elpix Rate Post in Comment Security & Risk Analysis

wordpress.org/plugins/elpix-rate-post-in-comment

Star rating for posts and pages integrated in comment-functionality of wordpress.

10 active installs v1.1.0.1 PHP + WP 3.0.1+ Updated Jan 28, 2014
commentspostratingstarstar-rating
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is elpix Rate Post in Comment Safe to Use in 2026?

Generally Safe

Score 85/100

elpix Rate Post in Comment has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The 'elpix-rate-post-in-comment' plugin version 1.1.0.1 exhibits a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, performing all SQL queries using prepared statements, and including a nonce check. The absence of known CVEs and a history of past vulnerabilities also suggests a potentially stable and well-maintained codebase. However, there are significant concerns regarding output escaping, with 100% of outputs not being properly escaped. This presents a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data could be injected into the page and executed by other users' browsers.

While the static analysis shows no critical or high-severity taint flows and a small attack surface with no immediately apparent unprotected entry points, the lack of output escaping is a critical oversight. The plugin's vulnerability history is clean, which is a positive indicator, but it does not mitigate the identified risk of XSS. The overall risk is elevated due to the high likelihood of XSS due to unescaped output, despite the plugin's other seemingly secure attributes. Addressing the output escaping is paramount to improving the plugin's security.

Key Concerns

  • Output escaping issues
Vulnerabilities
None known

elpix Rate Post in Comment Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

elpix Rate Post in Comment Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
0 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped3 total outputs
Attack Surface

elpix Rate Post in Comment Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[elpix_average_rating] elpix-rate-post-in-comment.php:103
WordPress Hooks 10
actionplugins_loadedelpix-rate-post-in-comment.php:33
actionwp_enqueue_scriptselpix-rate-post-in-comment.php:45
actionadmin_initelpix-rate-post-in-comment.php:59
actioncomment_form_logged_in_afterelpix-rate-post-in-comment.php:75
actioncomment_form_after_fieldselpix-rate-post-in-comment.php:77
actioncomment_postelpix-rate-post-in-comment.php:157
filterpreprocess_commentelpix-rate-post-in-comment.php:172
filtercomment_textelpix-rate-post-in-comment.php:188
actionadd_meta_boxes_commentelpix-rate-post-in-comment.php:215
actionedit_commentelpix-rate-post-in-comment.php:251
Maintenance & Trust

elpix Rate Post in Comment Maintenance & Trust

Maintenance Signals

WordPress version tested3.7.41
Last updatedJan 28, 2014
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

elpix Rate Post in Comment Developer Profile

elpix-GmbH

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect elpix Rate Post in Comment

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/elpix-rate-post-in-comment/elpix-rate-post.css/wp-content/plugins/elpix-rate-post-in-comment/elpix-rate-post.js
Script Paths
/wp-content/plugins/elpix-rate-post-in-comment/elpix-rate-post.js
Version Parameters
elpix-rate-post-in-comment/elpix-rate-post.css?ver=elpix-rate-post-in-comment/elpix-rate-post.js?ver=

HTML / DOM Fingerprints

CSS Classes
comment-form-ratingcomment-rating-boxstar_linkstar_setstar_not_setcommentratingboxcommentrating
Data Attributes
id="elpix-post-rating"name="elpix-post-rating"id="elpix-post-rating"name="elpix-post-rating"id="elpix-post-rating"name="elpix-post-rating"
Shortcode Output
<p class="comment-rating"><span class="star_set" ></span><span class="star_not_set" ></span>
FAQ

Frequently Asked Questions about elpix Rate Post in Comment