Aggregate Rating Schema Generator for Blogs Security & Risk Analysis

wordpress.org/plugins/aggregate-rating-schema-generator-for-blogs

Boost your blog with user reviews and ratings. Use Schema markup for aggregate ratings to improve SEO and engagement.

70 active installs v1.9.9 PHP 5.6+ WP 5.0+ Updated Mar 28, 2025
aggregate-ratingschema-markupseo-schema-markupstar-ratingsuser-ratings
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Aggregate Rating Schema Generator for Blogs Safe to Use in 2026?

Generally Safe

Score 92/100

Aggregate Rating Schema Generator for Blogs has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The aggregate-rating-schema-generator-for-blogs plugin v1.9.9 demonstrates a generally strong security posture based on the provided static analysis. The absence of dangerous functions, file operations, and external HTTP requests, coupled with 100% prepared statement usage for SQL queries and a high percentage of properly escaped output, indicates good development practices. The total lack of known vulnerabilities and CVEs further reinforces this positive impression, suggesting a mature and well-maintained codebase.

However, there are specific areas that warrant attention. The presence of 4 AJAX handlers with no explicit authentication checks is a significant concern, as it could potentially expose functionalities to unauthorized users. While the taint analysis shows no unsanitized paths, the lack of capability checks on these AJAX handlers means that even if the entry points are protected by nonces, their underlying actions might not be restricted to privileged users. The limited number of nonce checks (3) also raises questions about the coverage of all AJAX endpoints.

In conclusion, while the plugin benefits from robust data handling and a clean vulnerability history, the unprotected AJAX endpoints represent a tangible risk. Addressing these entry points with proper authentication and capability checks would significantly enhance the plugin's overall security.

Key Concerns

  • AJAX handlers without authentication checks
  • AJAX handlers without capability checks
  • Limited number of nonce checks
Vulnerabilities
None known

Aggregate Rating Schema Generator for Blogs Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Aggregate Rating Schema Generator for Blogs Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
16 prepared
Unescaped Output
1
117 escaped
Nonce Checks
3
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared16 total queries

Output Escaping

99% escaped118 total outputs
Data Flows
All sanitized

Data Flow Analysis

3 flows
strpgn_save_star_rating (aggregate-rating-schema-generator-for-blogs.php:312)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Aggregate Rating Schema Generator for Blogs Attack Surface

Entry Points5
Unprotected0

AJAX Handlers 4

authwp_ajax_save_star_ratingaggregate-rating-schema-generator-for-blogs.php:368
noprivwp_ajax_save_star_ratingaggregate-rating-schema-generator-for-blogs.php:369
authwp_ajax_get_average_ratingaggregate-rating-schema-generator-for-blogs.php:406
noprivwp_ajax_get_average_ratingaggregate-rating-schema-generator-for-blogs.php:407

Shortcodes 1

[strpgn_rating] aggregate-rating-schema-generator-for-blogs.php:522
WordPress Hooks 6
actionwp_enqueue_scriptsaggregate-rating-schema-generator-for-blogs.php:177
filterthe_contentaggregate-rating-schema-generator-for-blogs.php:228
filterthe_contentaggregate-rating-schema-generator-for-blogs.php:309
filterplugin_row_metaaggregate-rating-schema-generator-for-blogs.php:419
actionadmin_initdashboard.php:131
actionadmin_menudashboard.php:190
Maintenance & Trust

Aggregate Rating Schema Generator for Blogs Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedMar 28, 2025
PHP min version5.6
Downloads2K

Community Trust

Rating94/100
Number of ratings3
Active installs70
Developer Profile

Aggregate Rating Schema Generator for Blogs Developer Profile

Najmus

1 plugin · 70 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Aggregate Rating Schema Generator for Blogs

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/aggregate-rating-schema-generator-for-blogs/css/style.css/wp-content/plugins/aggregate-rating-schema-generator-for-blogs/js/confetti.browser.min.js/wp-content/plugins/aggregate-rating-schema-generator-for-blogs/js/rating.js
Script Paths
js/confetti.browser.min.jsjs/rating.js
Version Parameters
aggregate-rating-schema-generator-for-blogs/css/style.css?ver=aggregate-rating-schema-generator-for-blogs/js/rating.js?ver=aggregate-rating-schema-generator-for-blogs/js/confetti.browser.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
strpgn-rating-containerstrpgn-starstrpgn-star-filledstrpgn-average-ratingstrpgn-starsstrpgn-total-ratings
Data Attributes
strpgn_hide_auto_display
JS Globals
strpgn_ajax_object
Shortcode Output
[strpgn_rating]
FAQ

Frequently Asked Questions about Aggregate Rating Schema Generator for Blogs