VidShop – Shoppable Videos for WooCommerce Security & Risk Analysis

wordpress.org/plugins/vidshop-for-woocommerce

Engage customers with swipeable shoppable videos, seamless checkout, and powerful analytics for WooCommerce.

400 active installs v1.1.5 PHP 7.4+ WP 5.8+ Updated Jan 16, 2026
mobile-shoppingproduct-videosshoppable-videosvideo-commercewoocommerce-videos
97
A · Safe
CVEs total1
Unpatched0
Last CVEJan 27, 2026
Safety Verdict

Is VidShop – Shoppable Videos for WooCommerce Safe to Use in 2026?

Generally Safe

Score 97/100

VidShop – Shoppable Videos for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Jan 27, 2026Updated 3mo ago
Risk Assessment

The vidshop-for-woocommerce plugin v1.1.5 exhibits a generally strong security posture based on the static analysis. The code demonstrates excellent practices with 100% output escaping and 96% of SQL queries utilizing prepared statements. The absence of dangerous functions, file operations, and external HTTP requests is also a positive sign. Furthermore, the limited attack surface, with only two entry points and no unprotected ones, further contributes to its secure design.

However, the vulnerability history presents a significant concern. The presence of one known high-severity CVE, specifically an SQL Injection vulnerability, even though it is currently patched, suggests a past weakness that could be exploited if the plugin were not updated. The nature of SQL Injection vulnerabilities indicates potential issues with how user-supplied data is handled, which is a critical area for security. While the current code analysis does not reveal any active taint flows or direct SQL injection risks, the historical vulnerability is a reminder of potential complexities in data handling.

In conclusion, vidshop-for-woocommerce v1.1.5 is well-implemented from a static analysis perspective, with strong adherence to secure coding practices. The primary weakness lies in its past vulnerability history, specifically the high-severity SQL injection. Users must ensure they are running the latest version to benefit from past patches. The lack of any current critical or high-severity findings in the static analysis is encouraging, but the historical context necessitates vigilance.

Key Concerns

  • Past high severity SQL Injection vulnerability
Vulnerabilities
1 published

VidShop – Shoppable Videos for WooCommerce Security Vulnerabilities

CVEs by Year

1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

High
1

1 total CVE

CVE-2026-0702high · 7.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

VidShop – Shoppable Videos for WooCommerce <= 1.1.4 - Unauthenticated Time-Based SQL Injection via 'fields'

Jan 27, 2026 Patched in 1.1.5 (1d)
Version History

VidShop – Shoppable Videos for WooCommerce Release Timeline

v1.1.5Current
v1.1.41 CVE
v1.1.31 CVE
v1.1.21 CVE
v1.1.11 CVE
v1.1.01 CVE
v1.0.31 CVE
v1.0.21 CVE
v1.0.11 CVE
v1.0.01 CVE
Code Analysis
Analyzed Mar 16, 2026

VidShop – Shoppable Videos for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
50 prepared
Unescaped Output
0
22 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

96% prepared52 total queries

Output Escaping

100% escaped22 total outputs
Attack Surface

VidShop – Shoppable Videos for WooCommerce Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 1

authwp_ajax_vsfw_dismiss_review_noticeincludes\admin\class-review-notice.php:30

Shortcodes 1

[vsfw-videos] includes\frontend\class-frontend-loader.php:44
WordPress Hooks 14
actionadmin_initincludes\admin\class-activation-handler.php:30
actionadmin_menuincludes\admin\class-admin-loader.php:52
actionadmin_noticesincludes\admin\class-admin-loader.php:55
actionadmin_noticesincludes\admin\class-admin-loader.php:56
actionadmin_noticesincludes\admin\class-admin-loader.php:57
filteradmin_footer_textincludes\admin\class-admin-loader.php:60
filteradmin_body_classincludes\admin\class-admin-loader.php:63
actionwp_enqueue_scriptsincludes\admin\class-admin-loader.php:75
actionadmin_noticesincludes\admin\class-review-notice.php:27
actionplugins_loadedincludes\database\class-database-module.php:42
actioninitincludes\frontend\class-frontend-loader.php:33
actionwp_enqueue_scriptsincludes\frontend\class-frontend-loader.php:36
actionrest_api_initincludes\rest-api\class-rest-api-module.php:73
actionplugins_loadedvidshop-for-woocommerce.php:41
Maintenance & Trust

VidShop – Shoppable Videos for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 16, 2026
PHP min version7.4
Downloads2K

Community Trust

Rating100/100
Number of ratings3
Active installs400
Developer Profile

VidShop – Shoppable Videos for WooCommerce Developer Profile

WPCreatix

2 plugins · 900 total installs

99
trust score
Avg Security Score
99/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect VidShop – Shoppable Videos for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/vidshop-for-woocommerce/assets/css/admin-style.css/wp-content/plugins/vidshop-for-woocommerce/assets/css/admin-style.min.css/wp-content/plugins/vidshop-for-woocommerce/assets/js/admin-script.js/wp-content/plugins/vidshop-for-woocommerce/assets/js/admin-script.min.js/wp-content/plugins/vidshop-for-woocommerce/assets/css/front-style.css/wp-content/plugins/vidshop-for-woocommerce/assets/css/front-style.min.css/wp-content/plugins/vidshop-for-woocommerce/assets/js/front-script.js/wp-content/plugins/vidshop-for-woocommerce/assets/js/front-script.min.js
Script Paths
/wp-content/plugins/vidshop-for-woocommerce/assets/js/admin-script.js/wp-content/plugins/vidshop-for-woocommerce/assets/js/front-script.js
Version Parameters
vidshop-for-woocommerce/assets/css/admin-style.css?ver=vidshop-for-woocommerce/assets/js/admin-script.js?ver=vidshop-for-woocommerce/assets/css/front-style.css?ver=vidshop-for-woocommerce/assets/js/front-script.js?ver=

HTML / DOM Fingerprints

CSS Classes
vsfw-adminvsfw-page
Data Attributes
data-vsfw-video-productdata-vsfw-video-iddata-vsfw-product-iddata-vsfw-product-urldata-vsfw-product-position
JS Globals
vsfw_params
Shortcode Output
[vidshop_video]
FAQ

Frequently Asked Questions about VidShop – Shoppable Videos for WooCommerce