
Business Reviews – Display Customer Reviews from Popular Sites Security & Risk Analysis
wordpress.org/plugins/business-reviewBusiness Reviews helps you display Google, Facebook, and Yelp reviews easily on your WordPress site to build trust and boost your business reputation.
Is Business Reviews – Display Customer Reviews from Popular Sites Safe to Use in 2026?
Generally Safe
Score 100/100Business Reviews – Display Customer Reviews from Popular Sites has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "business-review" plugin v1.0.16 exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of any critical or high-severity taint flows, dangerous functions, raw SQL queries, or file operations is a significant positive indicator. The plugin also demonstrates good practices by implementing nonce checks on all its AJAX handlers and capability checks on most, with a high percentage of properly escaped output. The total entry points are well-protected.
However, there are minor areas for improvement. While all AJAX handlers have nonce checks, not all (5 out of 6) have capability checks, leaving a potential, albeit small, window for unauthorized actions if an attacker could bypass the nonce. The presence of 6 external HTTP requests could be a concern if these endpoints are not properly secured or if they introduce dependencies on vulnerable external services. The plugin also bundles the Freemius library, which, if outdated, could introduce vulnerabilities.
Historically, the plugin has no recorded vulnerabilities, which is an excellent sign of a well-maintained and secure codebase. This lack of past issues suggests a commitment to security. In conclusion, the plugin is generally secure with a low-risk profile, but attention to ensuring capability checks on all AJAX actions and vigilance regarding external dependencies and bundled libraries would further enhance its security.
Key Concerns
- Missing capability check on one AJAX handler
- Bundled library (Freemius) may be outdated
Business Reviews – Display Customer Reviews from Popular Sites Security Vulnerabilities
Business Reviews – Display Customer Reviews from Popular Sites Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Business Reviews – Display Customer Reviews from Popular Sites Attack Surface
AJAX Handlers 6
Shortcodes 1
WordPress Hooks 21
Maintenance & Trust
Business Reviews – Display Customer Reviews from Popular Sites Maintenance & Trust
Maintenance Signals
Community Trust
Business Reviews – Display Customer Reviews from Popular Sites Alternatives
Review Map by RevuKangaroo
review-map-by-revukangaroo
Show off your customer's online reviews with Review Map by Revukangaroo.
Widgets for Google Reviews
wp-reviews-plugin-for-google
Embed Google reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Google reviews.
Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More
reviews-feed
No API key required. Display Yelp and Google reviews for any business in a clean, customizable feed on your site.
Reviews and Rating – Google Reviews
g-business-reviews-rating
Completely restriction-free Google reviews and rating as Shortcode/Widget. Extensive display options; delicious themes; includes Structured Data.
Reviews Widgets for Google, Yelp & TripAdvisor
fb-reviews-widget
Combine Facebook recommendations with Google, Yelp and TripAdvisor reviews in a widget, block or shortcode. Build a trusted website!
Business Reviews – Display Customer Reviews from Popular Sites Developer Profile
120 plugins · 738K total installs
How We Detect Business Reviews – Display Customer Reviews from Popular Sites
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/business-review/assets/css/admin.css/wp-content/plugins/business-review/assets/js/admin.js/wp-content/plugins/business-review/assets/css/fontAwesome.min.css/wp-content/plugins/business-review/assets/js/masonry.min.jsbusiness-review/assets/css/admin.css?ver=business-review/assets/js/admin.js?ver=business-review/assets/css/fontAwesome.min.css?ver=business-review/assets/js/masonry.min.js?ver=HTML / DOM Fingerprints
grbb-admin-editorbp_reviews_containerbp-reviews-wrapperbusiness-review-widgetdata-plugin-name="business-review"data-plugin-version="1.0.16"grbbData/wp-json/grbb-business-review/v1/reviews[business_reviews][business_review]