Shoppable Images by WP-Plugz – Increase Engagement and Conversions Security & Risk Analysis

wordpress.org/plugins/wpplugz-shoppable-image

Introducing the Shoppable Images plugin for WordPress sites built with WooCommerce! Turn stunning product visuals into interactive experiences that dr …

10 active installs v1.1.0 PHP 7.4+ WP 6.4.1+ Updated Jan 27, 2026
ecommerceimage-hotspotslookbookshoppable-imagewoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Shoppable Images by WP-Plugz – Increase Engagement and Conversions Safe to Use in 2026?

Generally Safe

Score 100/100

Shoppable Images by WP-Plugz – Increase Engagement and Conversions has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The wpplugz-shoppable-image plugin version 1.1.0 demonstrates a generally strong security posture, with an excellent track record and adherence to many WordPress security best practices. The static analysis reveals no critical vulnerabilities such as dangerous functions, unescaped output, or insecure file operations. Furthermore, the absence of known CVEs and a clean vulnerability history indicate a well-maintained and secure codebase over time.

However, there are a few areas that warrant attention. The plugin relies on a single shortcode as its only identified entry point, and this shortcode lacks any explicit capability checks or nonce validations. While the static analysis did not detect any taint flows or insecure SQL queries, the absence of these protective measures on the shortcode could theoretically open it up to certain types of attacks if user-supplied data is not handled with extreme care within the shortcode's execution. The small number of entry points and the absence of AJAX/REST API routes are positive aspects, but the security of the existing shortcode needs to be robust.

In conclusion, wpplugz-shoppable-image v1.1.0 is in good shape security-wise, with its most significant weakness being the lack of authentication and authorization checks on its sole shortcode. This is a minor concern given the lack of other security issues and its clean history, but it represents a potential avenue for exploitation that could be mitigated by implementing proper checks. The plugin's overall adherence to secure coding practices is commendable.

Key Concerns

  • Shortcode missing capability checks
  • Shortcode missing nonce checks
Vulnerabilities
None known

Shoppable Images by WP-Plugz – Increase Engagement and Conversions Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Shoppable Images by WP-Plugz – Increase Engagement and Conversions Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
51 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

98% escaped52 total outputs
Attack Surface

Shoppable Images by WP-Plugz – Increase Engagement and Conversions Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[wpplugz-shoppable-image] class-shoppableimage.php:100
WordPress Hooks 22
actioninitclass-shoppableimage.php:69
actionenqueue_block_assetsclass-shoppableimage.php:72
actioninitclass-shoppableimage.php:75
actionrest_prepare_shoppable_imageclass-shoppableimage.php:76
actionsave_postclass-shoppableimage.php:77
filterrest_product_queryclass-shoppableimage.php:80
actioninitclass-shoppableimage.php:83
actionadmin_initclass-shoppableimage.php:84
actionrest_api_initclass-shoppableimage.php:85
actionadmin_menuclass-shoppableimage.php:86
actionadmin_enqueue_scriptsclass-shoppableimage.php:87
filterinitclass-shoppableimage.php:91
filterpost_thumbnail_htmlclass-shoppableimage.php:94
actionwp_print_scriptsclass-shoppableimage.php:97
filtermanage_shoppable_image_posts_columnsclass-shoppableimage.php:103
actionmanage_shoppable_image_posts_custom_columnclass-shoppableimage.php:104
filtermanage_edit-shoppable_image_sortable_columnsclass-shoppableimage.php:105
actionadmin_headclass-shoppableimage.php:106
actionadmin_initshoppable-image.php:65
actionplugins_loadedshoppable-image.php:110
filterwoocommerce_add_to_cart_form_actiontemplates\shoppable-image.php:160
filterwoocommerce_add_to_cart_form_actiontemplates\shoppable-image.php:173
Maintenance & Trust

Shoppable Images by WP-Plugz – Increase Engagement and Conversions Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJan 27, 2026
PHP min version7.4
Downloads2K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

Shoppable Images by WP-Plugz – Increase Engagement and Conversions Developer Profile

WPPlugz

2 plugins · 30 total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Shoppable Images by WP-Plugz – Increase Engagement and Conversions

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wpplugz-shoppable-image/build/index.js/wp-content/plugins/wpplugz-shoppable-image/build/index.asset.php/wp-content/plugins/wpplugz-shoppable-image/build/style-index.css/wp-content/plugins/wpplugz-shoppable-image/assets/css/shoppable-image-admin-style.css
Script Paths
/wp-content/plugins/wpplugz-shoppable-image/build/index.js
Version Parameters
wpplugz-shoppable-image/build/index.asset.php?ver=wpplugz-shoppable-image/build/index.js?ver=wpplugz-shoppable-image/build/style-index.css?ver=wpplugz-shoppable-image/assets/css/shoppable-image-admin-style.css?ver=

HTML / DOM Fingerprints

CSS Classes
wpplugz-shoppable-image-blockwp-block-wpplugz-shoppable-image-shoppable-image-blockshoppable-image-admin-wrapper
Data Attributes
data-post-iddata-block-namedata-image-id
JS Globals
window.wp.element.createElementwindow.wp.blocks.registerBlockTypewindow.wp.components.PanelBodywindow.wp.components.SelectControlwindow.wp.components.TextControlwindow.wp.components.TextareaControl+7 more
REST Endpoints
/wp-json/wpplugz-shoppable-image/v1/settings
Shortcode Output
[wpplugz-shoppable-image id="post_id="
FAQ

Frequently Asked Questions about Shoppable Images by WP-Plugz – Increase Engagement and Conversions