
Author hReview Security & Risk Analysis
wordpress.org/plugins/author-hreviewAdd Google Rich Snippets for reviews based on schema.org for a better WordPress SEO, customize search results with rating stars for more traffic and c …
Is Author hReview Safe to Use in 2026?
Generally Safe
Score 85/100Author hReview has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "author-hreview" plugin v1.0 presents a generally positive security posture based on the provided static analysis. The absence of any registered AJAX handlers, REST API routes, shortcodes, or cron events significantly limits its attack surface, and importantly, all identified entry points are reported as protected. The code also demonstrates good practices by exclusively using prepared statements for SQL queries and avoiding file operations or external HTTP requests. The presence of nonce and capability checks, while minimal, indicates an awareness of security principles.
However, a significant concern arises from the low percentage of properly escaped output (12%). This suggests a high likelihood of Cross-Site Scripting (XSS) vulnerabilities. With 43 total output operations and only a small fraction being properly escaped, a substantial number of these could be susceptible to malicious input injection, allowing attackers to execute arbitrary JavaScript in a user's browser. Taint analysis reported no flows, which is positive, but this may be due to the limited scope or the lack of exploitable paths given the other findings. The plugin's vulnerability history is clean, with no recorded CVEs, which is a strong indicator of past security diligence or a lack of discovery.
In conclusion, while the plugin boasts a small attack surface and good practices in data handling and authentication checks, the extensive unescaped output is a critical weakness. This plugin should be considered moderately risky due to the high probability of XSS vulnerabilities, despite its otherwise clean history and limited attack surface. Addressing the output escaping issue should be a priority.
Key Concerns
- Low percentage of properly escaped output
Author hReview Security Vulnerabilities
Author hReview Code Analysis
Output Escaping
Author hReview Attack Surface
WordPress Hooks 21
Maintenance & Trust
Author hReview Maintenance & Trust
Maintenance Signals
Community Trust
Author hReview Alternatives
WPSSO Ratings and Reviews
wpsso-ratings-and-reviews
Adds Ratings and Reviews Features to the WordPress Comments System.
Site Reviews
site-reviews
Site Reviews is a complete review management solution that integrates with WooCommerce and SureCart and works similarly to reviews on Amazon, Tripadvi …
WP Customer Reviews
wp-customer-reviews
Allows your visitors to leave business / product reviews. Testimonials are in Microdata / Microformat and may display star ratings in search results.
Photo Reviews for WooCommerce
woo-photo-reviews
Let customers attach photos to reviews, enhanced with filterable grids and overall ratings. Auto-send review reminders and coupon emails
ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema
reviewx
Drive woocommerce business growth with social proof: gather product reviews with multicriteria ratings, auto-reminder emails, discounts, and more.
Author hReview Developer Profile
8 plugins · 41K total installs
How We Detect Author hReview
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.