Product Image Zoom & Gallery for WooCommerce by WPBean Security & Risk Analysis

wordpress.org/plugins/woocommerce-image-zoom

Add responsive image zoom effects to WooCommerce product images for better visual engagement and a closer look at product details.

3K active installs v2.1 PHP 7.4+ WP 5.0+ Updated Mar 13, 2026
magnifierproduct-gallerywoocommercewoocommerce-zoomzoom
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Product Image Zoom & Gallery for WooCommerce by WPBean Safe to Use in 2026?

Generally Safe

Score 100/100

Product Image Zoom & Gallery for WooCommerce by WPBean has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 21d ago
Risk Assessment

The "woocommerce-image-zoom" plugin v2.1 demonstrates a generally strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, cron events, and file operations, along with a complete absence of known CVEs, are all positive indicators. The plugin also makes good use of prepared statements for its SQL queries. However, a key concern arises from the lack of nonce checks and capability checks. While the current attack surface is minimal (one shortcode), this absence of authentication and authorization checks on the shortcode handler leaves it potentially vulnerable to issues like cross-site request forgery (CSRF) if the shortcode's functionality can be manipulated to perform sensitive actions or disclose information. Additionally, the 12% of improperly escaped output, while not flagged as critical or high severity in taint analysis, still represents a potential vector for cross-site scripting (XSS) vulnerabilities if user-controlled data is involved in those outputs. The plugin's clean vulnerability history is a significant strength, suggesting good development practices, but the identified areas for improvement in authorization and output escaping should be addressed to further harden its security.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • Improperly escaped output detected
Vulnerabilities
None known

Product Image Zoom & Gallery for WooCommerce by WPBean Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Product Image Zoom & Gallery for WooCommerce by WPBean Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
15
110 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

88% escaped125 total outputs
Attack Surface

Product Image Zoom & Gallery for WooCommerce by WPBean Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[wpb_wiz_product_image] inc\wpb-wiz-filter.php:250
WordPress Hooks 15
actionadmin_enqueue_scriptsadmin\class.settings-api.php:32
actionadmin_initadmin\plugin-settings.php:18
actionadmin_menuadmin\plugin-settings.php:19
actionwoocommerce_before_single_product_summaryinc\wpb-wiz-filter.php:31
filterwoocommerce_single_product_image_htmlinc\wpb-wiz-filter.php:34
actiontemplate_redirectinc\wpb-wiz-filter.php:37
actionwpinc\wpb-wiz-filter.php:237
actionafter_setup_themeinc\wpb-wiz-filter.php:243
actionadmin_noticesmain.php:47
actionadmin_noticesmain.php:147
actionadmin_initmain.php:148
actionwp_enqueue_scriptsmain.php:152
actioninitmain.php:153
actionadmin_noticesmain.php:165
actionplugins_loadedmain.php:168
Maintenance & Trust

Product Image Zoom & Gallery for WooCommerce by WPBean Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 13, 2026
PHP min version7.4
Downloads299K

Community Trust

Rating86/100
Number of ratings26
Active installs3K
Developer Profile

Product Image Zoom & Gallery for WooCommerce by WPBean Developer Profile

WPBean

25 plugins · 40K total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
20 days
View full developer profile
Detection Fingerprints

How We Detect Product Image Zoom & Gallery for WooCommerce by WPBean

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woocommerce-image-zoom/assets/css/jquery.fancybox.min.css/wp-content/plugins/woocommerce-image-zoom/assets/css/main.css/wp-content/plugins/woocommerce-image-zoom/assets/js/jquery.fancybox.min.js/wp-content/plugins/woocommerce-image-zoom/assets/js/jquery.ez-plus.js/wp-content/plugins/woocommerce-image-zoom/assets/js/main.js/wp-content/plugins/woocommerce-image-zoom/assets/images/spinner.gif
Script Paths
/wp-content/plugins/woocommerce-image-zoom/assets/js/jquery.fancybox.min.js/wp-content/plugins/woocommerce-image-zoom/assets/js/jquery.ez-plus.js/wp-content/plugins/woocommerce-image-zoom/assets/js/main.js
Version Parameters
woocommerce-image-zoom/assets/css/jquery.fancybox.min.css?ver=woocommerce-image-zoom/assets/css/main.css?ver=woocommerce-image-zoom/assets/js/jquery.fancybox.min.js?ver=woocommerce-image-zoom/assets/js/jquery.ez-plus.js?ver=woocommerce-image-zoom/assets/js/main.js?ver=

HTML / DOM Fingerprints

CSS Classes
wpb-wiz-discount-notice
HTML Comments
<!-- Product Image Zoom & Gallery for WooCommerce by WPBean --><!-- Highly customizable product image zoom plugin for Woocommerce Store. -->
Data Attributes
data-zoom-image
JS Globals
wpb_wiz_free
FAQ

Frequently Asked Questions about Product Image Zoom & Gallery for WooCommerce by WPBean