Woo Product Slider by Pangolin – Lite Security & Risk Analysis

wordpress.org/plugins/woo-product-slider-by-pangolin-lite

An elegant WooCommerce product slider (widget & shortcode).

10 active installs v1.01 PHP + WP 3.8+ Updated Unknown
woocommercewoocommerce-product-sliderwoocommerce-product-slider-pluginwoocommerce-productswoocommerce-slider
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Woo Product Slider by Pangolin – Lite Safe to Use in 2026?

Generally Safe

Score 100/100

Woo Product Slider by Pangolin – Lite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "woo-product-slider-by-pangolin-lite" plugin version 1.01 exhibits a generally positive security posture based on the provided static analysis. The absence of known CVEs and recorded vulnerabilities in its history is a strong indicator of responsible development and maintenance. Furthermore, the plugin utilizes prepared statements for all its SQL queries and performs no file operations or external HTTP requests, significantly reducing common attack vectors. The lack of a large attack surface without authentication is also a positive sign, with all identified entry points (shortcodes) presumably being handled securely.

However, a notable concern arises from the output escaping. With only 33% of the 122 outputs properly escaped, there is a significant risk of Cross-Site Scripting (XSS) vulnerabilities. This means that unsanitized user input, if present and processed by these unescaped outputs, could be injected and executed in the user's browser. The absence of nonce checks and capability checks on the identified entry points, while not explicitly a risk given the current analysis of zero unprotected entry points, indicates a potential for future issues if new AJAX or REST API endpoints are introduced without proper authorization controls. The zero taint flows and zero critical/high severity signals are reassuring, but the unescaped output remains the primary concern.

Key Concerns

  • Low percentage of properly escaped output
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Woo Product Slider by Pangolin – Lite Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Woo Product Slider by Pangolin – Lite Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
82
40 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

33% escaped122 total outputs
Attack Surface

Woo Product Slider by Pangolin – Lite Attack Surface

Entry Points3
Unprotected0

Shortcodes 3

[woo-product-featured] woo-product-slider.php:76
[woo-product] woo-product-slider.php:77
[woo-product-category] woo-product-slider.php:78
WordPress Hooks 9
actionadmin_enqueue_scriptsinc\widget-woocommerce-category.php:31
actionadmin_footer-widgets.phpinc\widget-woocommerce-category.php:32
actionadmin_enqueue_scriptsinc\widget-woocommerce-slider-featured.php:31
actionadmin_footer-widgets.phpinc\widget-woocommerce-slider-featured.php:32
actionadmin_enqueue_scriptsinc\widget-woocommerce-slider-recent.php:38
actionadmin_footer-widgets.phpinc\widget-woocommerce-slider-recent.php:39
actionwp_enqueue_scriptswoo-product-slider.php:39
actionwidgets_initwoo-product-slider.php:67
actionadmin_enqueue_scriptswoo-product-slider.php:80
Maintenance & Trust

Woo Product Slider by Pangolin – Lite Maintenance & Trust

Maintenance Signals

WordPress version tested4.4.34
Last updatedUnknown
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Woo Product Slider by Pangolin – Lite Developer Profile

Atlantis Themes

2 plugins · 910 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Woo Product Slider by Pangolin – Lite

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woo-product-slider-by-pangolin-lite/lib/css/libraries.css/wp-content/plugins/woo-product-slider-by-pangolin-lite/lib/css/bellini-woocommerce.css/wp-content/plugins/woo-product-slider-by-pangolin-lite/lib/js/library.js/wp-content/plugins/woo-product-slider-by-pangolin-lite/lib/js/pangolin.js
Script Paths
/wp-content/plugins/woo-product-slider-by-pangolin-lite/lib/js/library.js/wp-content/plugins/woo-product-slider-by-pangolin-lite/lib/js/pangolin.js
Version Parameters
woo-product-slider-by-pangolin-lite/lib/css/libraries.css?ver=woo-product-slider-by-pangolin-lite/lib/css/bellini-woocommerce.css?ver=woo-product-slider-by-pangolin-lite/lib/js/library.js?ver=woo-product-slider-by-pangolin-lite/lib/js/pangolin.js?ver=

HTML / DOM Fingerprints

CSS Classes
wpspl-librarywpspl-core-stylewpspl-library-jswpspl-core-jswpspl_woo_product_categorywidget__canvas--woofront-product-category__cardfront-product-category__card__inner+6 more
HTML Comments
<!-- WooCommerce Not Found --><!-- WooCommerce Products Category ########## -->
Data Attributes
itemprop="category"itemprop="image"
JS Globals
wpspl_enqueue_scriptswpspl_print_scripts
Shortcode Output
<div class="front-product-category__card<div class="front-product-category__card__inner" style="background-color:<h3 class="element-title element-title--sub" style="color:
FAQ

Frequently Asked Questions about Woo Product Slider by Pangolin – Lite