
CBX Multi Criteria Rating & Review Security & Risk Analysis
wordpress.org/plugins/cbxmcratingreviewMulti Criteria Rating and Review for WordPress with Multi Forms, Question bank and more.
Is CBX Multi Criteria Rating & Review Safe to Use in 2026?
Generally Safe
Score 100/100CBX Multi Criteria Rating & Review has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "cbxmcratingreview" plugin v2.0.4 presents a mixed security posture. On the positive side, it has a clean vulnerability history with no recorded CVEs, indicating a potentially stable and well-maintained codebase. The plugin also demonstrates good practices in its use of prepared statements for SQL queries and proper output escaping, which are crucial for preventing common web vulnerabilities. However, the static analysis reveals significant concerns regarding its attack surface. A notable portion of its AJAX handlers lack proper authentication checks, creating an immediate risk of unauthorized actions. The presence of the `unserialize` function also warrants caution, as it can be a vector for remote code execution if not handled with extreme care and input validation. While taint analysis didn't highlight critical issues in this specific scan, the combination of insecure AJAX endpoints and the `unserialize` function remains a latent threat.
Overall, while the plugin avoids historical vulnerabilities and implements some good security practices, the identified weaknesses in its attack surface and the potential danger of `unserialize` introduce significant risks. The lack of authentication on AJAX endpoints is a primary concern that requires immediate attention. Strengthening access control on these entry points, alongside careful review of any data processed by `unserialize`, would greatly improve the plugin's security. The absence of file operations and external HTTP requests is a positive aspect, reducing potential attack vectors in those areas. The plugin's strengths lie in its database query security and output sanitization, but these are unfortunately overshadowed by the vulnerabilities in its direct interaction points.
Key Concerns
- Unprotected AJAX handlers
- Dangerous function: unserialize
- Bundled library: Select2 (potential outdatedness)
CBX Multi Criteria Rating & Review Security Vulnerabilities
CBX Multi Criteria Rating & Review Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
CBX Multi Criteria Rating & Review Attack Surface
AJAX Handlers 7
Shortcodes 8
WordPress Hooks 45
Maintenance & Trust
CBX Multi Criteria Rating & Review Maintenance & Trust
Maintenance Signals
Community Trust
CBX Multi Criteria Rating & Review Alternatives
CBX 5 Star Rating & Review
cbxscratingreview
Single Criteria Rating and Review for WordPress and more.
Site Reviews
site-reviews
Site Reviews is a complete review management solution that integrates with WooCommerce and SureCart and works similarly to reviews on Amazon, Tripadvi …
Better Business Reviews – Trustpilot WordPress Plugin
better-business-reviews
Better Business Reviews allows you to display your business reviews from a Trustpilot profile.
Smart Showcase for Google Reviews
smart-showcase-for-google-reviews
Smart Showcase for Google Reviews is a WordPress plugin that lets businesses display Google customer reviews on their websites easily.
Automatic Update Google Business Profile Reviews
automatic-update-google-business-profile-reviews
This Plugins gets average rating from your company\'s Google My Business entry. You can display the rating on your wordpress website.
CBX Multi Criteria Rating & Review Developer Profile
9 plugins · 3K total installs
How We Detect CBX Multi Criteria Rating & Review
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cbxmcratingreview/assets/css/backend.css/wp-content/plugins/cbxmcratingreview/assets/css/frontend.css/wp-content/plugins/cbxmcratingreview/assets/js/backend.js/wp-content/plugins/cbxmcratingreview/assets/js/frontend.js/wp-content/plugins/cbxmcratingreview/assets/js/backend.js/wp-content/plugins/cbxmcratingreview/assets/js/frontend.jscbxmcratingreview/assets/css/backend.css?ver=cbxmcratingreview/assets/css/frontend.css?ver=cbxmcratingreview/assets/js/backend.js?ver=cbxmcratingreview/assets/js/frontend.js?ver=HTML / DOM Fingerprints
cbx-rating-review-wrappercbx-rating-review-summarycbx-rating-review-criteriacbx-rating-review-itemcbx-rating-review-starscbx-rating-review-bar-wrappercbx-rating-review-barcbx-rating-review-scoredata-cbx-rating-reviewcbx_rating_review_frontend_params/wp-json/cbxratingreview/v1/submit/wp-json/cbxratingreview/v1/get_reviews