Featured Reviews for Woocommerce Security & Risk Analysis

wordpress.org/plugins/ecommerce-featured-reviews

This plugin will helps to change review order, You can easily move any review to top or bottom, for that you have to setup order number in reviews.

0 active installs v1.1 PHP 5.7+ WP 3.6+ Updated Nov 30, 2019
comments-order-setupfeatured-reviews-for-woocommercepriority-reviewsreview-orderreviews-rearrange
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Featured Reviews for Woocommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Featured Reviews for Woocommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The ecommerce-featured-reviews plugin version 1.1 exhibits a strong security posture based on the provided static analysis. The absence of any detected AJAX handlers, REST API routes, shortcodes, or cron events with exploitable attack surfaces significantly reduces the potential for direct malicious access. Furthermore, the code demonstrates good practices by using prepared statements for all SQL queries and includes nonce checks and capability checks, which are crucial for preventing common attack vectors.

While the static analysis reveals a clean code base with no dangerous functions, file operations, or external HTTP requests, a notable concern arises from the output escaping. With only 17% of outputs being properly escaped, there is a significant risk of Cross-Site Scripting (XSS) vulnerabilities. This means user-supplied data, if not handled carefully in the remaining 83% of outputs, could be injected and executed in a user's browser, potentially leading to session hijacking or other malicious actions. The lack of any recorded vulnerabilities in its history is a positive indicator, suggesting a generally well-maintained codebase, but this should not overshadow the identified output escaping weakness.

In conclusion, the plugin's strengths lie in its limited attack surface and secure handling of database operations and authentication mechanisms. However, the widespread lack of output escaping presents a substantial risk that needs to be addressed promptly. The absence of past vulnerabilities is encouraging but does not mitigate the current potential for XSS attacks. Addressing the output escaping issue should be the highest priority.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

Featured Reviews for Woocommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Featured Reviews for Woocommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
1 escaped
Nonce Checks
1
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

17% escaped6 total outputs
Attack Surface

Featured Reviews for Woocommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionedit_commentfeatured-reviews-for-woocommerce.php:38
actionadmin_menufeatured-reviews-for-woocommerce.php:39
filtercomment_textfeatured-reviews-for-woocommerce.php:40
filtercomment_row_actionsfeatured-reviews-for-woocommerce.php:41
actionadmin_print_scriptsfeatured-reviews-for-woocommerce.php:42
filtercomment_classfeatured-reviews-for-woocommerce.php:45
actionwp_enqueue_scriptsfeatured-reviews-for-woocommerce.php:46
Maintenance & Trust

Featured Reviews for Woocommerce Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedNov 30, 2019
PHP min version5.7
Downloads1K

Community Trust

Rating100/100
Number of ratings2
Active installs0
Alternatives

Featured Reviews for Woocommerce Alternatives

No alternatives data available yet.

Developer Profile

Featured Reviews for Woocommerce Developer Profile

Karam Singh

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Featured Reviews for Woocommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ecommerce-featured-reviews/style.css/wp-content/plugins/ecommerce-featured-reviews/front.js/wp-content/plugins/ecommerce-featured-reviews/app.js
Version Parameters
ecommerce-featured-reviews/style.css?ver=ecommerce-featured-reviews/front.js?ver=ecommerce-featured-reviews/app.js?ver=

HTML / DOM Fingerprints

CSS Classes
featuredorder_commento-
Data Attributes
data-comment_id
JS Globals
woocommerce_reviews
FAQ

Frequently Asked Questions about Featured Reviews for Woocommerce