TP WooCommerce Product Gallery Security & Risk Analysis

wordpress.org/plugins/tp-woocommerce-product-gallery

Boost your sales by replacing WooCommerce's default product gallery with a beautiful, feature-rich gallery.

1K active installs v2.0.2 PHP + WP 4.5+ Updated Apr 5, 2026
product-gallery-sliderwoocommerce-product-gallery-carouselwoocommerce-product-gallery-sliderwoocommerce-product-image-slider
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is TP WooCommerce Product Gallery Safe to Use in 2026?

Generally Safe

Score 100/100

TP WooCommerce Product Gallery has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The static analysis of tp-woocommerce-product-gallery v2.0.1 reveals a generally strong security posture. The absence of SQL queries without prepared statements, a very high percentage of properly escaped output, and no identified dangerous functions or file operations are positive indicators. The plugin also boasts a completely clean vulnerability history with no known CVEs, which is excellent. However, there are a few areas that warrant attention. The presence of an external HTTP request without further context is a potential risk, as it could be exploited if the external service is compromised or the request is improperly handled. Additionally, the complete lack of nonce checks and capability checks across all identified entry points (even though the entry point count is zero) suggests a potential gap in robust access control if new entry points are added or if the plugin's scope expands in future versions. The absence of taint analysis findings is a good sign, indicating no immediately obvious unsanitized data flows.

Key Concerns

  • External HTTP request without evident sanitization/validation
  • Zero nonce checks across all potential entry points
  • Zero capability checks across all potential entry points
Vulnerabilities
None known

TP WooCommerce Product Gallery Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

TP WooCommerce Product Gallery Release Timeline

v2.0.2Current
v2.0.1
v2.0.0
v1.1.9
v1.1.8
v1.1.7
v1.1.6
Code Analysis
Analyzed Mar 16, 2026

TP WooCommerce Product Gallery Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
124 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

99% escaped125 total outputs
Attack Surface

TP WooCommerce Product Gallery Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 13
actionplugins_loadedincludes\class-woocommerce-product-gallery.php:143
actionadmin_enqueue_scriptsincludes\class-woocommerce-product-gallery.php:158
actionadmin_enqueue_scriptsincludes\class-woocommerce-product-gallery.php:159
actionadmin_menuincludes\class-woocommerce-product-gallery.php:161
filterplugin_row_metaincludes\class-woocommerce-product-gallery.php:164
actionwp_enqueue_scriptsincludes\class-woocommerce-product-gallery.php:181
actionwp_enqueue_scriptsincludes\class-woocommerce-product-gallery.php:182
actionloop_startincludes\class-woocommerce-product-gallery.php:184
actionloop_startincludes\class-woocommerce-product-gallery.php:185
actionwp_footerincludes\class-woocommerce-product-gallery.php:187
actionwp_footerincludes\class-woocommerce-product-gallery.php:188
actionwoocommerce_before_single_product_summarypublic\class-woocommerce-product-gallery-public.php:127
actionbefore_woocommerce_inittp-woocommerce-product-gallery.php:53
Maintenance & Trust

TP WooCommerce Product Gallery Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 5, 2026
PHP min version
Downloads53K

Community Trust

Rating76/100
Number of ratings26
Active installs1K
Developer Profile

TP WooCommerce Product Gallery Developer Profile

Payment Plugins

76 plugins · 308K total installs

85
trust score
Avg Security Score
95/100
Avg Patch Time
84 days
View full developer profile
Detection Fingerprints

How We Detect TP WooCommerce Product Gallery

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tp-woocommerce-product-gallery/css/woocommerce-product-gallery-admin.css/wp-content/plugins/tp-woocommerce-product-gallery/css/jquery.minicolors.css/wp-content/plugins/tp-woocommerce-product-gallery/js/jquery.minicolors.min.js/wp-content/plugins/tp-woocommerce-product-gallery/js/woocommerce-product-gallery-admin.js
Script Paths
/wp-content/plugins/tp-woocommerce-product-gallery/js/woocommerce-product-gallery-admin.js/wp-content/plugins/tp-woocommerce-product-gallery/js/jquery.minicolors.min.js
Version Parameters
tp-woocommerce-product-gallery/css/woocommerce-product-gallery-admin.css?ver=tp-woocommerce-product-gallery/css/jquery.minicolors.css?ver=tp-woocommerce-product-gallery/js/jquery.minicolors.min.js?ver=tp-woocommerce-product-gallery/js/woocommerce-product-gallery-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
tpwpg-thumbnail-wraptpwpg-dots-wraptpwpg-arrows-wraptpwpg-content-wraptpwpg-thumbnail-itemtpwpg-image-itemtpwpg-gallery-wrappertpwpg-main-gallery-carousel
HTML Comments
<!-- TP WooCommerce Product Gallery --><!-- tpwpg: This plugin adds the gallery functionality. -->
Data Attributes
data-tpwpg-optionsdata-tpwpg-thumbnail-positiondata-tpwpg-thumbnail-columnsdata-tpwpg-dots-colordata-tpwpg-arrow-color
JS Globals
tp_wc_gallery_params
Shortcode Output
[tp_wc_gallery]
FAQ

Frequently Asked Questions about TP WooCommerce Product Gallery