
Feefo Ratings & Reviews for WooCommerce Security & Risk Analysis
wordpress.org/plugins/feefo-ratings-reviews-for-woocommerceGather trusted ratings and reviews from your customers with the award winning closed-feedback platform Feefo and hear the real voice of your customer.
Is Feefo Ratings & Reviews for WooCommerce Safe to Use in 2026?
Generally Safe
Score 92/100Feefo Ratings & Reviews for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "feefo-ratings-reviews-for-woocommerce" v1.0.16 exhibits a mixed security posture. On the positive side, the static analysis reveals no critical security vulnerabilities identified through taint analysis, a clean vulnerability history with no known CVEs, and a relatively small attack surface in terms of exposed entry points (AJAX, REST API, shortcodes, cron events). The presence of nonce and capability checks also indicates some effort towards securing operations.
However, significant concerns arise from the SQL query handling and output escaping. All SQL queries are not using prepared statements, which can lead to SQL injection vulnerabilities if user-supplied data is not meticulously sanitized before being passed to these queries. Furthermore, a substantial portion of output (100%) is not properly escaped, presenting a high risk of Cross-Site Scripting (XSS) vulnerabilities. This lack of output escaping is a critical weakness, as it allows attackers to inject malicious scripts into web pages viewed by other users.
While the absence of past vulnerabilities and a clean taint analysis are reassuring, the current code analysis reveals fundamental security flaws in data handling. The strength lies in the limited attack surface and the presence of some basic security checks. The weakness, however, is profound, with unescaped output and raw SQL queries posing immediate and severe risks to the security of any WordPress site using this plugin. Mitigation of these risks should be a priority.
Key Concerns
- SQL queries do not use prepared statements
- No output properly escaped
Feefo Ratings & Reviews for WooCommerce Security Vulnerabilities
Feefo Ratings & Reviews for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Feefo Ratings & Reviews for WooCommerce Attack Surface
WordPress Hooks 7
Maintenance & Trust
Feefo Ratings & Reviews for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Feefo Ratings & Reviews for WooCommerce Alternatives
Site Reviews
site-reviews
Site Reviews is a complete review management solution that integrates with WooCommerce and SureCart and works similarly to reviews on Amazon, Tripadvi …
Photo Reviews for WooCommerce
woo-photo-reviews
Let customers attach photos to reviews, enhanced with filterable grids and overall ratings. Auto-send review reminders and coupon emails
ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema
reviewx
Drive woocommerce business growth with social proof: gather product reviews with multicriteria ratings, auto-reminder emails, discounts, and more.
Yotpo: Product & Photo Reviews for WooCommerce
yotpo-social-reviews-for-woocommerce
Collect product reviews, photo reviews, site reviews & ratings
Gutena Star Ratings
gutena-star-ratings
Gutena Star Ratings is a great block that lets you add star rating to client testimonials and reviews. Not only the star rating will tell customers ho …
Feefo Ratings & Reviews for WooCommerce Developer Profile
1 plugin · 300 total installs
How We Detect Feefo Ratings & Reviews for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/feefo-ratings-reviews-for-woocommerce/assets/css/side-menu-logo.css/wp-content/plugins/feefo-ratings-reviews-for-woocommerce/assets/css/iframe-display.css/wp-content/plugins/feefo-ratings-reviews-for-woocommerce/assets/css/start-plugin-setup-display.cssHTML / DOM Fingerprints
plugin-setup-divplugin-setup-h1plugin-setup-aid="plugin-setup-div"id="plugin-setup-h1"id="plugin-setup-a"/ecommerce/plugin/woocommerce/register/callback