
Flexible hReview Security & Risk Analysis
wordpress.org/plugins/flexible-hreviewEasily add hReview data to a Post. Show it anywhere using the function or the shortcode.
Is Flexible hReview Safe to Use in 2026?
Generally Safe
Score 85/100Flexible hReview has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "flexible-hreview" plugin v0.5 exhibits a generally good security posture with several strong practices observed. The complete absence of dangerous functions, SQL injection vulnerabilities, external HTTP requests, and file operations is highly positive. The use of prepared statements for all SQL queries and the presence of nonce checks indicate a good understanding of WordPress security best practices. However, the analysis reveals a significant concern regarding output escaping, with only 19% of outputs being properly escaped. This means that a substantial portion of the plugin's output is vulnerable to cross-site scripting (XSS) attacks, allowing attackers to inject malicious scripts into the user's browser. While there are no recorded vulnerabilities or critical taint flows, the lack of robust output escaping presents a tangible risk.
The plugin's vulnerability history is clean, with no known CVEs. This, combined with the limited attack surface (primarily a single shortcode), suggests that the plugin has been relatively secure in the past. However, the lack of extensive testing or previous vulnerabilities does not negate the identified risks. The presence of an unsanitized path in the taint analysis, though not classified as critical or high severity, warrants attention as it could potentially lead to unexpected behavior or information disclosure in certain edge cases. In conclusion, while the plugin demonstrates good foundational security, the widespread issue with output escaping is a critical weakness that needs immediate remediation to prevent potential XSS vulnerabilities.
Key Concerns
- Low output escaping percentage
- Unsanitized path in taint flow
Flexible hReview Security Vulnerabilities
Flexible hReview Release Timeline
Flexible hReview Code Analysis
Output Escaping
Data Flow Analysis
Flexible hReview Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
Flexible hReview Maintenance & Trust
Maintenance Signals
Community Trust
Flexible hReview Alternatives
WP Customer Reviews
wp-customer-reviews
Allows your visitors to leave business / product reviews. Testimonials are in Microdata / Microformat and may display star ratings in search results.
Author hReview
author-hreview
Add Google Rich Snippets for reviews based on schema.org for a better WordPress SEO, customize search results with rating stars for more traffic and c …
hReview Support for Editor
hreview-support-for-editor
This is a plugin to allow the easy entry of microformat content for reviews (i.e. the hReview microformat) in WordPress pages and posts.
WPRS Data Transporter
wprs-data-transporter
Simply transfer your inputs Schema markups for reviews and star ratings data from one theme/plugin to another.
Widgets for Google Reviews
wp-reviews-plugin-for-google
Embed Google reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Google reviews.
Flexible hReview Developer Profile
3 plugins · 30 total installs
How We Detect Flexible hReview
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/flexible-hreview/fhr-admin.css/wp-content/plugins/flexible-hreview/fhr-front.css/wp-content/plugins/flexible-hreview/fhr-front.js/wp-content/plugins/flexible-hreview/fhr-front.jsflexible-hreview/fhr-admin.css?ver=flexible-hreview/fhr-front.css?ver=flexible-hreview/fhr-front.js?ver=HTML / DOM Fingerprints
fhr-ratingfhr-item-namefhr-item-urlfhr-typefhr-summaryfhr-rating-maxfhr-rating-commentarydata-fhr-rating-maxdata-fhr-rating-commentaryfhr_obj<div class="hreview"><p class="fhr-summary"><span class="fhr-item-name"><a class="fhr-item-url" href="