
Reviews Widgets for Google, Yelp & TripAdvisor Security & Risk Analysis
wordpress.org/plugins/fb-reviews-widgetCombine Facebook recommendations with Google, Yelp and TripAdvisor reviews in a widget, block or shortcode. Build a trusted website!
Is Reviews Widgets for Google, Yelp & TripAdvisor Safe to Use in 2026?
Generally Safe
Score 96/100Reviews Widgets for Google, Yelp & TripAdvisor has a strong security track record. Known vulnerabilities have been patched promptly.
The 'fb-reviews-widget' v2.7.3 plugin presents a mixed security posture. On the positive side, the static analysis shows no unprotected AJAX handlers or REST API routes, a decent number of capability checks and nonce checks, and a majority of SQL queries utilizing prepared statements. However, concerns arise from the 50% of outputs that are not properly escaped, indicating a potential for Cross-Site Scripting (XSS) vulnerabilities.
The taint analysis reveals four high-severity flows with unsanitized paths, which are significant risks. While no critical severity taint flows were found, these high-severity ones demand immediate attention as they can lead to serious security breaches. The plugin's vulnerability history, with two known CVEs, including a high and medium severity vulnerability, and past occurrences of XSS and Missing Authorization, reinforces the need for vigilance.
Despite strengths in some areas like the absence of unprotected entry points, the prevalent issue of unescaped output and the presence of high-severity taint flows are notable weaknesses. The historical pattern of XSS and authorization vulnerabilities suggests recurring coding flaws that need to be addressed comprehensively to improve the plugin's overall security. A balanced conclusion would be that while the plugin has some good security practices in place, the identified risks in output handling and taint flows, coupled with its vulnerability history, indicate areas that require urgent improvement.
Key Concerns
- High severity taint flows found
- Half of outputs not properly escaped (XSS risk)
- High severity CVE historically
- Medium severity CVE historically
- Vulnerability history includes XSS
- Vulnerability history includes Missing Authorization
Reviews Widgets for Google, Yelp & TripAdvisor Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Social Reviews & Recommendations <= 2.5 - Unauthenticated Stored Cross-Site Scripting via Social Media Reviews
Trust.Reviews <= 2.3 - Missing Authorization
Reviews Widgets for Google, Yelp & TripAdvisor Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Reviews Widgets for Google, Yelp & TripAdvisor Attack Surface
Shortcodes 1
WordPress Hooks 31
Maintenance & Trust
Reviews Widgets for Google, Yelp & TripAdvisor Maintenance & Trust
Maintenance Signals
Community Trust
Reviews Widgets for Google, Yelp & TripAdvisor Alternatives
Tagembed: Embed Twitter Feed, Google Reviews, YouTube Videos, TikTok, RSS Feed & More Social Media Feeds
tagembed-widget
Collect & Embed Instagram Feed, Embed Facebook Feed, Embed YouTube Videos, Embed Twitter Feed, Google Reviews & 15+ Social Media Feed on website.
Taggbox: Social Feed Widgets
taggbox-widget
Collect, Curate & Publish Instagram, Facebook Feeds, YouTube Videos, Twitter (X) Feeds, Google Reviews & 20+ Social Media Widgets on your website.
Review Map by RevuKangaroo
review-map-by-revukangaroo
Show off your customer's online reviews with Review Map by Revukangaroo.
Proton Reviews
proton-reviews
Proton Reviews is the Best Reviews Funnel for Google and Yelp
ReviewsTap
reviewstap
ReviewsTap helps small businesses collect, monitor and manage reviews across a range of online platforms.
Reviews Widgets for Google, Yelp & TripAdvisor Developer Profile
5 plugins · 114K total installs
How We Detect Reviews Widgets for Google, Yelp & TripAdvisor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/fb-reviews-widget/css/admin-main.css/wp-content/plugins/fb-reviews-widget/css/public-main.css/wp-content/plugins/fb-reviews-widget/js/admin-main.js/wp-content/plugins/fb-reviews-widget/js/admin-builder.js/wp-content/plugins/fb-reviews-widget/js/admin-apexcharts.js/wp-content/plugins/fb-reviews-widget/js/public-main.jshttps://cdn.reviewsplugin.com/assets/js/toast.jshttps://cdn.reviewsplugin.com/assets/js/time.jsfb-reviews-widget/css/admin-main.css?ver=fb-reviews-widget/css/public-main.css?ver=fb-reviews-widget/js/admin-main.js?ver=fb-reviews-widget/js/admin-builder.js?ver=fb-reviews-widget/js/admin-apexcharts.js?ver=fb-reviews-widget/js/public-main.js?ver=HTML / DOM Fingerprints
trustreviews-containerdata-trustreviews-widget-idTRUSTREVIEWS_VARS