Collect Reviews Security & Risk Analysis

wordpress.org/plugins/collect-reviews

The ultimate WordPress plugin for automatically collecting reviews on any platform like Google or Facebook.

60 active installs v1.1.4 PHP 7.2+ WP 5.3+ Updated May 17, 2025
customer-reviewsgoogle-reviewsreviews-collectionwoocommercewpforms
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Collect Reviews Safe to Use in 2026?

Generally Safe

Score 100/100

Collect Reviews has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10mo ago
Risk Assessment

The collect-reviews plugin v1.1.4 demonstrates a generally strong security posture based on the provided static analysis. The absence of directly exploitable attack surface, such as unprotected AJAX handlers, REST API routes, or shortcodes, is a significant positive. The code also shows excellent adherence to secure coding practices with 100% output escaping and a high percentage of SQL queries utilizing prepared statements. The presence of nonce and capability checks further reinforces its defensive measures.

However, there are a few areas that warrant attention. The existence of a cron event without explicitly stated authentication checks could potentially introduce a minor risk if it interacts with sensitive data or functions. While the taint analysis found no issues, the limited scope (only 2 flows analyzed) means this is not exhaustive. The plugin's clean vulnerability history is encouraging, suggesting good maintenance and a lack of past exploitable flaws. This indicates a well-developed plugin, but the limited scope of the taint analysis prevents a complete assurance.

Overall, collect-reviews v1.1.4 appears to be a secure plugin, with its strengths significantly outweighing potential minor concerns. The developers seem to follow secure coding best practices. The main area for potential enhancement would be to ensure all components, including cron events, are adequately secured, and to perform more extensive taint analysis if possible.

Key Concerns

  • Cron event without explicit auth check
Vulnerabilities
None known

Collect Reviews Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Collect Reviews Code Analysis

Dangerous Functions
0
Raw SQL Queries
4
21 prepared
Unescaped Output
0
104 escaped
Nonce Checks
1
Capability Checks
1
File Operations
2
External Requests
0
Bundled Libraries
0

SQL Query Safety

84% prepared25 total queries

Output Escaping

100% escaped104 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
handle (src\Ajax\AjaxManager.php:92)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Collect Reviews Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 20
actionadmin_noticescollect-reviews.php:131
actionadmin_noticescollect-reviews.php:142
actionadmin_menusrc\Admin\Admin.php:29
actionin_admin_headersrc\Admin\Admin.php:51
filteradmin_footer_textsrc\Admin\Admin.php:54
actionadmin_enqueue_scriptssrc\Admin\Scripts.php:25
actionplugins_loadedsrc\Core.php:85
actionadmin_initsrc\DatabaseMigrations\DatabaseMigrations.php:47
filterwp_mail_fromsrc\Emails\Mailer.php:222
filterwp_mail_from_namesrc\Emails\Mailer.php:223
filterwp_mail_content_typesrc\Emails\Mailer.php:224
actionedd_before_payment_status_changesrc\Integrations\EasyDigitalDownloads\Integration.php:34
actionwoocommerce_order_status_changedsrc\Integrations\WooCommerce\Integration.php:34
actionwpforms_process_completesrc\Integrations\WPForms\Integration.php:35
actiontemplate_redirectsrc\ReviewReplies\ReviewReplyPage.php:34
filterdocument_title_partssrc\ReviewReplies\ReviewReplyPage.php:48
actionwp_enqueue_scriptssrc\ReviewReplies\ReviewReplyPage.php:49
filtertemplate_includesrc\ReviewReplies\ReviewReplyPage.php:160
actioncollect_reviews_review_requests_queuesrc\ReviewRequests\Queue.php:35
filterdate_query_valid_columnssrc\ReviewRequests\ReviewRequestsDataStore.php:365

Scheduled Events 1

collect_reviews_review_requests_queue
Maintenance & Trust

Collect Reviews Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 17, 2025
PHP min version7.2
Downloads6K

Community Trust

Rating100/100
Number of ratings1
Active installs60
Developer Profile

Collect Reviews Developer Profile

Collect Reviews WP

1 plugin · 60 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Collect Reviews

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/collect-reviews/assets/app/app.css/wp-content/plugins/collect-reviews/assets/app/app.js
Script Paths
/wp-content/plugins/collect-reviews/assets/app/app.js
Version Parameters
collect-reviews/assets/app/app.css?ver=collect-reviews/assets/app/app.js?ver=

HTML / DOM Fingerprints

CSS Classes
collect-reviews-reply-form
Data Attributes
data-collect-reviews-ajax-urldata-collect-reviews-ajax-noncedata-collect-reviews-plugin-urldata-collect-reviews-optionsdata-collect-reviews-pagedata-collect-reviews-integrations+6 more
JS Globals
collect_reviews_admin
FAQ

Frequently Asked Questions about Collect Reviews