
Author Product Review Security & Risk Analysis
wordpress.org/plugins/author-product-reviewThis plugin allow author to add Schema.org markup options for product reviews.
Is Author Product Review Safe to Use in 2026?
Generally Safe
Score 100/100Author Product Review has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "author-product-review" plugin version 1.1 exhibits a generally strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the potential attack surface. Furthermore, the code demonstrates good practices by utilizing prepared statements for all SQL queries and implementing nonce and capability checks. This indicates a developer who is aware of common WordPress security vulnerabilities.
However, a significant concern arises from the output escaping. With only 13% of outputs properly escaped, there is a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. Attackers could potentially inject malicious scripts through user-provided data that is displayed on the frontend without adequate sanitization or escaping. While taint analysis shows no current unsanitized flows, this is likely due to the limited attack surface identified. The lack of any recorded vulnerabilities in the plugin's history is a positive sign, suggesting a history of secure development, but it does not negate the immediate risk posed by the poor output escaping.
In conclusion, the plugin has a solid foundation with a small attack surface and secure data handling for SQL. The primary and most immediate risk is the widespread lack of output escaping, which could lead to XSS attacks. While the vulnerability history is clean, this single identified weakness warrants attention and remediation to maintain a secure application.
Key Concerns
- Low percentage of properly escaped output
Author Product Review Security Vulnerabilities
Author Product Review Code Analysis
Output Escaping
Author Product Review Attack Surface
WordPress Hooks 6
Maintenance & Trust
Author Product Review Maintenance & Trust
Maintenance Signals
Community Trust
Author Product Review Alternatives
Review Schema
review-schema-markup
This plugin will add Schema.org markup options for reviews.
ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema
reviewx
Drive woocommerce business growth with social proof: gather product reviews with multicriteria ratings, auto-reminder emails, discounts, and more.
JSON-LD Breadcrumbs
json-ld-breadcrumbs
Adds JSON-LD based breadcrumb schema to your site visible only to the Search Engines such as Google.
Feefo Ratings & Reviews for WooCommerce
feefo-ratings-reviews-for-woocommerce
Gather trusted ratings and reviews from your customers with the award winning closed-feedback platform Feefo and hear the real voice of your customer.
Builder for WooCommerce product reviews shortcodes – ReviewShort
woo-product-reviews-shortcode
Show WooCommerce customer feedback anywhere with WooCommerce reviews shortcodes, beautifully and ...
Author Product Review Developer Profile
1 plugin · 60 total installs
How We Detect Author Product Review
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/author-product-review/css/style.css/wp-content/plugins/author-product-review/js/script.js/wp-content/plugins/author-product-review/js/script.jsauthor-product-review/css/style.css?ver=author-product-review/js/script.js?ver=HTML / DOM Fingerprints
inline-ratingreview-ratingbest-ratingreview-star-emptyreview-starreview-datastar-rating<!-- Author Product Review -->itemscopeitemtypeitemprop{rating}