026
PHP min version7.4
Downloads475

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Step Kit OS Developer Profile

stepkitos

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Step Kit OS

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/step-kit-os/assets/css//wp-content/plugins/step-kit-os/assets/js//wp-content/plugins/step-kit-os/assets/vendor//wp-content/plugins/step-kit-os/includes/
Script Paths
/wp-content/plugins/step-kit-os/assets/js/step-kit-os-frontend.js/wp-content/plugins/step-kit-os/assets/js/step-kit-os-admin.js
Version Parameters
step-kit-os/assets/css/step-kit-os-frontend.css?ver=step-kit-os/assets/css/step-kit-os-admin.css?ver=step-kit-os/assets/js/step-kit-os-frontend.js?ver=step-kit-os/assets/js/step-kit-os-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
step-kit-os
JS Globals
stepKitOSFrontend
FAQ

Frequently Asked Questions about Step Kit OS