
Customer Reviews Collector for WooCommerce Security & Risk Analysis
wordpress.org/plugins/customer-reviews-collector-for-woocommerceCollect reviews on Google, Facebook, Yelp, Trustindex and other platforms automatically, with the help of our system.
Is Customer Reviews Collector for WooCommerce Safe to Use in 2026?
Generally Safe
Score 99/100Customer Reviews Collector for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.
The "customer-reviews-collector-for-woocommerce" plugin version 4.7.3 exhibits a generally good security posture with a strong adherence to best practices like prepared statements for SQL queries and proper output escaping. The plugin's attack surface appears to be minimal, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events that lack authentication or permission checks. The presence of a capability check and nonce checks further strengthens its defenses against common web vulnerabilities.
However, the static analysis did reveal some areas of concern. Specifically, there are a significant number of "flows with unsanitized paths" (6 out of 9 analyzed), with four of these identified as "High severity" taint flows. While the plugin doesn't appear to have any directly exploitable critical or high severity vulnerabilities in its code based on this snapshot, these unsanitized paths indicate potential pathways where malicious input could be processed insecurely, possibly leading to unexpected behavior or further exploitation if combined with other factors. The vulnerability history shows one medium severity CVE related to Cross-Site Scripting, which is concerning as it points to past weaknesses in input sanitization or output escaping, even though it's currently patched.
In conclusion, while the plugin demonstrates good fundamental security practices, the high number of unsanitized paths with high severity taint flows is a notable weakness. This suggests a need for more thorough input validation and sanitization to mitigate potential risks, especially considering the past XSS vulnerability. Addressing these taint flows should be a priority to further harden the plugin's security.
Key Concerns
- High severity taint flows found
- Flows with unsanitized paths
- Medium severity CVE in history
Customer Reviews Collector for WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Customer Reviews Collector for WooCommerce <= 4.6.1 - Reflected Cross-Site Scripting
Customer Reviews Collector for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Customer Reviews Collector for WooCommerce Attack Surface
WordPress Hooks 12
Maintenance & Trust
Customer Reviews Collector for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Customer Reviews Collector for WooCommerce Alternatives
ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema
reviewx
Drive woocommerce business growth with social proof: gather product reviews with multicriteria ratings, auto-reminder emails, discounts, and more.
Builder for WooCommerce product reviews shortcodes – ReviewShort
woo-product-reviews-shortcode
Show WooCommerce customer feedback anywhere with WooCommerce reviews shortcodes, beautifully and ...
Collect Reviews
collect-reviews
The ultimate WordPress plugin for automatically collecting reviews on any platform like Google or Facebook.
Reviews for WooCommerce
reviews-for-woocommerce
This plugin provides different template to show WooCommerce reviews of any product.
Customer Reviews for WooCommerce
customer-reviews-woocommerce
Customer Reviews for WooCommerce plugin helps you get more sales with social proof. Set up automated review reminders and increase conversion rate.
Customer Reviews Collector for WooCommerce Developer Profile
32 plugins · 976K total installs
How We Detect Customer Reviews Collector for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/customer-reviews-collector-for-woocommerce/trustindex-collector-plugin.css/wp-content/plugins/customer-reviews-collector-for-woocommerce/trustindex-collector-plugin.js/wp-content/plugins/customer-reviews-collector-for-woocommerce/trustindex-collector-plugin.jscustomer-reviews-collector-for-woocommerce/trustindex-collector-plugin.css?ver=customer-reviews-collector-for-woocommerce/trustindex-collector-plugin.js?ver=HTML / DOM Fingerprints
trustindex-review-widgetti-widget-wrapperti-reviews-containerti-widget-star-ratingtrustindex-col-wrapperCopyright 2019 Trustindex Kft (email: support@trustindex.io)No script kiddies please!data-ti-widget-iddata-ti-platform-urltrustindex_collector