Customer Reviews Collector for WooCommerce Security & Risk Analysis

wordpress.org/plugins/customer-reviews-collector-for-woocommerce

Collect reviews on Google, Facebook, Yelp, Trustindex and other platforms automatically, with the help of our system.

5K active installs v4.7.3 PHP 7.0+ WP 6.2+ Updated Feb 2, 2026
collectcustomer-reviewsgoogle-reviewsreview-pluginwoocommerce-reviews
99
A · Safe
CVEs total1
Unpatched0
Last CVENov 26, 2025
Safety Verdict

Is Customer Reviews Collector for WooCommerce Safe to Use in 2026?

Generally Safe

Score 99/100

Customer Reviews Collector for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Nov 26, 2025Updated 2mo ago
Risk Assessment

The "customer-reviews-collector-for-woocommerce" plugin version 4.7.3 exhibits a generally good security posture with a strong adherence to best practices like prepared statements for SQL queries and proper output escaping. The plugin's attack surface appears to be minimal, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events that lack authentication or permission checks. The presence of a capability check and nonce checks further strengthens its defenses against common web vulnerabilities.

However, the static analysis did reveal some areas of concern. Specifically, there are a significant number of "flows with unsanitized paths" (6 out of 9 analyzed), with four of these identified as "High severity" taint flows. While the plugin doesn't appear to have any directly exploitable critical or high severity vulnerabilities in its code based on this snapshot, these unsanitized paths indicate potential pathways where malicious input could be processed insecurely, possibly leading to unexpected behavior or further exploitation if combined with other factors. The vulnerability history shows one medium severity CVE related to Cross-Site Scripting, which is concerning as it points to past weaknesses in input sanitization or output escaping, even though it's currently patched.

In conclusion, while the plugin demonstrates good fundamental security practices, the high number of unsanitized paths with high severity taint flows is a notable weakness. This suggests a need for more thorough input validation and sanitization to mitigate potential risks, especially considering the past XSS vulnerability. Addressing these taint flows should be a priority to further harden the plugin's security.

Key Concerns

  • High severity taint flows found
  • Flows with unsanitized paths
  • Medium severity CVE in history
Vulnerabilities
1

Customer Reviews Collector for WooCommerce Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-12123medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Customer Reviews Collector for WooCommerce <= 4.6.1 - Reflected Cross-Site Scripting

Nov 26, 2025 Patched in 4.7 (1d)
Code Analysis
Analyzed Mar 16, 2026

Customer Reviews Collector for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
58 prepared
Unescaped Output
4
599 escaped
Nonce Checks
14
Capability Checks
1
File Operations
1
External Requests
3
Bundled Libraries
0

SQL Query Safety

98% prepared59 total queries

Output Escaping

99% escaped603 total outputs
Data Flows
6 unsanitized

Data Flow Analysis

9 flows6 with unsanitized paths
<settings> (tabs\settings.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Customer Reviews Collector for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actionplugins_loadedcustomer-reviews-collector-for-woocommerce.php:31
actionwoocommerce_order_status_changedcustomer-reviews-collector-for-woocommerce.php:32
actionwp_loadedcustomer-reviews-collector-for-woocommerce.php:83
actioninitcustomer-reviews-collector-for-woocommerce.php:131
actionadmin_menucustomer-reviews-collector-for-woocommerce.php:132
filterplugin_action_linkscustomer-reviews-collector-for-woocommerce.php:133
filterplugin_row_metacustomer-reviews-collector-for-woocommerce.php:134
actioninitcustomer-reviews-collector-for-woocommerce.php:135
actionadmin_enqueue_scriptscustomer-reviews-collector-for-woocommerce.php:136
actionparse_requestcustomer-reviews-collector-for-woocommerce.php:150
actionadmin_noticescustomer-reviews-collector-for-woocommerce.php:259
actionhttp_api_curltrustindex-collector-plugin.class.php:105
Maintenance & Trust

Customer Reviews Collector for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 2, 2026
PHP min version7.0
Downloads102K

Community Trust

Rating96/100
Number of ratings22
Active installs5K
Developer Profile

Customer Reviews Collector for WooCommerce Developer Profile

Trustindex

32 plugins · 976K total installs

87
trust score
Avg Security Score
99/100
Avg Patch Time
87 days
View full developer profile
Detection Fingerprints

How We Detect Customer Reviews Collector for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/customer-reviews-collector-for-woocommerce/trustindex-collector-plugin.css/wp-content/plugins/customer-reviews-collector-for-woocommerce/trustindex-collector-plugin.js
Script Paths
/wp-content/plugins/customer-reviews-collector-for-woocommerce/trustindex-collector-plugin.js
Version Parameters
customer-reviews-collector-for-woocommerce/trustindex-collector-plugin.css?ver=customer-reviews-collector-for-woocommerce/trustindex-collector-plugin.js?ver=

HTML / DOM Fingerprints

CSS Classes
trustindex-review-widgetti-widget-wrapperti-reviews-containerti-widget-star-ratingtrustindex-col-wrapper
HTML Comments
Copyright 2019 Trustindex Kft (email: support@trustindex.io)No script kiddies please!
Data Attributes
data-ti-widget-iddata-ti-platform-url
JS Globals
trustindex_collector
FAQ

Frequently Asked Questions about Customer Reviews Collector for WooCommerce