
Critique Security & Risk Analysis
wordpress.org/plugins/critiqueA WordPress plugin for making either single score or multiple break down reviews on posts and/or pages.
Is Critique Safe to Use in 2026?
Generally Safe
Score 92/100Critique has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "critique" plugin v1.4.4 demonstrates a strong security posture in several key areas. The static analysis reveals a very small attack surface with no identified unprotected entry points. The code signals are also very positive, with 100% of SQL queries using prepared statements, a high percentage of properly escaped output, and the presence of nonce and capability checks. The absence of dangerous functions, file operations, and external HTTP requests further contributes to its security. The vulnerability history is also excellent, with no recorded CVEs, suggesting a history of secure development or diligent patching by the developers.
However, a concerning finding in the taint analysis is the presence of 2 flows with unsanitized paths. While these did not escalate to critical or high severity, unsanitized paths represent potential vulnerabilities if they were to be exploited in conjunction with other weaknesses or if the severity assessment of these flows is underestimated. This is the primary area of concern despite the otherwise robust security practices observed in the static analysis and vulnerability history. The plugin's strengths lie in its minimal attack surface and good core security practices, but the unsanitized path flows warrant careful monitoring and potential future review.
In conclusion, "critique" v1.4.4 is generally well-secured with diligent coding practices evident. The lack of known vulnerabilities and the minimal attack surface are significant strengths. The only notable weakness is the presence of two flows with unsanitized paths, which, while not currently critical, represent a potential risk that should not be ignored. Users should remain vigilant for any future updates addressing this specific finding.
Key Concerns
- Flows with unsanitized paths
Critique Security Vulnerabilities
Critique Code Analysis
Output Escaping
Data Flow Analysis
Critique Attack Surface
Shortcodes 1
WordPress Hooks 8
Maintenance & Trust
Critique Maintenance & Trust
Maintenance Signals
Community Trust
Critique Alternatives
Widgets for Google Reviews
wp-reviews-plugin-for-google
Embed Google reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Google reviews.
Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More
reviews-feed
No API key required. Display Yelp and Google reviews for any business in a clean, customizable feed on your site.
Rich Showcase for Google Reviews
widget-google-reviews
Display up to 10 Google reviews in less than a minute. Continue collecting new reviews. No limits on connected places, widgets, shortcodes and blocks.
Customer Reviews for WooCommerce
customer-reviews-woocommerce
Customer Reviews for WooCommerce plugin helps you get more sales with social proof. Set up automated review reminders and increase conversion rate.
Site Reviews
site-reviews
Site Reviews is a complete review management solution that integrates with WooCommerce and SureCart and works similarly to reviews on Amazon, Tripadvi …
Critique Developer Profile
3 plugins · 630 total installs
How We Detect Critique
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/critique/fontello/css/critique.css/wp-content/plugins/critique/admin.css/wp-content/plugins/critique/admin.js/wp-content/plugins/critique/critique.css/wp-content/plugins/critique/admin.jscritique/fontello/css/critique.css?ver=critique/admin.css?ver=critique/admin.js?ver=critique/fontello/css/critique.css?ver=critique/critique.css?ver=HTML / DOM Fingerprints
critique-review-inputscritique-metabox-scalecritique-admin-star-containercritique-average-calculationcritique-score-output-sectioncritique-score-overalldata-critique-scale[critique_score]