
AppStore Reviews Viewer Security & Risk Analysis
wordpress.org/plugins/appstore-reviews-viewerAdds a shortcode that displays reviews and ratings of an app from the iOS AppStore’s country you chose.
Is AppStore Reviews Viewer Safe to Use in 2026?
Generally Safe
Score 85/100AppStore Reviews Viewer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The security posture of the "appstore-reviews-viewer" plugin version 1.2.3 appears to have some concerning weaknesses despite a lack of recorded vulnerabilities and the absence of critical code signals like dangerous functions or unsanitized taint flows. The most significant red flag is the complete lack of output escaping across all identified output points. This means that any data displayed by the plugin, especially if it originates from user input or external sources, is not being properly sanitized, leaving it vulnerable to Cross-Site Scripting (XSS) attacks. Furthermore, the absence of any nonce or capability checks on the identified entry points, specifically the shortcode, is a major concern. While the static analysis shows a small attack surface, the lack of authorization checks means that any user, regardless of their role or permissions, could potentially interact with or manipulate the functionality exposed by the shortcode. The plugin's history of zero CVEs is positive, suggesting a potentially well-maintained codebase or a low profile, but it does not mitigate the present risks identified in the code analysis. The plugin demonstrates good practices in its use of prepared statements for SQL queries and avoids dangerous functions, but the critical gaps in output escaping and authorization checks significantly undermine its overall security.
Key Concerns
- No output escaping properly implemented
- No nonce checks on entry points
- No capability checks on entry points
AppStore Reviews Viewer Security Vulnerabilities
AppStore Reviews Viewer Release Timeline
AppStore Reviews Viewer Code Analysis
Output Escaping
AppStore Reviews Viewer Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
AppStore Reviews Viewer Maintenance & Trust
Maintenance Signals
Community Trust
AppStore Reviews Viewer Alternatives
App Display Page
app-display-page
Adds a shortcode to display information about iOS apps from Apple's App Store.
App Store Assistant
app-store-assistant
Lets you display the detail of an item or an RSS feed from Apple's App Store, iTunes Stores or Amazon.com. Affiliate ready.
AppStore Lookup for WordPress
appstore-lookup
Adds shortcodes that display data from iOS and Mac AppStore applications.
Itunes AppStore App Ranking
itunes-appstore-app-ranking
This plugin lets you add your app's position on the appstore to your blog. Simple add the Apple ID, select genre and range and your on the go.
WP App Store API
wp-app-store-landing-page
The WP App Store API allows you to search the App Store for any app information and use them to display on your site via shortcodes.
AppStore Reviews Viewer Developer Profile
1 plugin · 40 total installs
How We Detect AppStore Reviews Viewer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/appstore-reviews-viewer/appstore-review.css/wp-content/plugins/appstore-reviews-viewer/appstore-review.js/wp-content/plugins/appstore-reviews-viewer/appstore-review.jsappstore-review.css?ver=appstore-review.js?ver=HTML / DOM Fingerprints
asrv_listasrv_reviewasrv_appasrv_app_iconasrv_infoasrv_titleasrv_ratingasrv_content+1 moreid="asrv_list"<div id="asrv_list"><li class="asrv_review"><div class="asrv_app"><img src="