Feefo Ratings & Reviews for WooCommerce Security & Risk Analysis

wordpress.org/plugins/feefo-ratings-reviews-for-woocommerce

Gather trusted ratings and reviews from your customers with the award winning closed-feedback platform Feefo and hear the real voice of your customer.

300 active installs v1.0.16 PHP + WP 4.1+ Updated Nov 22, 2024
feefogoogle-product-listing-adsonline-reviewsproduct-reviewsreviews
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Feefo Ratings & Reviews for WooCommerce Safe to Use in 2026?

Generally Safe

Score 92/100

Feefo Ratings & Reviews for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The plugin "feefo-ratings-reviews-for-woocommerce" v1.0.16 exhibits a mixed security posture. On the positive side, the static analysis reveals no critical security vulnerabilities identified through taint analysis, a clean vulnerability history with no known CVEs, and a relatively small attack surface in terms of exposed entry points (AJAX, REST API, shortcodes, cron events). The presence of nonce and capability checks also indicates some effort towards securing operations.

However, significant concerns arise from the SQL query handling and output escaping. All SQL queries are not using prepared statements, which can lead to SQL injection vulnerabilities if user-supplied data is not meticulously sanitized before being passed to these queries. Furthermore, a substantial portion of output (100%) is not properly escaped, presenting a high risk of Cross-Site Scripting (XSS) vulnerabilities. This lack of output escaping is a critical weakness, as it allows attackers to inject malicious scripts into web pages viewed by other users.

While the absence of past vulnerabilities and a clean taint analysis are reassuring, the current code analysis reveals fundamental security flaws in data handling. The strength lies in the limited attack surface and the presence of some basic security checks. The weakness, however, is profound, with unescaped output and raw SQL queries posing immediate and severe risks to the security of any WordPress site using this plugin. Mitigation of these risks should be a priority.

Key Concerns

  • SQL queries do not use prepared statements
  • No output properly escaped
Vulnerabilities
None known

Feefo Ratings & Reviews for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Feefo Ratings & Reviews for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
0 prepared
Unescaped Output
7
0 escaped
Nonce Checks
2
Capability Checks
3
File Operations
0
External Requests
6
Bundled Libraries
0

SQL Query Safety

0% prepared2 total queries

Output Escaping

0% escaped7 total outputs
Attack Surface

Feefo Ratings & Reviews for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_enqueue_scriptsfeefo-ratings-and-reviews.php:114
actionadmin_menufeefo-ratings-and-reviews.php:643
actioninitfeefo-ratings-and-reviews.php:645
filterwoocommerce_product_tabsfeefo-ratings-and-reviews.php:646
actionwp_footerfeefo-ratings-and-reviews.php:647
actionwoocommerce_after_add_to_cart_buttonfeefo-ratings-and-reviews.php:648
actionwoocommerce_after_single_product_summaryfeefo-ratings-and-reviews.php:649
Maintenance & Trust

Feefo Ratings & Reviews for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedNov 22, 2024
PHP min version
Downloads10K

Community Trust

Rating46/100
Number of ratings4
Active installs300
Developer Profile

Feefo Ratings & Reviews for WooCommerce Developer Profile

feefo

1 plugin · 300 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Feefo Ratings & Reviews for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/feefo-ratings-reviews-for-woocommerce/assets/css/side-menu-logo.css/wp-content/plugins/feefo-ratings-reviews-for-woocommerce/assets/css/iframe-display.css/wp-content/plugins/feefo-ratings-reviews-for-woocommerce/assets/css/start-plugin-setup-display.css

HTML / DOM Fingerprints

CSS Classes
plugin-setup-divplugin-setup-h1plugin-setup-a
Data Attributes
id="plugin-setup-div"id="plugin-setup-h1"id="plugin-setup-a"
REST Endpoints
/ecommerce/plugin/woocommerce/register/callback
FAQ

Frequently Asked Questions about Feefo Ratings & Reviews for WooCommerce