
Additional Variation Images Gallery for WooCommerce Security & Risk Analysis
wordpress.org/plugins/woo-variation-galleryAllows inserting multiple images per variation to let your store customers to see different sets of images when WooCommerce product variations are swi …
Is Additional Variation Images Gallery for WooCommerce Safe to Use in 2026?
Generally Safe
Score 92/100Additional Variation Images Gallery for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of woo-variation-gallery v1.3.28 indicates a generally good security posture, with a notable lack of exploitable entry points like unprotected AJAX handlers, REST API routes, or shortcodes. The plugin also demonstrates strong practices in output escaping, with 93% of outputs being properly handled. Nonce and capability checks are present, and there are no identified dangerous functions or file operations that raise immediate red flags.
However, a significant concern lies in the SQL query handling. The presence of a single SQL query that is not using prepared statements presents a potential risk for SQL injection, even if the attack surface is otherwise limited. The external HTTP request also warrants attention, as it could be a vector for further vulnerabilities if not handled with extreme care regarding input validation and output sanitization. The vulnerability history, while not indicating any currently unpatched issues, shows a past medium severity Cross-Site Scripting vulnerability, which highlights the need for continued vigilance in secure coding practices.
In conclusion, while the plugin has made significant strides in securing its entry points and output handling, the unescaped SQL query and the external HTTP request represent clear areas for improvement. The past XSS vulnerability also suggests that ongoing security audits are beneficial to prevent future similar issues. Overall, the plugin is in a relatively good state but requires attention to the identified SQL and HTTP request risks.
Key Concerns
- SQL queries not using prepared statements
- External HTTP request without obvious sanitization
Additional Variation Images Gallery for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Additional Variation Images Gallery for WooCommerce <= 1.1.28 - Authenticated Stored Cross-Site Scripting
Additional Variation Images Gallery for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Additional Variation Images Gallery for WooCommerce Attack Surface
WordPress Hooks 66
Maintenance & Trust
Additional Variation Images Gallery for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Additional Variation Images Gallery for WooCommerce Alternatives
Variation Images – Additional Variation Images for WooCommerce
wc-variation-images
Add multiple images per WooCommerce variation to enhance product visuals, build trust, and boost conversions with advanced galleries.
GWL Variation Gallery
gwl-variation-gallery
The GWL Variation Gallery plugin allows you to add additional gallery images per variation on variable products within WooCommerce.
Variation Images Gallery for WooCommerce
woo-product-variation-gallery
Variation Images Gallery for WooCommerce plugin allows to add UNLIMITED additional images for each variation of product.
Product Gallery Slider, Additional Variation Images, Product Video, Product Image Zoom and Lightbox for WooCommerce – WooGallery
gallery-slider-for-woocommerce
🔥 All-in-One WooCommerce Product Image and Video Gallery Solution to Enhance Your Customers' Shopping Experience and Boost Sales Instantly! 🚀
Duplicate Variations for WooCommerce
variation-duplicator-for-woocommerce
Duplicate WooCommerce product variations with its all available properties including Variation Price, Variation Image, and SKU in just a single click.
Additional Variation Images Gallery for WooCommerce Developer Profile
6 plugins · 324K total installs
How We Detect Additional Variation Images Gallery for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woo-variation-gallery/assets/css/woo-variation-gallery-frontend.css/wp-content/plugins/woo-variation-gallery/assets/js/woo-variation-gallery-frontend.js/wp-content/plugins/woo-variation-gallery/assets/css/woo-variation-gallery-admin.css/wp-content/plugins/woo-variation-gallery/assets/js/woo-variation-gallery-admin.js/wp-content/plugins/woo-variation-gallery/assets/js/woo-variation-gallery-frontend.js/wp-content/plugins/woo-variation-gallery/assets/js/woo-variation-gallery-admin.jswoo-variation-gallery/assets/css/woo-variation-gallery-frontend.css?ver=woo-variation-gallery/assets/js/woo-variation-gallery-frontend.js?ver=woo-variation-gallery/assets/css/woo-variation-gallery-admin.css?ver=woo-variation-gallery/assets/js/woo-variation-gallery-admin.js?ver=HTML / DOM Fingerprints
woo-variation-gallery-wrapperwoo-variation-gallery-postboxwoo-variation-gallery-insidewoo-variation-gallery-image-containerwoo-variation-gallery-imagesadd-woo-variation-gallery-image-wrapperadd-woo-variation-gallery-imagewoo-variation-gallery-pro-buttondata-product_variation_iddata-product_variation_loopwoo_variation_gallery/wp-json/woo-variation-gallery/v1/settings