
EWZ-Rating Security & Risk Analysis
wordpress.org/plugins/ewz-ratingCompanion plugin to EntryWizard, for display and judging of the uploaded images.
Is EWZ-Rating Safe to Use in 2026?
Generally Safe
Score 100/100EWZ-Rating has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The ewz-rating plugin version 1.1.40 exhibits a mixed security posture. On the positive side, the plugin has no known vulnerabilities (CVEs) and demonstrates good practices in certain areas, such as utilizing prepared statements for the vast majority of its SQL queries and implementing a significant number of nonce checks and capability checks. The absence of external HTTP requests and bundled libraries also reduces certain attack vectors.
However, several concerning aspects were identified in the static analysis. The taint analysis revealed two flows with unsanitized paths, both categorized as high severity. This indicates a potential for attackers to manipulate input that could lead to unintended or malicious behavior, despite the limited number of total flows analyzed. Furthermore, a significant portion of the plugin's output (51%) is not properly escaped, posing a risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is displayed without adequate sanitization.
The plugin's vulnerability history is clean, which is a strong positive signal. It suggests that the developers may be diligent about security or that the plugin has not been a significant target. However, the presence of high-severity taint flows and unescaped output in the current version indicates that past good security practices might not have been consistently maintained or that new vulnerabilities have been introduced. Therefore, while the lack of known CVEs is encouraging, the identified code signals warrant attention and remediation.
Key Concerns
- High severity taint flows
- Significant unescaped output
EWZ-Rating Security Vulnerabilities
EWZ-Rating Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
EWZ-Rating Attack Surface
AJAX Handlers 20
Shortcodes 1
WordPress Hooks 29
Maintenance & Trust
EWZ-Rating Maintenance & Trust
Maintenance Signals
Community Trust
EWZ-Rating Alternatives
EntryWizard
entrywizard
Uploading by logged-in users of sets of image files and associated data. Administrators design the upload form, and download the images and data.
Auto Upload Images
auto-upload-images
Automatically detect external images in the post content and import images to your site then adding to the media library and replace image urls.
Clean Image Filenames
clean-image-filenames
This plugin automatically converts language accent characters to non-accent characters in filenames when uploading to the media library.
Disable "BIG Image" Threshold
disable-big-image-threshold
Disables the "BIG image" threshold introduced in WordPress 5.3.
Disable Media Sizes
disable-media-sizes
Provides options to disable the extra images generated by WordPress.
EWZ-Rating Developer Profile
2 plugins · 150 total installs
How We Detect EWZ-Rating
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ewz-rating/admin/css/ewz-rating-admin.css/wp-content/plugins/ewz-rating/css/ewz-rating.css/wp-content/plugins/ewz-rating/js/ewz-rating-public.js/wp-content/plugins/ewz-rating/js/ewz-rating-admin.js/wp-content/plugins/ewz-rating/admin/js/ewz-rating-admin-schemes.js/wp-content/plugins/ewz-rating/admin/js/ewz-rating-admin-forms.js/wp-content/plugins/ewz-rating/admin/js/ewz-rating-admin-help.jsHTML / DOM Fingerprints
ewz-rating-resultsewz-rating-title<!-- Rating Info Goes Here --><!-- Rating Form Goes Here --><!-- Rating Results Go Here --><!-- Rating Form Section -->+1 moredata-ewz-rating-iddata-ewz-rating-scheme-iddata-ewz-rating-item-iddata-ewz-rating-form-idewz_rating_vars[ewz_show_rating][ewz_rating_form]