Certishopping Social Reviews for Woocommerce Security & Risk Analysis

wordpress.org/plugins/certishopping-social-reviews-for-woocommerce

Certishopping is a commerce marketing platform that helps brands of all sizes collect and showcase reviews, photos.

100 active installs v4.2.9 PHP + WP 4.5+ Updated Mar 13, 2025
aviscertishoppingreviewsstars
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Certishopping Social Reviews for Woocommerce Safe to Use in 2026?

Generally Safe

Score 92/100

Certishopping Social Reviews for Woocommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "certishopping-social-reviews-for-woocommerce" plugin version 4.2.9 exhibits a generally strong security posture. The static analysis reveals good security practices, with no dangerous functions detected, all SQL queries utilizing prepared statements, and a high percentage of output properly escaped. Furthermore, the plugin incorporates nonce and capability checks for all identified entry points. The absence of any recorded CVEs, past or present, is a significant positive indicator of its historical security. The taint analysis also did not identify any critical or high severity vulnerabilities, though one flow with an unsanitized path was noted, which warrants further investigation.

While the overall picture is positive, the presence of one unsanitized path in the taint analysis, even without a critical or high severity rating, represents a potential area of concern that could be exploited under specific circumstances. The relatively small attack surface of 4 shortcodes is a strength, and the lack of direct file operations or external HTTP requests further reduces risk. However, no security solution is perfect, and the single unsanitized path, however minor it appears, means there is a theoretical avenue for data manipulation.

In conclusion, this plugin appears to be well-secured based on the provided data. Its developers have implemented several key security best practices. The limited number of entry points and the robust use of prepared statements and escaping are commendable. The absence of known vulnerabilities is a strong testament to its reliability. The only notable weakness is the single identified unsanitized path, which, while not rated as critical, should still be considered in a comprehensive risk assessment.

Key Concerns

  • Taint flow with unsanitized path
Vulnerabilities
None known

Certishopping Social Reviews for Woocommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Certishopping Social Reviews for Woocommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
10
56 escaped
Nonce Checks
4
Capability Checks
4
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

85% escaped66 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
wc_proccess_certishopping_settings (templates\wc-certishopping-settings.php:349)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Certishopping Social Reviews for Woocommerce Attack Surface

Entry Points4
Unprotected0

Shortcodes 4

[certishopping_widget_slider_reviews] wc-certishopping-shortcodes.php:34
[certishopping_widget_modal_reviews] wc-certishopping-shortcodes.php:48
[certishopping_show_product_widget] wc_certishopping.php:102
[certishopping_star_rating] wc_certishopping.php:113
WordPress Hooks 20
actionwp_footerwc-certishopping-shortcodes.php:66
actionplugins_loadedwc_certishopping.php:19
actioninitwc_certishopping.php:20
actionwp_enqueue_scriptswc_certishopping.php:21
actionadmin_menuwc_certishopping.php:44
actionwp_headwc_certishopping.php:56
actiontemplate_redirectwc_certishopping.php:57
actionadmin_enqueue_scriptswc_certishopping.php:75
actionwoocommerce_thankyouwc_certishopping.php:81
filtercomments_openwc_certishopping.php:90
actionwoocommerce_after_single_productwc_certishopping.php:94
actionwoocommerce_product_tabswc_certishopping.php:98
actionwoocommerce_single_product_summarywc_certishopping.php:108
actionwoocommerce_after_shop_loop_itemwc_certishopping.php:119
filterwoocommerce_tab_manager_integration_tab_allowedwc_certishopping.php:788
actionwoocommerce_order_status_changedwc_certishopping.php:917
actionwoocommerce_new_orderwc_certishopping.php:918
actionplugins_loadedwc_certishopping.php:943
actionadded_post_metawc_certishopping.php:1151
actionsave_postwc_certishopping.php:1152
Maintenance & Trust

Certishopping Social Reviews for Woocommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedMar 13, 2025
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings2
Active installs100
Developer Profile

Certishopping Social Reviews for Woocommerce Developer Profile

certishopping

1 plugin · 100 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Certishopping Social Reviews for Woocommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/certishopping-social-reviews-for-woocommerce/assets/css/bottom-line.css
Script Paths
https://certishopping.com/api/widget/v8/javascript/widgetv8.min.js

HTML / DOM Fingerprints

CSS Classes
certishopping-widget
Data Attributes
data-certishopping-widget
JS Globals
certishopping
Shortcode Output
[certishopping_show_product_widget][certishopping_star_rating]
FAQ

Frequently Asked Questions about Certishopping Social Reviews for Woocommerce