
Customer Reviews for WooCommerce Security & Risk Analysis
wordpress.org/plugins/customer-reviews-for-woocommerceLooking to boost your WooCommerce sales? Using the WooCommerce customer reviews widget, you can! Collect more reviews and build brand loyalty with thi …
Is Customer Reviews for WooCommerce Safe to Use in 2026?
Generally Safe
Score 85/100Customer Reviews for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "customer-reviews-for-woocommerce" v3.2.1 presents a moderate security risk. While it has no known historical CVEs, indicating a generally stable past, the static analysis reveals significant concerns regarding its attack surface and code quality. The presence of two unprotected REST API routes is a major red flag, creating direct entry points for potential attackers. Furthermore, the use of the `unserialize` function without apparent sanitization or validation for its input is a critical vulnerability that could lead to remote code execution. The high number of unsanitized paths identified in the taint analysis also points to potential cross-site scripting (XSS) or other injection vulnerabilities. The low percentage of properly escaped output and the significant portion of SQL queries not using prepared statements further contribute to the risk profile, increasing the likelihood of injection attacks.
Key Concerns
- REST API routes without permission callbacks
- Dangerous function: unserialize
- High severity taint flows
- Low percentage of properly escaped output
- Low percentage of SQL queries using prepared statements
Customer Reviews for WooCommerce Security Vulnerabilities
Customer Reviews for WooCommerce Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Customer Reviews for WooCommerce Attack Surface
REST API Routes 2
WordPress Hooks 14
Maintenance & Trust
Customer Reviews for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Customer Reviews for WooCommerce Alternatives
Customer Reviews for WooCommerce
customer-reviews-woocommerce
Customer Reviews for WooCommerce plugin helps you get more sales with social proof. Set up automated review reminders and increase conversion rate.
WiserReview Product Reviews for WooCommerce
wiser-review
Collect, manage, and display powerful product reviews and testimonials for WooCommerce stores. Boost trust and conversion with automated review collec …
PiWeb Customer review / Product review for WooCommerce
product-review-for-woocommerce
Send a reminder email to customers for WooCommerce product reviews. You can send manual reminders or configure the plugin to send automatic review rem …
Photo Reviews for WooCommerce
woo-photo-reviews
Let customers attach photos to reviews, enhanced with filterable grids and overall ratings. Auto-send review reminders and coupon emails
ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema
reviewx
Drive woocommerce business growth with social proof: gather product reviews with multicriteria ratings, auto-reminder emails, discounts, and more.
Customer Reviews for WooCommerce Developer Profile
32 plugins · 976K total installs
How We Detect Customer Reviews for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/customer-reviews-for-woocommerce/assets/css/style.css/wp-content/plugins/customer-reviews-for-woocommerce/assets/js/frontend.js/wp-content/plugins/customer-reviews-for-woocommerce/assets/css/frontend.css/wp-content/plugins/customer-reviews-for-woocommerce/assets/js/main.jscustomer-reviews-for-woocommerce/assets/css/style.css?ver=customer-reviews-for-woocommerce/assets/js/frontend.js?ver=customer-reviews-for-woocommerce/assets/css/frontend.css?ver=customer-reviews-for-woocommerce/assets/js/main.js?ver=HTML / DOM Fingerprints
ti-boxti-rowti-col-6ti-checkti-noticeti-headerti-my-reviewsti-widget+3 moreNo script kiddies please!src='https://cdn.trustindex.io/loader.js?76afafc10ad42261d7587d98bf'data-idTrustindexWoocommercePlugin<div src='https://cdn.trustindex.io/loader.js?76afafc10ad42261d7587d98bf'></div>