
Collect Reviews Security & Risk Analysis
wordpress.org/plugins/collect-reviewsThe ultimate WordPress plugin for automatically collecting reviews on any platform like Google or Facebook.
Is Collect Reviews Safe to Use in 2026?
Generally Safe
Score 100/100Collect Reviews has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The collect-reviews plugin v1.1.4 demonstrates a generally strong security posture based on the provided static analysis. The absence of directly exploitable attack surface, such as unprotected AJAX handlers, REST API routes, or shortcodes, is a significant positive. The code also shows excellent adherence to secure coding practices with 100% output escaping and a high percentage of SQL queries utilizing prepared statements. The presence of nonce and capability checks further reinforces its defensive measures.
However, there are a few areas that warrant attention. The existence of a cron event without explicitly stated authentication checks could potentially introduce a minor risk if it interacts with sensitive data or functions. While the taint analysis found no issues, the limited scope (only 2 flows analyzed) means this is not exhaustive. The plugin's clean vulnerability history is encouraging, suggesting good maintenance and a lack of past exploitable flaws. This indicates a well-developed plugin, but the limited scope of the taint analysis prevents a complete assurance.
Overall, collect-reviews v1.1.4 appears to be a secure plugin, with its strengths significantly outweighing potential minor concerns. The developers seem to follow secure coding best practices. The main area for potential enhancement would be to ensure all components, including cron events, are adequately secured, and to perform more extensive taint analysis if possible.
Key Concerns
- Cron event without explicit auth check
Collect Reviews Security Vulnerabilities
Collect Reviews Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Collect Reviews Attack Surface
WordPress Hooks 20
Scheduled Events 1
Maintenance & Trust
Collect Reviews Maintenance & Trust
Maintenance Signals
Community Trust
Collect Reviews Alternatives
ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema
reviewx
Drive woocommerce business growth with social proof: gather product reviews with multicriteria ratings, auto-reminder emails, discounts, and more.
Customer Reviews Collector for WooCommerce
customer-reviews-collector-for-woocommerce
Collect reviews on Google, Facebook, Yelp, Trustindex and other platforms automatically, with the help of our system.
Merchant Center Reviews for Woocommerce
merchant-center-reviews-for-woocommerce
Merchant Center Reviews for WooCommerce automates the process of requesting reviews via Google Merchant Center, helping you collect valuable feedback.
Customer Reviews for WooCommerce
customer-reviews-woocommerce
Customer Reviews for WooCommerce plugin helps you get more sales with social proof. Set up automated review reminders and increase conversion rate.
WP Social Ninja – Embed Social Feeds, User Reviews & Chat Widgets
wp-social-reviews
Add Facebook feeds, Instagram feeds, TikTok feeds, Facebook reviews, WhatsApp Chat, Messenger chat, Testimonial, and others using a single dashboard.
Collect Reviews Developer Profile
1 plugin · 60 total installs
How We Detect Collect Reviews
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/collect-reviews/assets/app/app.css/wp-content/plugins/collect-reviews/assets/app/app.js/wp-content/plugins/collect-reviews/assets/app/app.jscollect-reviews/assets/app/app.css?ver=collect-reviews/assets/app/app.js?ver=HTML / DOM Fingerprints
collect-reviews-reply-formdata-collect-reviews-ajax-urldata-collect-reviews-ajax-noncedata-collect-reviews-plugin-urldata-collect-reviews-optionsdata-collect-reviews-pagedata-collect-reviews-integrations+6 morecollect_reviews_admin