Uix Products Security & Risk Analysis

wordpress.org/plugins/uix-products

Readily organize & present your artworks, themes, plugins with Uix Products template files. Convenient for theme customization.

10 active installs v1.6.2 PHP 5.6+ WP 4.2+ Updated Apr 24, 2025
portfolioproductproductsshowcasework-show
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Uix Products Safe to Use in 2026?

Generally Safe

Score 100/100

Uix Products has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

The "uix-products" v1.6.2 plugin exhibits a strong security posture in terms of its attack surface and vulnerability history. The static analysis reveals no exposed AJAX handlers, REST API routes, shortcodes, or cron events that lack authentication or permission checks, indicating a minimal attack surface. Furthermore, the absence of any recorded CVEs, past or present, and no common vulnerability types suggests a history of responsible development and maintenance. The code signals also point to good practices, with all SQL queries utilizing prepared statements and a high percentage of output being properly escaped. Nonce and capability checks are present, and critical taint analysis flows are absent.

However, the static analysis does highlight a potential area for concern: the presence of one file operation. While not inherently a vulnerability, file operations can introduce risks if not handled with extreme care regarding user input and access controls. The 80% output escaping, while good, means 20% of outputs are not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if malicious data is processed and displayed without proper sanitization. The bundled libraries, TinyMCE and jQuery, are standard but should be monitored for potential vulnerabilities in their own right, though no specific issues are indicated here.

In conclusion, the "uix-products" plugin demonstrates a commendable commitment to security, with a small attack surface and a clean vulnerability history. The primary areas to monitor would be the secure handling of the single file operation and further improving output escaping to reach 100%. Despite these minor points, the plugin appears to be a relatively safe option based on the provided data.

Key Concerns

  • 20% of outputs not properly escaped
  • Presence of one file operation
Vulnerabilities
None known

Uix Products Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Uix Products Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
131
509 escaped
Nonce Checks
3
Capability Checks
5
File Operations
1
External Requests
0
Bundled Libraries
2

Bundled Libraries

TinyMCEjQuery

Output Escaping

80% escaped640 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
<custom-css> (helper\tabs\custom-css.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Uix Products Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 45
actionadmin_enqueue_scriptshelper\settings.php:22
actionfeatured_image_column_initincludes\admin\post-type-init.php:9
filterfeatured_image_column_post_typesincludes\admin\post-type-init.php:11
actioninitincludes\admin\post-type-init.php:33
filtergallery_metabox_post_typesincludes\admin\post-type-init.php:134
actionrestrict_manage_postsincludes\admin\post-type-init.php:193
actionload-post.phpincludes\admin\post-type-init.php:316
actionload-post-new.phpincludes\admin\post-type-init.php:317
filtermanage_edit-uix_products_columnsincludes\admin\post-type-init.php:348
actionmanage_uix_products_posts_custom_columnincludes\admin\post-type-init.php:375
filterparse_queryincludes\admin\post-type-init.php:535
filtermanage_edit-uix_products_sortable_columnsincludes\admin\post-type-init.php:579
filterpre_post_titleincludes\admin\post-type-init.php:595
actionadd_meta_boxesincludes\admin\uix-custom-metaboxes\init.php:85
actionsave_postincludes\admin\uix-custom-metaboxes\init.php:89
actionadmin_enqueue_scriptsincludes\admin\uix-custom-metaboxes\init.php:93
actionadmin_initincludes\admin\uix-custom-metaboxes\init.php:134
filteradmin_body_classincludes\admin\uix-custom-metaboxes\init.php:137
actionadmin_inituix-products.php:35
actioninituix-products.php:47
actionadmin_print_scripts-edit.phpuix-products.php:48
actionadmin_print_scripts-post-new.phpuix-products.php:49
actionadmin_print_scripts-post.phpuix-products.php:50
actionadmin_enqueue_scriptsuix-products.php:52
actionwp_enqueue_scriptsuix-products.php:53
actionwp_enqueue_scriptsuix-products.php:54
actioncurrent_screenuix-products.php:55
actionadmin_inituix-products.php:56
actionadmin_inituix-products.php:57
actionadmin_inituix-products.php:58
actionadmin_menuuix-products.php:59
actionwp_headuix-products.php:60
actionwp_headuix-products.php:61
filterbody_classuix-products.php:62
actionwidgets_inituix-products.php:63
filterpost_thumbnail_htmluix-products.php:64
actionafter_setup_themeuix-products.php:65
filterinituix-products.php:66
filternext_posts_link_attributesuix-products.php:67
filterprevious_posts_link_attributesuix-products.php:68
actionadmin_noticesuix-products.php:454
actionadmin_noticesuix-products.php:455
filterfeatured_image_column_post_typesuix-products.php:1033
filteroption_posts_per_pageuix-products.php:1263
actionplugins_loadeduix-products.php:1530
Maintenance & Trust

Uix Products Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 24, 2025
PHP min version5.6
Downloads6K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Uix Products Developer Profile

UIUX Lab

6 plugins · 540 total installs

86
trust score
Avg Security Score
97/100
Avg Patch Time
32 days
View full developer profile
Detection Fingerprints

How We Detect Uix Products

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/uix-products/assets/add-ons/prettyPhoto/jquery.prettyPhoto.js/wp-content/plugins/uix-products/assets/add-ons/prettyPhoto/jquery.prettyPhoto.css/wp-content/plugins/uix-products/assets/add-ons/muuri/muuri.min.js/wp-content/plugins/uix-products/includes/admin/css/style.min.css/wp-content/plugins/uix-products/includes/admin/js/core.min.js
Script Paths
/wp-content/plugins/uix-products/assets/add-ons/prettyPhoto/jquery.prettyPhoto.js/wp-content/plugins/uix-products/assets/add-ons/muuri/muuri.min.js/wp-content/plugins/uix-products/includes/admin/js/core.min.js
Version Parameters
uix-products/assets/add-ons/prettyPhoto/jquery.prettyPhoto.js?ver=uix-products/assets/add-ons/prettyPhoto/jquery.prettyPhoto.css?ver=uix-products/assets/add-ons/muuri/muuri.min.js?ver=uix-products/includes/admin/css/style.min.css?ver=uix-products/includes/admin/js/core.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
uix-products-adminuix-products-admin-tooltip
Data Attributes
data-uix-products-iddata-uix-products-settings
JS Globals
uixProductsAdmin
FAQ

Frequently Asked Questions about Uix Products