
Shoppable Images by WP-Plugz – Increase Engagement and Conversions Security & Risk Analysis
wordpress.org/plugins/wpplugz-shoppable-imageIntroducing the Shoppable Images plugin for WordPress sites built with WooCommerce! Turn stunning product visuals into interactive experiences that dr …
Is Shoppable Images by WP-Plugz – Increase Engagement and Conversions Safe to Use in 2026?
Generally Safe
Score 100/100Shoppable Images by WP-Plugz – Increase Engagement and Conversions has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wpplugz-shoppable-image plugin version 1.1.0 demonstrates a generally strong security posture, with an excellent track record and adherence to many WordPress security best practices. The static analysis reveals no critical vulnerabilities such as dangerous functions, unescaped output, or insecure file operations. Furthermore, the absence of known CVEs and a clean vulnerability history indicate a well-maintained and secure codebase over time.
However, there are a few areas that warrant attention. The plugin relies on a single shortcode as its only identified entry point, and this shortcode lacks any explicit capability checks or nonce validations. While the static analysis did not detect any taint flows or insecure SQL queries, the absence of these protective measures on the shortcode could theoretically open it up to certain types of attacks if user-supplied data is not handled with extreme care within the shortcode's execution. The small number of entry points and the absence of AJAX/REST API routes are positive aspects, but the security of the existing shortcode needs to be robust.
In conclusion, wpplugz-shoppable-image v1.1.0 is in good shape security-wise, with its most significant weakness being the lack of authentication and authorization checks on its sole shortcode. This is a minor concern given the lack of other security issues and its clean history, but it represents a potential avenue for exploitation that could be mitigated by implementing proper checks. The plugin's overall adherence to secure coding practices is commendable.
Key Concerns
- Shortcode missing capability checks
- Shortcode missing nonce checks
Shoppable Images by WP-Plugz – Increase Engagement and Conversions Security Vulnerabilities
Shoppable Images by WP-Plugz – Increase Engagement and Conversions Code Analysis
Output Escaping
Shoppable Images by WP-Plugz – Increase Engagement and Conversions Attack Surface
Shortcodes 1
WordPress Hooks 22
Maintenance & Trust
Shoppable Images by WP-Plugz – Increase Engagement and Conversions Maintenance & Trust
Maintenance Signals
Community Trust
Shoppable Images by WP-Plugz – Increase Engagement and Conversions Alternatives
Shoppable Images (Lookbook) for WooCommerce
mabel-shoppable-images-lite
Create interactive 'shoppable' images (lookbooks) with click-to-buy tags. Ideal to showcase your products in a different way and drive more traffic.
LookBook for WooCommerce – Shoppable with Product Tags
woo-lookbook
Easily create stunning lookbooks or sync Instagram photos. Captivate customers with beautiful displays and boost sales with in-lookbook Quick View
WooCommerce PayPal Payments
woocommerce-paypal-payments
PayPal's latest payment processing solution. Accept PayPal, Pay Later, credit/debit cards, alternative digital wallets and bank accounts.
Mollie Payments for WooCommerce
mollie-payments-for-woocommerce
Accept all major payment methods in WooCommerce today. Credit cards, iDEAL and more! Fast, safe and intuitive.
TI WooCommerce Wishlist
ti-woocommerce-wishlist
Boost your sales with a free WooCommerce Wishlist feature. Let your customers save and share their favorite products!
Shoppable Images by WP-Plugz – Increase Engagement and Conversions Developer Profile
2 plugins · 30 total installs
How We Detect Shoppable Images by WP-Plugz – Increase Engagement and Conversions
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpplugz-shoppable-image/build/index.js/wp-content/plugins/wpplugz-shoppable-image/build/index.asset.php/wp-content/plugins/wpplugz-shoppable-image/build/style-index.css/wp-content/plugins/wpplugz-shoppable-image/assets/css/shoppable-image-admin-style.css/wp-content/plugins/wpplugz-shoppable-image/build/index.jswpplugz-shoppable-image/build/index.asset.php?ver=wpplugz-shoppable-image/build/index.js?ver=wpplugz-shoppable-image/build/style-index.css?ver=wpplugz-shoppable-image/assets/css/shoppable-image-admin-style.css?ver=HTML / DOM Fingerprints
wpplugz-shoppable-image-blockwp-block-wpplugz-shoppable-image-shoppable-image-blockshoppable-image-admin-wrapperdata-post-iddata-block-namedata-image-idwindow.wp.element.createElementwindow.wp.blocks.registerBlockTypewindow.wp.components.PanelBodywindow.wp.components.SelectControlwindow.wp.components.TextControlwindow.wp.components.TextareaControl+7 more/wp-json/wpplugz-shoppable-image/v1/settings[wpplugz-shoppable-image id="post_id="