Touchtry RoomFit Security & Risk Analysis

wordpress.org/plugins/touchtry-roomfit

Touchtry RoomFit AR allows your customers to virtually place and try furniture in their room using Augmented Reality. Seamless integration with WooCom …

0 active installs v1.0.2 PHP 7.2+ WP 5.5+ Updated Feb 26, 2026
augmented-realityfurniture-arroom-visualizationvirtual-try-on-furniturewoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Touchtry RoomFit Safe to Use in 2026?

Generally Safe

Score 100/100

Touchtry RoomFit has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The 'touchtry-roomfit' plugin version 1.0.2 exhibits a strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points is a significant strength, indicating a minimal attack surface. Furthermore, the code effectively utilizes prepared statements for all SQL queries and incorporates nonce and capability checks, which are fundamental security practices. The high percentage of properly escaped output further mitigates the risk of cross-site scripting vulnerabilities.

The vulnerability history also appears clean, with no recorded CVEs, suggesting a good track record for this plugin. The taint analysis did not reveal any flows with unsanitized paths, further reinforcing the impression of secure coding.

While the plugin demonstrates excellent adherence to core WordPress security principles, a minor concern arises from the fact that not all output is properly escaped (76%). This small percentage of unescaped output, though not critical given the other security measures, represents a potential, albeit low, risk of XSS if the unescaped outputs are ever exposed to user-controlled data. Overall, this plugin is well-secured, with only a marginal area for improvement.

Key Concerns

  • Some output not properly escaped
Vulnerabilities
None known

Touchtry RoomFit Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Touchtry RoomFit Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
19
61 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

76% escaped80 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<furniture-ar-viewer> (furniture-ar-viewer.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Touchtry RoomFit Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionbefore_woocommerce_initfurniture-ar-viewer.php:21
actionadmin_enqueue_scriptsfurniture-ar-viewer.php:86
actionadmin_menufurniture-ar-viewer.php:103
actionadd_meta_boxesfurniture-ar-viewer.php:170
actionsave_post_productfurniture-ar-viewer.php:171
actionadmin_noticesfurniture-ar-viewer.php:174
actionwp_enqueue_scriptsfurniture-ar-viewer.php:197
actionwoocommerce_after_add_to_cart_buttonfurniture-ar-viewer.php:254
actionwoocommerce_after_add_to_cart_formfurniture-ar-viewer.php:255
actionwoocommerce_single_product_summaryfurniture-ar-viewer.php:256
actionwoocommerce_after_single_product_summaryfurniture-ar-viewer.php:257
Maintenance & Trust

Touchtry RoomFit Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedFeb 26, 2026
PHP min version7.2
Downloads265

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

Touchtry RoomFit Developer Profile

touchtry

4 plugins · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Touchtry RoomFit

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/touchtry-roomfit/assets/css/admin-dashboard.css/wp-content/plugins/touchtry-roomfit/assets/js/admin-dashboard.js/wp-content/plugins/touchtry-roomfit/assets/css/admin-meta.css/wp-content/plugins/touchtry-roomfit/assets/css/frontend.css
Script Paths
/wp-content/plugins/touchtry-roomfit/assets/js/admin-dashboard.js
Version Parameters
/wp-content/plugins/touchtry-roomfit/assets/css/admin-dashboard.css?ver=/wp-content/plugins/touchtry-roomfit/assets/js/admin-dashboard.js?ver=/wp-content/plugins/touchtry-roomfit/assets/css/admin-meta.css?ver=/wp-content/plugins/touchtry-roomfit/assets/css/frontend.css?ver=

HTML / DOM Fingerprints

CSS Classes
furniture-ar-tryon-wrapfurniture-ar-tryon-btntouchrf-meta-help
HTML Comments
<!-- ✅ Issue #5 FIX: Declare WooCommerce HPOS compatibility --><!-- ✅ Issue #2 FIX: WooCommerce dependency check --><!-- 1) Admin enqueue (Dashboard page only) + Meta box CSS (Product edit/add only) --><!-- NOTE: Admin assets can load even without WooCommerce (dashboard page) -->+18 more
Data Attributes
id="touchrf_ar_tryon_link"name="touchrf_ar_tryon_link"value=""placeholder="https://..."name="touchrf_ar_tryon_nonce"aria-label="Try this furniture in augmented reality"
Shortcode Output
<div class="furniture-ar-tryon-wrap"><a class="furniture-ar-tryon-btn" href="" target="_blank" rel="noopener noreferrer" aria-label="Try this furniture in augmented reality">Try it On</a></div>
FAQ

Frequently Asked Questions about Touchtry RoomFit