
Codeies – Elite user Ratings Security & Risk Analysis
wordpress.org/plugins/codeies-elite-user-ratingsElite User ratings allows your visitors to submit user reviews with a 1-5 star rating on your website
Is Codeies – Elite user Ratings Safe to Use in 2026?
Generally Safe
Score 85/100Codeies – Elite user Ratings has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "codeies-elite-user-ratings" plugin v1.0.0 exhibits a mixed security posture. While it has no recorded vulnerability history, indicating a positive trend in past security practices or discovery, the static analysis reveals significant concerns. A notable weakness is the presence of two AJAX handlers that lack authentication checks, creating an open attack vector. Furthermore, the plugin utilizes the `unserialize` function twice, which is inherently dangerous if used with user-supplied data, and a critical taint flow was identified, suggesting a potential for malicious input to be processed without proper sanitization.
The absence of nonce checks on AJAX actions and the identification of a flow with unsanitized paths are particularly worrying. Although 63% of SQL queries use prepared statements and 74% of outputs are properly escaped, these mitigating factors are overshadowed by the critical security flaws. The plugin's attack surface is relatively small with 6 entry points, but the fact that 2 of these are unprotected is a critical oversight. In conclusion, while the plugin's lack of historical vulnerabilities is a positive sign, the current static analysis highlights critical vulnerabilities that require immediate attention to secure the plugin against potential exploitation.
Key Concerns
- Unprotected AJAX handlers
- Dangerous function: unserialize
- Critical severity taint flow
- Flows with unsanitized paths
- Missing nonce checks
- Limited capability checks
Codeies – Elite user Ratings Security Vulnerabilities
Codeies – Elite user Ratings Release Timeline
Codeies – Elite user Ratings Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Codeies – Elite user Ratings Attack Surface
AJAX Handlers 2
Shortcodes 4
WordPress Hooks 8
Maintenance & Trust
Codeies – Elite user Ratings Maintenance & Trust
Maintenance Signals
Community Trust
Codeies – Elite user Ratings Alternatives
BP Profile Search
bp-profile-search
Member search and member directories for BuddyPress and the BuddyBoss Platform.
Bulk Edit and Create User Profiles – WP Sheet Editor
bulk-edit-user-profiles-in-spreadsheet
Modern Bulk Editor for Users and Profiles, create and edit hundreds of users in a spreadsheet inside wp-admin. Quick edits.
BuddyPress Default Data
bp-default-data
Plugin will create lots of users, messages, friends connections, groups, topics, activity items, profile data - useful for testing purpose.
BuddyPress to WordPress Full Sync
bp2wp-full-sync
BuddyPress to WordPress Full Sync lets BuddyPress xProfile fields to synchronize with WordPress user fields
LH Buddypress Export Xprofile Data
lh-buddypress-export-xprofile-data
This plugin lets you export xprofile field data from BuddyPress, as CSV, for manipulation elsewhere..
Codeies – Elite user Ratings Developer Profile
2 plugins · 10 total installs
How We Detect Codeies – Elite user Ratings
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/codeies-elite-user-ratings/admin/js/wordpress-member-ratings-admin.js/wp-content/plugins/codeies-elite-user-ratings/admin/js/wordpress-member-ratings-admin.jswordpress-member-ratings-admin.js?ver=