Five-Star Ratings Shortcode Security & Risk Analysis

wordpress.org/plugins/five-star-ratings-shortcode

Simple lightweight shortcode to add 5-star ratings anywhere.

700 active installs v1.2.61 PHP 7.0+ WP 4.6.1+ Updated Feb 2, 2026
accessibleiconratingsshortcodestars
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Five-Star Ratings Shortcode Safe to Use in 2026?

Generally Safe

Score 100/100

Five-Star Ratings Shortcode has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The 'five-star-ratings-shortcode' plugin v1.2.61 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The plugin demonstrates good practices by utilizing prepared statements for all SQL queries and properly escaping a high percentage (91%) of its outputs. Furthermore, there is no recorded history of known vulnerabilities (CVEs), indicating a sustained effort towards security or a lack of discovered flaws. The limited attack surface, with only one shortcode and no unprotected entry points, is also a positive sign. However, the absence of nonce checks across all identified entry points presents a potential concern. While the current analysis doesn't highlight any immediate critical risks from taint flows or dangerous functions, the lack of nonce validation could theoretically be exploited if input from the shortcode is not handled with extreme care, especially if it were to interact with external systems or perform sensitive actions in the future. The presence of a bundled Freemius library, while common, warrants a note as outdated versions can introduce vulnerabilities.

Key Concerns

  • Missing nonce checks on entry points
  • Bundled outdated library (Freemius v1.0)
Vulnerabilities
None known

Five-Star Ratings Shortcode Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Five-Star Ratings Shortcode Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
62 escaped
Nonce Checks
0
Capability Checks
4
File Operations
4
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

Output Escaping

91% escaped68 total outputs
Attack Surface

Five-Star Ratings Shortcode Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[rating] includes\class-five-star-ratings-shortcode.php:248
WordPress Hooks 13
actionplugins_loadedfive-star-ratings-shortcode.php:163
actionafter_uninstallfive-star-ratings-shortcode.php:178
filterplugin_row_metaincludes\class-five-star-ratings-shortcode-meta.php:38
actioninitincludes\class-five-star-ratings-shortcode-settings.php:53
actionadmin_initincludes\class-five-star-ratings-shortcode-settings.php:55
actionadmin_menuincludes\class-five-star-ratings-shortcode-settings.php:57
actionadmin_enqueue_scriptsincludes\class-five-star-ratings-shortcode.php:211
actionadmin_enqueue_scriptsincludes\class-five-star-ratings-shortcode.php:217
actionwp_enqueue_scriptsincludes\class-five-star-ratings-shortcode.php:223
actionwp_enqueue_scriptsincludes\class-five-star-ratings-shortcode.php:229
filterscript_loader_tagincludes\class-five-star-ratings-shortcode.php:235
actioninitincludes\class-five-star-ratings-shortcode.php:243
actionadmin_noticesincludes\class-five-star-ratings-shortcode.php:246
Maintenance & Trust

Five-Star Ratings Shortcode Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 2, 2026
PHP min version7.0
Downloads27K

Community Trust

Rating84/100
Number of ratings5
Active installs700
Developer Profile

Five-Star Ratings Shortcode Developer Profile

Chris J. Zähller

3 plugins · 810 total installs

99
trust score
Avg Security Score
99/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect Five-Star Ratings Shortcode

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Five-Star Ratings Shortcode