
Widget for Google Reviews Security & Risk Analysis
wordpress.org/plugins/business-reviews-wpShortcode and widget for Google Reviews. Display Google Business Reviews on your WordPress website to increase user confidence and SEO.
Is Widget for Google Reviews Safe to Use in 2026?
Generally Safe
Score 95/100Widget for Google Reviews has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "business-reviews-wp" plugin exhibits a mixed security posture. While it demonstrates strong practices in areas like SQL query sanitization and output escaping, with 100% of SQL queries using prepared statements and 98% of output properly escaped, significant concerns arise from its attack surface. Specifically, the presence of 4 AJAX handlers, with 2 lacking authentication checks, presents a direct pathway for potential exploitation. The taint analysis reveals no critical or high-severity issues, which is a positive sign, suggesting that user-supplied data, if it reaches sensitive functions, is generally handled with some degree of sanitization. However, the absence of taint issues doesn't negate the risk posed by unprotected entry points.
The plugin's vulnerability history is a major red flag. Having 2 known high-severity CVEs, both related to 'Improper Control of Filename for Include/Require Statement in PHP Program' (PHP Remote File Inclusion), strongly indicates a recurring pattern of critical security flaws. The fact that these vulnerabilities are historical and currently patched is a mitigating factor, but the nature of past exploits suggests that the code may have underlying architectural weaknesses that could be re-introduced or discovered in future versions. The most recent vulnerability being dated 2025-07-16 is unusual, suggesting either a future discovery or a typo in the data provided. Regardless, the historical context of RFI vulnerabilities demands vigilance. In conclusion, while the plugin has improved its secure coding practices in certain aspects, the significant attack surface with unprotected AJAX handlers and the history of high-severity RFI vulnerabilities necessitate careful consideration and ongoing monitoring.
Key Concerns
- AJAX handlers without auth checks
- 2 High severity CVEs in history
- History of RFI vulnerabilities
Widget for Google Reviews Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Widget for Google Reviews <= 1.0.15 - Unauthenticated Local File Inclusion
Widget for Google Reviews <= 1.0.15 - Authenticated (Subscriber+) Directory Traversal to Local File Inclusion
Widget for Google Reviews Release Timeline
Widget for Google Reviews Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Widget for Google Reviews Attack Surface
AJAX Handlers 4
WordPress Hooks 33
Maintenance & Trust
Widget for Google Reviews Maintenance & Trust
Maintenance Signals
Community Trust
Widget for Google Reviews Alternatives
Free Google Reviews widget by OpenWidget
free-google-reviews-widget-by-openwidget
⭐️ Embed Google reviews into your WordPress site. Improve trust, sales & SEO of your Wordpress site with Google reviews.
Smart Showcase for Google Reviews
smart-showcase-for-google-reviews
Smart Showcase for Google Reviews is a WordPress plugin that lets businesses display Google customer reviews on their websites easily.
Get Google Reviews
get-google-reviews
Get your Google Reviews and display them on your website. Easily and without needing an API key.
Automatic Update Google Business Profile Reviews
automatic-update-google-business-profile-reviews
This Plugins gets average rating from your company\'s Google My Business entry. You can display the rating on your wordpress website.
Widgets for Google Reviews
wp-reviews-plugin-for-google
Embed Google reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Google reviews.
Widget for Google Reviews Developer Profile
16 plugins · 214K total installs
How We Detect Widget for Google Reviews
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/business-reviews-wp/assets/css/app.css/wp-content/plugins/business-reviews-wp/assets/js/app.js/wp-content/plugins/business-reviews-wp/assets/vendor/select2/select2.min.css/wp-content/plugins/business-reviews-wp/assets/css/admin.css/wp-content/plugins/business-reviews-wp/assets/vendor/select2/select2.min.js/wp-content/plugins/business-reviews-wp/assets/js/admin.js/wp-content/plugins/business-reviews-wp/assets/js/app.js/wp-content/plugins/business-reviews-wp/assets/js/admin.jsbusiness-reviews-wp/assets/css/app.css?ver=business-reviews-wp/assets/js/app.js?ver=business-reviews-wp/assets/vendor/select2/select2.min.css?ver=business-reviews-wp/assets/css/admin.css?ver=business-reviews-wp/assets/vendor/select2/select2.min.js?ver=business-reviews-wp/assets/js/admin.js?ver=HTML / DOM Fingerprints
rtbr-apprtbr-adminrtbr_ny_2023rtbr_noticedata-rtbrdismissablertbr