
Custom Review Security & Risk Analysis
wordpress.org/plugins/custom-reviewThis plugin gives functionality to gain more and more reviews on woocommerce stores products to the Store owners.
Is Custom Review Safe to Use in 2026?
Generally Safe
Score 85/100Custom Review has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "custom-review" plugin v1.0.0 exhibits a concerning security posture despite a clean vulnerability history. The static analysis reveals a significant attack surface with four AJAX handlers, all of which lack authentication checks. This means any unauthenticated user can trigger these functions, potentially leading to unintended actions or information disclosure depending on their implementation.
While the plugin demonstrates good practices in other areas, such as 100% proper output escaping and the absence of dangerous functions or raw SQL queries, the unprotected AJAX endpoints represent a critical weakness. The lack of nonce checks further exacerbates this issue, making the plugin vulnerable to Cross-Site Request Forgery (CSRF) attacks. The positive aspect is the absence of any known vulnerabilities or critical taint flows, suggesting that the core logic might be sound, but the exposed entry points are a serious oversight.
In conclusion, the plugin's strength lies in its secure handling of output and SQL. However, the unprotected AJAX endpoints are a major security flaw that requires immediate attention. Without these checks, the plugin is highly susceptible to exploitation by unauthenticated attackers. The clean vulnerability history is a good sign, but it doesn't mitigate the risks posed by the identified vulnerabilities in the current version.
Key Concerns
- AJAX handlers without auth checks
- AJAX handlers without nonce checks
Custom Review Security Vulnerabilities
Custom Review Release Timeline
Custom Review Code Analysis
Output Escaping
Data Flow Analysis
Custom Review Attack Surface
AJAX Handlers 4
WordPress Hooks 12
Maintenance & Trust
Custom Review Maintenance & Trust
Maintenance Signals
Community Trust
Custom Review Alternatives
Site Reviews
site-reviews
Site Reviews is a complete review management solution that integrates with WooCommerce and SureCart and works similarly to reviews on Amazon, Tripadvi …
Photo Reviews for WooCommerce
woo-photo-reviews
Let customers attach photos to reviews, enhanced with filterable grids and overall ratings. Auto-send review reminders and coupon emails
ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema
reviewx
Drive woocommerce business growth with social proof: gather product reviews with multicriteria ratings, auto-reminder emails, discounts, and more.
Yotpo: Product & Photo Reviews for WooCommerce
yotpo-social-reviews-for-woocommerce
Collect product reviews, photo reviews, site reviews & ratings
Gutena Star Ratings
gutena-star-ratings
Gutena Star Ratings is a great block that lets you add star rating to client testimonials and reviews. Not only the star rating will tell customers ho …
Custom Review Developer Profile
7 plugins · 30 total installs
How We Detect Custom Review
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-review/admin/css/zwk_custom_review-admin.css/wp-content/plugins/custom-review/admin/css/select.css/wp-content/plugins/custom-review/admin/js/zwk_custom_review-admin.js/wp-content/plugins/custom-review/admin/js/select.jshttps://maxcdn.bootstrapcdn.com/font-awesome/4.2.0/css/font-awesome.min.csszwk_custom_review-admin.css?ver=zwk_custom_review-admin.js?ver=HTML / DOM Fingerprints
data-comment_idzwk_custom_review_admin_object/wp-json/zwk_custom_review/v1/review