WooSwipe WooCommerce Gallery Security & Risk Analysis

wordpress.org/plugins/wooswipe

A WooCommerce gallery plugin built using PhotoSwipe from Dmitry Semenov and Slick carousel.

4K active installs v3.0.8 PHP + WP 6.0+ Updated Feb 11, 2025
product-galleryproductswoocommercewoocommerce-gallerywooswipe
92
A · Safe
CVEs total1
Unpatched0
Last CVENov 17, 2022
Safety Verdict

Is WooSwipe WooCommerce Gallery Safe to Use in 2026?

Generally Safe

Score 92/100

WooSwipe WooCommerce Gallery has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Nov 17, 2022Updated 1yr ago
Risk Assessment

The static analysis of Wooswipe v3.0.8 indicates a generally good security posture with no identified dangerous functions, raw SQL queries, or file operations. The plugin also demonstrates good practices in output escaping, with 88% of outputs properly escaped, and includes a nonce check and capability check. The attack surface appears minimal, with no AJAX handlers, REST API routes, shortcodes, or cron events exposed without authentication. Taint analysis also reveals no unsanitized paths or critical/high severity flows.

However, the vulnerability history is a concern. While there are no currently unpatched CVEs, the plugin has a history of one known CVE, specifically a 'Missing Authorization' vulnerability. The fact that this was a medium severity vulnerability and was patched indicates that such issues have occurred in the past. The presence of past vulnerabilities, even if patched, suggests that the development process may not consistently catch all security flaws, and a focus on robust authorization checks is important for this plugin.

In conclusion, Wooswipe v3.0.8 benefits from strong internal code hygiene in terms of avoiding dangerous functions and SQL injection vectors. The minimal attack surface is also a positive. The primary weakness lies in its past vulnerability history, particularly the 'Missing Authorization' issue, which warrants continued vigilance and thorough security testing for future updates. While current static analysis shows no immediate critical risks, the historical context suggests a moderate ongoing risk.

Key Concerns

  • 1 known CVE (medium severity) in history
  • Output escaping could be improved (12% unescaped)
Vulnerabilities
1

WooSwipe WooCommerce Gallery Security Vulnerabilities

CVEs by Year

1 CVE in 2022
2022
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2022-45066medium · 5.4Missing Authorization

WooSwipe WooCommerce Gallery <= 3.0.2 - Missing Authorization

Nov 17, 2022 Patched in 3.0.3 (431d)
Code Analysis
Analyzed Mar 16, 2026

WooSwipe WooCommerce Gallery Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
30 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

88% escaped34 total outputs
Attack Surface

WooSwipe WooCommerce Gallery Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 16
actionplugins_loadedincludes\class-wooswipe.php:141
actionplugins_loadedincludes\class-wooswipe.php:156
actionadmin_enqueue_scriptsincludes\class-wooswipe.php:157
actionadmin_enqueue_scriptsincludes\class-wooswipe.php:158
actionadmin_menuincludes\class-wooswipe.php:159
actioninitincludes\class-wooswipe.php:160
actionadmin_initincludes\class-wooswipe.php:161
actionsetup_themeincludes\class-wooswipe.php:177
actionwp_enqueue_scriptsincludes\class-wooswipe.php:178
actionwp_enqueue_scriptsincludes\class-wooswipe.php:179
actionafter_setup_themeincludes\class-wooswipe.php:180
actionwp_print_scriptsincludes\class-wooswipe.php:181
actionwp_print_stylesincludes\class-wooswipe.php:182
actionwoocommerce_before_single_product_summaryincludes\class-wooswipe.php:183
actionwoocommerce_before_single_product_summaryincludes\class-wooswipe.php:184
actionwpincludes\class-wooswipe.php:185
Maintenance & Trust

WooSwipe WooCommerce Gallery Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedFeb 11, 2025
PHP min version
Downloads154K

Community Trust

Rating90/100
Number of ratings39
Active installs4K
Developer Profile

WooSwipe WooCommerce Gallery Developer Profile

THRIVE - Web Design Gold Coast

7 plugins · 12K total installs

71
trust score
Avg Security Score
88/100
Avg Patch Time
735 days
View full developer profile
Detection Fingerprints

How We Detect WooSwipe WooCommerce Gallery

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wooswipe/admin/css/wooswipe-admin.css/wp-content/plugins/wooswipe/admin/js/wooswipe-admin.js/wp-content/plugins/wooswipe/public/css/wooswipe-public.css/wp-content/plugins/wooswipe/public/js/wooswipe-public.js/wp-content/plugins/wooswipe/public/js/photoswipe.min.js/wp-content/plugins/wooswipe/public/js/slick.min.js/wp-content/plugins/wooswipe/public/css/photoswipe.css/wp-content/plugins/wooswipe/public/css/slick.css
Script Paths
/wp-content/plugins/wooswipe/admin/js/wooswipe-admin.js/wp-content/plugins/wooswipe/public/js/wooswipe-public.js/wp-content/plugins/wooswipe/public/js/photoswipe.min.js/wp-content/plugins/wooswipe/public/js/slick.min.js
Version Parameters
wooswipe-admin?ver=wooswipe-public?ver=photoswipe.min.js?ver=slick.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
wooswipe-gallerywooswipe-thumbnails
Data Attributes
data-wooswipe-options
JS Globals
WooswipePublic
Shortcode Output
[wooswipe]
FAQ

Frequently Asked Questions about WooSwipe WooCommerce Gallery