
Editorial Rating – Product Review & Rating System Security & Risk Analysis
wordpress.org/plugins/editorial-ratingAdd multi-criteria product reviews and star ratings to WordPress posts. Boost engagement, SEO, and sales with editorial ratings.
Is Editorial Rating – Product Review & Rating System Safe to Use in 2026?
Generally Safe
Score 100/100Editorial Rating – Product Review & Rating System has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "editorial-rating" v4.0.3 plugin exhibits a generally good security posture with several positive indicators. The complete absence of known CVEs and the use of prepared statements for all SQL queries are strong points. Furthermore, the plugin demonstrates a good level of output escaping, with 70% of outputs being properly handled, and all identified SQL queries are secured. The presence of nonce checks for all identified AJAX handlers is also a positive sign.
However, there are a few areas of concern. The presence of four AJAX handlers without authentication checks represents a significant attack surface that could be exploited by unauthorized users. While taint analysis did not reveal critical or high severity issues, the existence of four flows with unsanitized paths warrants attention, as these could potentially lead to vulnerabilities if not handled carefully in future updates. The plugin also has a moderate attack surface with 16 entry points, four of which are unprotected.
Overall, the plugin is in a reasonably secure state, especially considering its lack of historical vulnerabilities. The main risks lie in the unprotected AJAX handlers and the unsanitized taint flows, which, while not currently exploited, represent potential weaknesses. Addressing these specific issues would further solidify the plugin's security.
Key Concerns
- AJAX handlers without authentication checks
- Flows with unsanitized paths
Editorial Rating – Product Review & Rating System Security Vulnerabilities
Editorial Rating – Product Review & Rating System Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Editorial Rating – Product Review & Rating System Attack Surface
AJAX Handlers 14
Shortcodes 2
WordPress Hooks 88
Maintenance & Trust
Editorial Rating – Product Review & Rating System Maintenance & Trust
Maintenance Signals
Community Trust
Editorial Rating – Product Review & Rating System Alternatives
WPSSO Ratings and Reviews
wpsso-ratings-and-reviews
Adds Ratings and Reviews Features to the WordPress Comments System.
Review & Product Review by Review Builder
review-builder
Review & Product Review by Review Builder plugin allows you to build a review and star rating section so customers can leave a review for your pro …
Strong Testimonials
strong-testimonials
An easy-to-use testimonial plugin to collect and show customer feedback in WordPress
kk Star Ratings – Rate Post & Collect User Feedbacks
kk-star-ratings
kk Star Ratings allows blog visitors to involve and interact more effectively with your website by rating posts.
Site Reviews
site-reviews
Site Reviews is a complete review management solution that integrates with WooCommerce and SureCart and works similarly to reviews on Amazon, Tripadvi …
Editorial Rating – Product Review & Rating System Developer Profile
7 plugins · 3K total installs
How We Detect Editorial Rating – Product Review & Rating System
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/editorial-rating/public/css/editorial-rating-public.css/wp-content/plugins/editorial-rating/public/js/editorial-rating-public.js/wp-content/plugins/editorial-rating/admin/css/average-score-admin.css/wp-content/plugins/editorial-rating/admin/js/average-score-admin.js/wp-content/plugins/editorial-rating/public/js/editorial-rating-public.js/wp-content/plugins/editorial-rating/admin/js/average-score-admin.jseditorial-rating/public/css/editorial-rating-public.css?ver=editorial-rating/public/js/editorial-rating-public.js?ver=editorial-rating/admin/css/average-score-admin.css?ver=editorial-rating/admin/js/average-score-admin.js?ver=HTML / DOM Fingerprints
wpas-rating-wrappereditorial-rating-scoreeditorial-rating-pros-conseditorial-rating-sidebar-sticky<!-- Editorial Rating Plugin --><!-- END Editorial Rating Plugin -->data-wpas-rating-iddata-wpas-rating-scoreeditorialRatingPublic/wp-json/editorial-rating/v1/settings/wp-json/editorial-rating/v1/rate[editorial_rating_display][editorial_rating_pros_cons][editorial_rating_sidebar]