
Custom Reviews Woocommerce Security & Risk Analysis
wordpress.org/plugins/custom-reviews-and-ratings-for-woocommerceYou can add custom reviews and ratings to your woocommerce products from wp admin dashboard.
Is Custom Reviews Woocommerce Safe to Use in 2026?
Generally Safe
Score 100/100Custom Reviews Woocommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The custom-reviews-and-ratings-for-woocommerce plugin version 1.0.0 exhibits a generally good security posture, with several positive indicators. The absence of known vulnerabilities, critical or high taint flows, and dangerous functions suggests a well-developed codebase. Furthermore, the presence of nonce and capability checks on its AJAX endpoint, along with the exclusive use of prepared statements for SQL queries, demonstrates an understanding of secure coding practices. File operations and external HTTP requests are also absent, reducing potential attack vectors.
However, a notable area of concern is the output escaping. With only 36% of outputs properly escaped, there is a significant risk of Cross-Site Scripting (XSS) vulnerabilities. While the static analysis did not report any direct XSS findings, the low percentage of proper escaping means that untrusted data could be rendered directly in the browser, potentially allowing attackers to inject malicious scripts. The single unprotected AJAX handler also presents a theoretical risk if it were to process sensitive data without proper authentication, though the analysis states it is protected.
In conclusion, the plugin's strength lies in its foundational security practices like secure SQL handling and proper authentication checks on entry points. The primary weakness, however, is the insufficient output escaping, which requires immediate attention to mitigate XSS risks. The lack of historical vulnerabilities is a positive sign, but the current static analysis results indicate that output sanitization should be prioritized.
Key Concerns
- Low percentage of properly escaped output
Custom Reviews Woocommerce Security Vulnerabilities
Custom Reviews Woocommerce Code Analysis
Output Escaping
Data Flow Analysis
Custom Reviews Woocommerce Attack Surface
AJAX Handlers 1
WordPress Hooks 2
Maintenance & Trust
Custom Reviews Woocommerce Maintenance & Trust
Maintenance Signals
Community Trust
Custom Reviews Woocommerce Alternatives
WPSSO Ratings and Reviews
wpsso-ratings-and-reviews
Adds Ratings and Reviews Features to the WordPress Comments System.
Breview – Order reviews for WooCommerce
breview
Collect reviews from order page after completion and display them on product pages on your WooCommerce store.
Kiyoh Reviews
kiyoh-reviews
Integrate Kiyoh reviews with your WooCommerce store. Automatically send review invitations and display product reviews.
Recotrust
recotrust-integration
By activating the plugin you enable the function to collect and visible customer reviews. This plugin requires an account on Recotrust.com
Mon Petit Avis
mon-petit-avis
Easily collect and display verified customer reviews after each WooCommerce sale with Mon Petit Avis, a French certified reviews platform.
Custom Reviews Woocommerce Developer Profile
1 plugin · 10 total installs
How We Detect Custom Reviews Woocommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-reviews-and-ratings-for-woocommerce/admin/custom_reviews.php/wp-content/plugins/custom-reviews-and-ratings-for-woocommerce/admin/reviewform.phpHTML / DOM Fingerprints
mw-crw_meta_box<!-- ... -->mw_noncemw_wc_ratingmw_wc_reviewmw_wc_review_datemw_product_idmw_custom_ratings_reviews_woocommerce_nonce+1 more