
EC Stars Rating Security & Risk Analysis
wordpress.org/plugins/ec-stars-ratingA lightweigt, blazing fast star rating plugin for WordPress
Is EC Stars Rating Safe to Use in 2026?
Use With Caution
Score 63/100EC Stars Rating has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "ec-stars-rating" plugin v1.0.11 presents a mixed security posture. While it demonstrates good practices in its handling of SQL queries, utilizing prepared statements exclusively, and avoiding file operations and external HTTP requests, significant concerns arise from its attack surface and code analysis. The presence of two unprotected AJAX handlers represents a considerable risk, as these are direct entry points that could be exploited without proper authentication. Furthermore, the taint analysis reveals two flows with unsanitized paths, both flagged as high severity, indicating potential vulnerabilities where user-controlled input could lead to unintended consequences.
The plugin's vulnerability history is also a point of concern. It has a known medium severity CVE that is currently unpatched, dating from June 2025. The common vulnerability type being Cross-site Scripting (XSS) and the fact that a medium-severity vulnerability remains unaddressed suggest a pattern of neglecting security updates or potentially a lack of rigorous security testing before releases.
In conclusion, the plugin exhibits strengths in database interaction and operational security, but the unprotected entry points, high-severity taint flows, and the unpatched historical vulnerability significantly detract from its overall security. Organizations using this plugin should be aware of the potential for XSS and unauthorized actions via its AJAX endpoints and prioritize updating to a version that addresses the known CVE.
Key Concerns
- Unprotected AJAX handlers
- High severity unsanitized taint flows
- Unpatched medium CVE
- Low percentage of properly escaped output
- Missing nonce checks on AJAX
- Missing capability checks
EC Stars Rating Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
EC Stars Rating <= 1.0.11 - Authenticated (Administrator+) Stored Cross-Site Scripting
EC Stars Rating Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
EC Stars Rating Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
EC Stars Rating Maintenance & Trust
Maintenance Signals
Community Trust
EC Stars Rating Alternatives
GD Rating System
gd-rating-system
Powerful, highly customizable and versatile ratings plugin to allow your users to vote for anything you want.
REVIEWS.io for WooCommerce
reviewscouk-for-woocommerce
REVIEWS.io, helps eCommerce merchants to collect & display verified product and company reviews. A Google Licensed partner.
Stars Rating
stars-rating
A plugin to turn comments into reviews by adding rating feature.
Five-Star Ratings Shortcode
five-star-ratings-shortcode
Simple lightweight shortcode to add 5-star ratings anywhere.
Rating by BestWebSoft
rating-bws
Add rating plugin to your WordPress website to receive feedback from your customers.
EC Stars Rating Developer Profile
1 plugin · 400 total installs
How We Detect EC Stars Rating
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ec-stars-rating/js/ec-stars-rating.js/wp-content/plugins/ec-stars-rating/js/ec-stars-rating-nojq.js/wp-content/plugins/ec-stars-rating/js/ec-stars-rating.js/wp-content/plugins/ec-stars-rating/js/ec-stars-rating-nojq.jsec-stars-rating/js/ec-stars-rating.js?ver=ec-stars-rating/js/ec-stars-rating-nojq.js?ver=HTML / DOM Fingerprints
ec-stars-wrapperec-stars-overlaydata-tooltipec_ajax_data[ec_stars_rating]