Business Reviews – Display Customer Reviews from Popular Sites Security & Risk Analysis

wordpress.org/plugins/business-review

Business Reviews helps you display Google, Facebook, and Yelp reviews easily on your WordPress site to build trust and boost your business reputation.

1K active installs v1.0.16 PHP 7.1+ WP 6.5+ Updated Feb 26, 2026
blockbusinessfacebookgooglereviews
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Business Reviews – Display Customer Reviews from Popular Sites Safe to Use in 2026?

Generally Safe

Score 100/100

Business Reviews – Display Customer Reviews from Popular Sites has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "business-review" plugin v1.0.16 exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of any critical or high-severity taint flows, dangerous functions, raw SQL queries, or file operations is a significant positive indicator. The plugin also demonstrates good practices by implementing nonce checks on all its AJAX handlers and capability checks on most, with a high percentage of properly escaped output. The total entry points are well-protected.

However, there are minor areas for improvement. While all AJAX handlers have nonce checks, not all (5 out of 6) have capability checks, leaving a potential, albeit small, window for unauthorized actions if an attacker could bypass the nonce. The presence of 6 external HTTP requests could be a concern if these endpoints are not properly secured or if they introduce dependencies on vulnerable external services. The plugin also bundles the Freemius library, which, if outdated, could introduce vulnerabilities.

Historically, the plugin has no recorded vulnerabilities, which is an excellent sign of a well-maintained and secure codebase. This lack of past issues suggests a commitment to security. In conclusion, the plugin is generally secure with a low-risk profile, but attention to ensuring capability checks on all AJAX actions and vigilance regarding external dependencies and bundled libraries would further enhance its security.

Key Concerns

  • Missing capability check on one AJAX handler
  • Bundled library (Freemius) may be outdated
Vulnerabilities
None known

Business Reviews – Display Customer Reviews from Popular Sites Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Business Reviews – Display Customer Reviews from Popular Sites Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
44 escaped
Nonce Checks
6
Capability Checks
5
File Operations
0
External Requests
6
Bundled Libraries
1

Bundled Libraries

Freemius

Output Escaping

94% escaped47 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
fs_init (freemius-lite\inc\Base\FSActivate.php:68)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Business Reviews – Display Customer Reviews from Popular Sites Attack Surface

Entry Points7
Unprotected0

AJAX Handlers 6

authwp_ajax_get_all_reviewsapi\BusinessReviewAPI.php:10
noprivwp_ajax_get_all_reviewsapi\BusinessReviewAPI.php:11
authwp_ajax_grbb_get_access_tokenapi\BusinessReviewAPI.php:13
noprivwp_ajax_grbb_get_access_tokenapi\BusinessReviewAPI.php:14
authwp_ajax_grbb_remove_cacheapi\BusinessReviewAPI.php:16
authwp_ajax_fs_initfreemius-lite\inc\Base\FSActivate.php:42

Shortcodes 1

[business-review] custom-post.php:11
WordPress Hooks 21
actioninitcustom-post.php:10
filtermanage_grbb_posts_columnscustom-post.php:12
actionmanage_grbb_posts_custom_columncustom-post.php:13
actionuse_block_editor_for_postcustom-post.php:14
actionadmin_headfreemius-lite\inc\Base\FSActivate.php:29
actionadmin_enqueue_scriptsfreemius-lite\inc\Base\FSActivate.php:30
actionadmin_menufreemius-lite\inc\Base\FSActivate.php:33
actionadmin_footerfreemius-lite\inc\Base\FSActivate.php:38
actionadmin_footerfreemius-lite\inc\Base\FSActivate.php:39
actionadmin_noticesfreemius-lite\inc\Base\FSActivate.php:44
actioninitfreemius-lite\inc\Base\FS_Lite.php:29
actionadmin_enqueue_scriptsincludes\admin-menu-free.php:9
actionadmin_menuincludes\admin-menu-free.php:10
actionenqueue_block_editor_assetsindex.php:84
actionenqueue_block_assetsindex.php:85
actioninitindex.php:86
actionadmin_enqueue_scriptsindex.php:87
filterplugin_row_metaindex.php:88
actionadmin_initindex.php:94
actionrest_api_initindex.php:95
filterplugin_action_linksindex.php:97
Maintenance & Trust

Business Reviews – Display Customer Reviews from Popular Sites Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 26, 2026
PHP min version7.1
Downloads24K

Community Trust

Rating100/100
Number of ratings1
Active installs1K
Developer Profile

Business Reviews – Display Customer Reviews from Popular Sites Developer Profile

colorlibplugins

120 plugins · 738K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
140 days
View full developer profile
Detection Fingerprints

How We Detect Business Reviews – Display Customer Reviews from Popular Sites

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/business-review/assets/css/admin.css/wp-content/plugins/business-review/assets/js/admin.js/wp-content/plugins/business-review/assets/css/fontAwesome.min.css/wp-content/plugins/business-review/assets/js/masonry.min.js
Version Parameters
business-review/assets/css/admin.css?ver=business-review/assets/js/admin.js?ver=business-review/assets/css/fontAwesome.min.css?ver=business-review/assets/js/masonry.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
grbb-admin-editorbp_reviews_containerbp-reviews-wrapperbusiness-review-widget
Data Attributes
data-plugin-name="business-review"data-plugin-version="1.0.16"
JS Globals
grbbData
REST Endpoints
/wp-json/grbb-business-review/v1/reviews
Shortcode Output
[business_reviews][business_review]
FAQ

Frequently Asked Questions about Business Reviews – Display Customer Reviews from Popular Sites