Breview – Order reviews for WooCommerce Security & Risk Analysis

wordpress.org/plugins/breview

Collect reviews from order page after completion and display them on product pages on your WooCommerce store.

10 active installs v1.2.3 PHP 7.4+ WP 5.5+ Updated Apr 3, 2024
customer-reviewsmarketplace-reviewsmulti-criteria-ratingsorder-reviewswoocommerce-review
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Breview – Order reviews for WooCommerce Safe to Use in 2026?

Generally Safe

Score 92/100

Breview – Order reviews for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "breview" plugin v1.2.3 exhibits a generally strong security posture based on the provided static analysis. The plugin has zero known vulnerabilities (CVEs) and no recorded history of past issues, which is a significant positive indicator. Furthermore, the static analysis reveals no dangerous functions, no raw SQL queries, no file operations, and no external HTTP requests, all of which are excellent security practices. The plugin also reports a clean attack surface with no AJAX handlers, REST API routes, shortcodes, or cron events that could be exploited, and importantly, none of these entry points are reported as unprotected.

However, there are some areas of concern that warrant attention. The taint analysis indicates two flows with unsanitized paths, which, while not reaching a critical or high severity in this analysis, represent potential vectors for unexpected behavior or vulnerabilities if inputs were to be manipulated. Additionally, the output escaping is only properly implemented for approximately 79% of outputs, leaving a significant portion potentially vulnerable to cross-site scripting (XSS) attacks if user-supplied data is not adequately sanitized before display. The complete absence of nonce and capability checks, while aligned with the zero attack surface, could become a weakness if the plugin's functionality were to expand or be integrated with other components in the future.

In conclusion, "breview" v1.2.3 is a plugin with a very low attack surface and a clean vulnerability history. Its adherence to secure coding practices for SQL and file operations is commendable. The primary risks stem from the identified unsanitized paths in the taint analysis and the sub-optimal output escaping, which could lead to XSS vulnerabilities. The lack of any authentication or authorization checks is not a current issue due to the zero attack surface, but it's a point to monitor for future development.

Key Concerns

  • Taint flow with unsanitized path
  • Taint flow with unsanitized path
  • Output escaping not properly handled for 21%
  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

Breview – Order reviews for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Breview – Order reviews for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
54
201 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

79% escaped255 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
msbr_breview_general_settings_page (inc\admin\options-panel\options-panel.php:8)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Breview – Order reviews for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 22
actionplugins_loadedbreview.php:53
actionwp_enqueue_scriptsbreview.php:54
actionadmin_menubreview.php:55
actionmswa_overview_contentbreview.php:56
actionmswa_overview_sidebarbreview.php:57
actionadmin_enqueue_scriptsbreview.php:58
actionadmin_enqueue_scriptsbreview.php:59
actioninitbreview.php:60
actionadmin_noticesbreview.php:87
actionwoocommerce_order_status_changedinc\emails\completed.php:2
actionmsbr_review_userinc\functions\hooks-actions.php:26
actionmsbr_review_userinc\functions\hooks-actions.php:38
actionmsbr_review_contentinc\functions\hooks-actions.php:50
actionmsbr_review_contentinc\functions\hooks-actions.php:61
filterwoocommerce_review_gravatar_sizeinc\functions\hooks-actions.php:73
actionmsbr_review_ratinginc\functions\hooks-actions.php:85
actionmsbr_review_ratinginc\functions\hooks-actions.php:104
actionwoocommerce_order_item_meta_endinc\functions\review-form.php:2
actioncomment_postinc\functions\review-form.php:95
actionwoocommerce_order_details_before_order_table_itemsinc\functions\review-form.php:118
filterwoocommerce_product_tabsinc\functions\review-product-page.php:3
filterwoocommerce_product_tabsinc\functions\review-product-page.php:11
Maintenance & Trust

Breview – Order reviews for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedApr 3, 2024
PHP min version7.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Breview – Order reviews for WooCommerce Developer Profile

MS Web Arts

2 plugins · 60 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Breview – Order reviews for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/breview/assets/js/star-rating.min.js/wp-content/plugins/breview/assets/js/jquery.star-rating-svg.min.js/wp-content/plugins/breview/assets/js/iziModal.min.js/wp-content/plugins/breview/assets/js/pagination.min.js/wp-content/plugins/breview/assets/js/jquery.validate.min.js/wp-content/plugins/breview/assets/js/main.js/wp-content/plugins/breview/assets/css/star-rating.min.css/wp-content/plugins/breview/assets/css/star-rating-svg.css+4 more
Script Paths
/wp-content/plugins/breview/assets/js/main.js
Version Parameters
msbr-star-rating?ver=msbr-star-rating-svg?ver=msbr-iziModal?ver=msbr-pagination?ver=msbr-jquery-validate?ver=msbr-script?ver=msbr-star-rating?ver=msbr-star-rating-svg?ver=msbr-iziModal?ver=msbr-style?ver=msbr-responsive?ver=msbr-inline?ver=

HTML / DOM Fingerprints

JS Globals
msbr_review
FAQ

Frequently Asked Questions about Breview – Order reviews for WooCommerce