Codeies – Elite user Ratings Security & Risk Analysis

wordpress.org/plugins/codeies-elite-user-ratings

Elite User ratings allows your visitors to submit user reviews with a 1-5 star rating on your website

0 active installs v1.0.0 PHP 7.4+ WP 6.0.3+ Updated Nov 7, 2022
buddypressratingusers
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Codeies – Elite user Ratings Safe to Use in 2026?

Generally Safe

Score 85/100

Codeies – Elite user Ratings has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "codeies-elite-user-ratings" plugin v1.0.0 exhibits a mixed security posture. While it has no recorded vulnerability history, indicating a positive trend in past security practices or discovery, the static analysis reveals significant concerns. A notable weakness is the presence of two AJAX handlers that lack authentication checks, creating an open attack vector. Furthermore, the plugin utilizes the `unserialize` function twice, which is inherently dangerous if used with user-supplied data, and a critical taint flow was identified, suggesting a potential for malicious input to be processed without proper sanitization.

The absence of nonce checks on AJAX actions and the identification of a flow with unsanitized paths are particularly worrying. Although 63% of SQL queries use prepared statements and 74% of outputs are properly escaped, these mitigating factors are overshadowed by the critical security flaws. The plugin's attack surface is relatively small with 6 entry points, but the fact that 2 of these are unprotected is a critical oversight. In conclusion, while the plugin's lack of historical vulnerabilities is a positive sign, the current static analysis highlights critical vulnerabilities that require immediate attention to secure the plugin against potential exploitation.

Key Concerns

  • Unprotected AJAX handlers
  • Dangerous function: unserialize
  • Critical severity taint flow
  • Flows with unsanitized paths
  • Missing nonce checks
  • Limited capability checks
Vulnerabilities
None known

Codeies – Elite user Ratings Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Codeies – Elite user Ratings Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

Codeies – Elite user Ratings Code Analysis

Dangerous Functions
2
Raw SQL Queries
3
5 prepared
Unescaped Output
9
26 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

unserialize$ratings = unserialize($isRated['criteria']);public\template\codeies_wmr_profile\codeies_wmr_profile.php:16
unserialize<?php $mainreviews = unserialize($reviews['criteria']); ?>public\template\codeies_wmr_profile\codeies_wmr_reviews.php:40

SQL Query Safety

63% prepared8 total queries

Output Escaping

74% escaped35 total outputs
Data Flows · Security
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<codeies_wmr_reviews> (public\template\codeies_wmr_profile\codeies_wmr_reviews.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Codeies – Elite user Ratings Attack Surface

Entry Points6
Unprotected2

AJAX Handlers 2

authwp_ajax_codeies_wmr_submit_reviewincludes\class-wordpress-member-ratings.php:164
authwp_ajax_codeies_wmr_resetDatabaseincludes\class-wordpress-member-ratings.php:166

Shortcodes 4

[codeies_wmr_ratings] public\class-wordpress-member-ratings-public.php:112
[codeies_wmr_profile] public\class-wordpress-member-ratings-public.php:113
[codeies_wmr_average_rating] public\class-wordpress-member-ratings-public.php:114
[codeies_wmr_ratingpage_link] public\class-wordpress-member-ratings-public.php:115
WordPress Hooks 8
actionplugins_loadedelite-user-ratings.php:78
actioncarbon_fields_register_fieldsincludes\class-wordpress-member-ratings-settings.php:33
actionplugins_loadedincludes\class-wordpress-member-ratings.php:147
actionadmin_enqueue_scriptsincludes\class-wordpress-member-ratings.php:162
actionadmin_enqueue_scriptsincludes\class-wordpress-member-ratings.php:163
actionwp_enqueue_scriptsincludes\class-wordpress-member-ratings.php:181
actionwp_enqueue_scriptsincludes\class-wordpress-member-ratings.php:182
actioninitincludes\class-wordpress-member-ratings.php:184
Maintenance & Trust

Codeies – Elite user Ratings Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedNov 7, 2022
PHP min version7.4
Downloads741

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Codeies – Elite user Ratings Developer Profile

Codeies Pvt Ltd

2 plugins · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Codeies – Elite user Ratings

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/codeies-elite-user-ratings/admin/js/wordpress-member-ratings-admin.js
Script Paths
/wp-content/plugins/codeies-elite-user-ratings/admin/js/wordpress-member-ratings-admin.js
Version Parameters
wordpress-member-ratings-admin.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Codeies – Elite user Ratings