
WCBox Lite – Product Slider Plugin For Woocommerce Security & Risk Analysis
wordpress.org/plugins/wcbox-liteWCBox – Woocommerce Plugin is help to display a list of products on WordPress Sidebar using Top Rated Products, Recent Products,Best Selling Products, …
Is WCBox Lite – Product Slider Plugin For Woocommerce Safe to Use in 2026?
Generally Safe
Score 85/100WCBox Lite – Product Slider Plugin For Woocommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wcbox-lite" v1.1 plugin exhibits a mixed security posture. While it has no recorded vulnerability history, indicating a potentially stable track record, the static analysis reveals several concerning areas. The presence of an unprotected AJAX handler represents a significant entry point that could be exploited without proper authentication. Furthermore, the taint analysis highlights two flows with unsanitized paths, both classified as high severity. This suggests a risk of malicious data being processed without adequate validation, potentially leading to code injection or other vulnerabilities.
The code analysis also points to the use of a dangerous function, `create_function`, which is known to have security implications. Coupled with the fact that none of the SQL queries use prepared statements and a very low percentage (2%) of outputs are properly escaped, the plugin appears to lack fundamental security best practices in handling data and user input. The limited attack surface and the presence of nonce and capability checks are positive signs, but they are overshadowed by the identified high-severity risks and the overall lack of robust input validation and output escaping.
Key Concerns
- Unprotected AJAX handler
- High severity taint flow with unsanitized path (x2)
- Dangerous function used (create_function)
- Raw SQL queries without prepared statements
- Very low output escaping (2%)
WCBox Lite – Product Slider Plugin For Woocommerce Security Vulnerabilities
WCBox Lite – Product Slider Plugin For Woocommerce Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
WCBox Lite – Product Slider Plugin For Woocommerce Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 45
Maintenance & Trust
WCBox Lite – Product Slider Plugin For Woocommerce Maintenance & Trust
Maintenance Signals
Community Trust
WCBox Lite – Product Slider Plugin For Woocommerce Alternatives
Product Category Slider & Grid for WooCommerce – WooCategory
woo-category-slider-grid
Display product categories in responsive sliders or grids to showcase them effectively on your WooCommerce store and improve shoppers' navigation.
Product Category Showcase for WooCommerce
wc-category-showcase
Showcase WooCommerce product categories in sliders, grids, or blocks with styling control, responsive layouts, and shortcode support
WPB Category Slider for WooCommerce – Product Categories Carousel & Grid
wpb-woocommerce-category-slider
Display WooCommerce product categories in responsive sliders and grids to boost navigation, engagement, and product discovery.
Dynamic Product Category Grid, Slider for WooCommerce
dynamic-product-categories-design
Show woocommerce categories in slider and grid layout with shortcode builder and Elementor widget.
Product Category Slider for Elementor
woo-category-slider-for-elementor
Display Product Category Slider For Elementor aesthetically in a slider to your store and boost conversion rate! Highly customizable.
WCBox Lite – Product Slider Plugin For Woocommerce Developer Profile
7 plugins · 29K total installs
How We Detect WCBox Lite – Product Slider Plugin For Woocommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wcbox-lite/assets/css/animate.min.css/wp-content/plugins/wcbox-lite/assets/css/font-awesome.min.css/wp-content/plugins/wcbox-lite/assets/css/turbotabs.css/wp-content/plugins/wcbox-lite/assets/css/owl.carousel.css/wp-content/plugins/wcbox-lite/assets/css/wc-box-public.css/wp-content/plugins/wcbox-lite/assets/js/prettyPhoto/jquery.prettyPhoto.js/wp-content/plugins/wcbox-lite/assets/js/prettyPhoto/jquery.prettyPhoto.init.js/wp-content/plugins/wcbox-lite/assets/js/owl.carousel.min.js+3 more/wp-content/plugins/wcbox-lite/assets/js/prettyPhoto/jquery.prettyPhoto.js/wp-content/plugins/wcbox-lite/assets/js/prettyPhoto/jquery.prettyPhoto.init.js/wp-content/plugins/wcbox-lite/assets/js/owl.carousel.min.js/wp-content/plugins/wcbox-lite/assets/js/turbotabs.js/wp-content/plugins/wcbox-lite/assets/js/wc-box-public.js/wp-content/plugins/wcbox-lite/assets/js/modernizr.custom.jswcbox-animatewcbox-font-awesomewcbox-turbotabswcbox-owl-carouselwcbox_prettyPhoto_csspublic-csswcbox_prettyPhotowcbox_prettyPhoto-initwcbox-owl-carouselturbotabspublic-jsmodernizr.customHTML / DOM Fingerprints
wcbox_sliderwcbox_dynamic_code[wcbox_slider id=