
Better WooCommerce Stars Shortcode Security & Risk Analysis
wordpress.org/plugins/better-woocommerce-stars-shortcodeCreates a shortcode that displays the rating, in stars, of any WooCommerce product.
Is Better WooCommerce Stars Shortcode Safe to Use in 2026?
Generally Safe
Score 85/100Better WooCommerce Stars Shortcode has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'better-woocommerce-stars-shortcode' v1.0 plugin exhibits a mixed security posture. While the static analysis shows no critical or high-severity code signals like dangerous functions, file operations, or external HTTP requests, and the vulnerability history is clean, there are significant concerns regarding data handling. The complete absence of prepared statements for SQL queries and the lack of output escaping for all identified outputs are major weaknesses. This means that any user-supplied data processed by the plugin's SQL queries or displayed on the frontend could be vulnerable to injection attacks (SQL injection and Cross-Site Scripting respectively).
The taint analysis showing zero flows is somewhat reassuring, suggesting that either the plugin's logic doesn't involve complex data flows that the analysis tool can detect, or the data processing is simple enough to avoid obvious unsanitized paths. However, this doesn't negate the risks posed by the raw SQL and unescaped output. The clean vulnerability history is a positive indicator, implying the developers have not historically introduced severe security flaws. Despite this, the current version's code practices, particularly around data sanitization and output encoding, present tangible risks that require immediate attention. The plugin needs to implement prepared statements for all database interactions and robust output escaping to mitigate these vulnerabilities.
Key Concerns
- SQL queries not using prepared statements
- Output escaping is not implemented
- No nonce checks for entry points
- No capability checks for entry points
Better WooCommerce Stars Shortcode Security Vulnerabilities
Better WooCommerce Stars Shortcode Code Analysis
SQL Query Safety
Output Escaping
Better WooCommerce Stars Shortcode Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
Better WooCommerce Stars Shortcode Maintenance & Trust
Maintenance Signals
Community Trust
Better WooCommerce Stars Shortcode Alternatives
Five-Star Ratings Shortcode
five-star-ratings-shortcode
Simple lightweight shortcode to add 5-star ratings anywhere.
Trusted Shops Easy Integration for WooCommerce
trusted-shops-easy-integration-for-woocommerce
Show that your customers love you with reviews in your online store and boost your business with the free Trusted Shops Easy Integration Plugin for Wo …
REVIEWS.io for WooCommerce
reviewscouk-for-woocommerce
REVIEWS.io, helps eCommerce merchants to collect & display verified product and company reviews. A Google Licensed partner.
Stars Rating
stars-rating
A plugin to turn comments into reviews by adding rating feature.
WPSSO Ratings and Reviews
wpsso-ratings-and-reviews
Adds Ratings and Reviews Features to the WordPress Comments System.
Better WooCommerce Stars Shortcode Developer Profile
1 plugin · 60 total installs
How We Detect Better WooCommerce Stars Shortcode
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/better-woocommerce-stars-shortcode/better-woocommerce-stars-shortcode.phpHTML / DOM Fingerprints
display-rating-valuedisplay-number-of-ratingsstar-ratingstarwrapperstar-rating-alt-textitemprop="aggregateRating"itemscopeitemtype="http://schema.org/AggregateRating"itemprop="ratingValue"<span style="display:inline-block;float:none;" class="starwrapper" itemprop="aggregateRating" itemscope itemtype="http://schema.org/AggregateRating">