
Breview – Order reviews for WooCommerce Security & Risk Analysis
wordpress.org/plugins/breviewCollect reviews from order page after completion and display them on product pages on your WooCommerce store.
Is Breview – Order reviews for WooCommerce Safe to Use in 2026?
Generally Safe
Score 92/100Breview – Order reviews for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "breview" plugin v1.2.3 exhibits a generally strong security posture based on the provided static analysis. The plugin has zero known vulnerabilities (CVEs) and no recorded history of past issues, which is a significant positive indicator. Furthermore, the static analysis reveals no dangerous functions, no raw SQL queries, no file operations, and no external HTTP requests, all of which are excellent security practices. The plugin also reports a clean attack surface with no AJAX handlers, REST API routes, shortcodes, or cron events that could be exploited, and importantly, none of these entry points are reported as unprotected.
However, there are some areas of concern that warrant attention. The taint analysis indicates two flows with unsanitized paths, which, while not reaching a critical or high severity in this analysis, represent potential vectors for unexpected behavior or vulnerabilities if inputs were to be manipulated. Additionally, the output escaping is only properly implemented for approximately 79% of outputs, leaving a significant portion potentially vulnerable to cross-site scripting (XSS) attacks if user-supplied data is not adequately sanitized before display. The complete absence of nonce and capability checks, while aligned with the zero attack surface, could become a weakness if the plugin's functionality were to expand or be integrated with other components in the future.
In conclusion, "breview" v1.2.3 is a plugin with a very low attack surface and a clean vulnerability history. Its adherence to secure coding practices for SQL and file operations is commendable. The primary risks stem from the identified unsanitized paths in the taint analysis and the sub-optimal output escaping, which could lead to XSS vulnerabilities. The lack of any authentication or authorization checks is not a current issue due to the zero attack surface, but it's a point to monitor for future development.
Key Concerns
- Taint flow with unsanitized path
- Taint flow with unsanitized path
- Output escaping not properly handled for 21%
- No nonce checks implemented
- No capability checks implemented
Breview – Order reviews for WooCommerce Security Vulnerabilities
Breview – Order reviews for WooCommerce Code Analysis
Output Escaping
Data Flow Analysis
Breview – Order reviews for WooCommerce Attack Surface
WordPress Hooks 22
Maintenance & Trust
Breview – Order reviews for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Breview – Order reviews for WooCommerce Alternatives
Photo Reviews for WooCommerce
woo-photo-reviews
Let customers attach photos to reviews, enhanced with filterable grids and overall ratings. Auto-send review reminders and coupon emails
ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema
reviewx
Drive woocommerce business growth with social proof: gather product reviews with multicriteria ratings, auto-reminder emails, discounts, and more.
Customer Reviews Collector for WooCommerce
customer-reviews-collector-for-woocommerce
Collect reviews on Google, Facebook, Yelp, Trustindex and other platforms automatically, with the help of our system.
Builder for WooCommerce product reviews shortcodes – ReviewShort
woo-product-reviews-shortcode
Show WooCommerce customer feedback anywhere with WooCommerce reviews shortcodes, beautifully and ...
PiWeb Customer review / Product review for WooCommerce
product-review-for-woocommerce
Send a reminder email to customers for WooCommerce product reviews. You can send manual reminders or configure the plugin to send automatic review rem …
Breview – Order reviews for WooCommerce Developer Profile
2 plugins · 60 total installs
How We Detect Breview – Order reviews for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/breview/assets/js/star-rating.min.js/wp-content/plugins/breview/assets/js/jquery.star-rating-svg.min.js/wp-content/plugins/breview/assets/js/iziModal.min.js/wp-content/plugins/breview/assets/js/pagination.min.js/wp-content/plugins/breview/assets/js/jquery.validate.min.js/wp-content/plugins/breview/assets/js/main.js/wp-content/plugins/breview/assets/css/star-rating.min.css/wp-content/plugins/breview/assets/css/star-rating-svg.css+4 more/wp-content/plugins/breview/assets/js/main.jsmsbr-star-rating?ver=msbr-star-rating-svg?ver=msbr-iziModal?ver=msbr-pagination?ver=msbr-jquery-validate?ver=msbr-script?ver=msbr-star-rating?ver=msbr-star-rating-svg?ver=msbr-iziModal?ver=msbr-style?ver=msbr-responsive?ver=msbr-inline?ver=HTML / DOM Fingerprints
msbr_review