Woo Product Carousel and Zoom Security & Risk Analysis

wordpress.org/plugins/woo-product-carousel-and-zoom

Convert WooCommerce product gallery thumbnails in a responsive carousel with mouseover zoom effect.

100 active installs v1.0.4 PHP + WP 3.5+ Updated Mar 31, 2017
product-carouselproduct-carousel-woocommerceproduct-zoomproduct-zoom-woocommercezoom
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Woo Product Carousel and Zoom Safe to Use in 2026?

Generally Safe

Score 85/100

Woo Product Carousel and Zoom has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The static analysis of the 'woo-product-carousel-and-zoom' plugin v1.0.4 reveals a generally good security posture with no identified critical vulnerabilities. The plugin demonstrates positive practices by avoiding dangerous functions, utilizing prepared statements for all SQL queries, and not making external HTTP requests. However, a significant concern arises from the output escaping, where only 51% of outputs are properly escaped. This indicates a potential for cross-site scripting (XSS) vulnerabilities if user-supplied data is rendered without adequate sanitization.

The plugin's attack surface is remarkably small, with no identified AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, the taint analysis found no unsanitized paths or critical/high severity flows, which is a strong indicator of robust code hygiene. The absence of any recorded vulnerabilities in its history further reinforces the impression of a secure plugin. However, the moderate output escaping rate remains a notable weakness that should be addressed to ensure complete security.

In conclusion, the plugin exhibits strong security development practices, particularly in its limited attack surface and absence of historical vulnerabilities. The use of prepared statements and lack of dangerous functions are commendable. The primary area for improvement lies in enhancing output escaping to mitigate potential XSS risks. Despite this, the plugin appears to be a low-risk option, provided the output escaping issue is resolved.

Key Concerns

  • Moderate output escaping rate
Vulnerabilities
None known

Woo Product Carousel and Zoom Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Woo Product Carousel and Zoom Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
19
20 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

51% escaped39 total outputs
Attack Surface

Woo Product Carousel and Zoom Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionadmin_enqueue_scriptsadmin\class-woo-product-carousel-and-zoom-admin.php:62
actionadmin_menuadmin\class-woo-product-carousel-and-zoom-admin.php:65
actionadmin_initadmin\includes\settings.php:71
actioninitpublic\class-woo-product-carousel-and-zoom.php:52
actionadmin_noticespublic\class-woo-product-carousel-and-zoom.php:55
actionwp_enqueue_scriptspublic\class-woo-product-carousel-and-zoom.php:58
filterwoocommerce_locate_templatepublic\class-woo-product-carousel-and-zoom.php:62
actionplugins_loadedwoo-product-carousel-and-zoom.php:53
actionplugins_loadedwoo-product-carousel-and-zoom.php:66
Maintenance & Trust

Woo Product Carousel and Zoom Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.32
Last updatedMar 31, 2017
PHP min version
Downloads9K

Community Trust

Rating100/100
Number of ratings2
Active installs100
Developer Profile

Woo Product Carousel and Zoom Developer Profile

asiermusa

1 plugin · 100 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Woo Product Carousel and Zoom

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woo-product-carousel-and-zoom/assets/admin/css/admin.styles.css/wp-content/plugins/woo-product-carousel-and-zoom/assets/admin/js/admin.custom.js/wp-content/plugins/woo-product-carousel-and-zoom/assets/admin/js/admin.libs.min.js
Script Paths
/wp-content/plugins/woo-product-carousel-and-zoom/assets/admin/js/admin.libs.min.js/wp-content/plugins/woo-product-carousel-and-zoom/assets/admin/js/admin.custom.js
Version Parameters
woo-product-carousel-and-zoom/assets/admin/css/admin.styles.css?ver=woo-product-carousel-and-zoom/assets/admin/js/admin.libs.min.js?ver=woo-product-carousel-and-zoom/assets/admin/js/admin.custom.js?ver=

HTML / DOM Fingerprints

CSS Classes
woocz_tabs_containerwoocz_tabswoocz_tabs_contentwoocz_tabwoocz_tab_contentwoocz_product_listwoocz_product_itemwoocz_zoom_image+2 more
HTML Comments
<!-- Plugin Scripts and Styles --><!-- Plugin Settings Page --><!-- Display Plugin Settings Page --><!-- Plugin Action Links -->+43 more
Data Attributes
data-woocz-nav-positiondata-woocz-nav-colordata-woocz-nav-arrow-colordata-woocz-nav-arrow-hover-colordata-woocz-nav-dots-colordata-woocz-nav-dots-hover-color+15 more
JS Globals
WOOCZ_PLUGIN_URLWOOCZ_VERSIONWOOCZ_DIR
FAQ

Frequently Asked Questions about Woo Product Carousel and Zoom