
Widgets for Reviews & Recommendations Security & Risk Analysis
wordpress.org/plugins/free-facebook-reviews-and-recommendations-widgetsEmbed Facebook reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Facebook recommendations.
Is Widgets for Reviews & Recommendations Safe to Use in 2026?
Generally Safe
Score 100/100Widgets for Reviews & Recommendations has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "free-facebook-reviews-and-recommendations-widgets" plugin v13.2.7 exhibits a mixed security posture. On the positive side, it demonstrates strong adherence to output escaping, with 100% of outputs being properly escaped. The extensive use of prepared statements for SQL queries (98%) is also a significant strength, greatly mitigating the risk of SQL injection. The plugin also features a healthy number of nonce checks, indicating an awareness of CSRF protection. However, critical security concerns arise from its attack surface. All three identified entry points (1 AJAX handler, 2 REST API routes) lack proper authentication and permission checks, leaving them entirely unprotected. While taint analysis did not reveal critical or high-severity vulnerabilities, the presence of one flow with unsanitized paths is a concern, especially when combined with the unprotected entry points. The lack of any recorded historical vulnerabilities might suggest either diligent security practices in the past or a lack of past security scrutiny. Overall, the plugin has robust internal coding practices for data handling and output, but its exposed interface presents a significant risk due to the absence of authentication.
Key Concerns
- AJAX handler without auth checks
- REST API route without permission callback
- REST API route without permission callback
- Flow with unsanitized paths
- Unprotected entry points
Widgets for Reviews & Recommendations Security Vulnerabilities
Widgets for Reviews & Recommendations Release Timeline
Widgets for Reviews & Recommendations Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Widgets for Reviews & Recommendations Attack Surface
AJAX Handlers 1
REST API Routes 2
WordPress Hooks 36
Maintenance & Trust
Widgets for Reviews & Recommendations Maintenance & Trust
Maintenance Signals
Community Trust
Widgets for Reviews & Recommendations Alternatives
WP Testimonials
testimonial-widgets
Display your Testimonials on your website fast and easily. 21 widget types, 25 widget styles available. (Free Plugin)
Widgets for Amazon Reviews
review-widgets-for-amazon
Embed Amazon reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Amazon reviews.
Review widget addon for Elementor
review-widget-addon-for-elementor
Use this Elementor addon to show your reviews (from Google, Facebook, Tripadvisor) in your site.
Widgets for Thumbtack Reviews
widgets-for-thumbtack-reviews
Embed Thumbtack reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Thumbtack reviews.
Review widget addon for Divi
review-widget-addon-for-divi
Display your Reviews for free with our responsive widgets in 2 minutes.
Widgets for Reviews & Recommendations Developer Profile
34 plugins · 975K total installs
How We Detect Widgets for Reviews & Recommendations
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/free-facebook-reviews-and-recommendations-widgets/css/style.css/wp-content/plugins/free-facebook-reviews-and-recommendations-widgets/css/custom.css/wp-content/plugins/free-facebook-reviews-and-recommendations-widgets/js/frontend.js/wp-content/plugins/free-facebook-reviews-and-recommendations-widgets/js/reviews.jsTrustindex.iohttps://cdn.trustindex.io/loader.jsfree-facebook-reviews-and-recommendations-widgets/css/style.css?ver=free-facebook-reviews-and-recommendations-widgets/css/custom.css?ver=free-facebook-reviews-and-recommendations-widgets/js/frontend.js?ver=free-facebook-reviews-and-recommendations-widgets/js/reviews.js?ver=trustindex-loader-jsHTML / DOM Fingerprints
trustindex-widgetCopyright 2019 Trustindex Kft (email: support@trustindex.io)data-ccm-injectedTrustindexPlugin_facebookTrustindexWidget/wp-json/trustindex-plugin/v1/get-reviews/wp-json/trustindex-plugin/v1/get-recommendations[trustindex no-reviews-message="No reviews yet."][trustindex][trustindex fb_type="page" page_id="YOUR_PAGE_ID"][trustindex fb_type="recommendations" page_id="YOUR_PAGE_ID"]