Widgets for Reviews & Recommendations Security & Risk Analysis

wordpress.org/plugins/free-facebook-reviews-and-recommendations-widgets

Embed Facebook reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Facebook recommendations.

8K active installs v13.2.9 PHP 7.4+ WP 6.2+ Updated Apr 14, 2026
facebookfacebook-pagerecommendationrecommendationsreviews
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Widgets for Reviews & Recommendations Safe to Use in 2026?

Generally Safe

Score 100/100

Widgets for Reviews & Recommendations has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "free-facebook-reviews-and-recommendations-widgets" plugin v13.2.7 exhibits a mixed security posture. On the positive side, it demonstrates strong adherence to output escaping, with 100% of outputs being properly escaped. The extensive use of prepared statements for SQL queries (98%) is also a significant strength, greatly mitigating the risk of SQL injection. The plugin also features a healthy number of nonce checks, indicating an awareness of CSRF protection. However, critical security concerns arise from its attack surface. All three identified entry points (1 AJAX handler, 2 REST API routes) lack proper authentication and permission checks, leaving them entirely unprotected. While taint analysis did not reveal critical or high-severity vulnerabilities, the presence of one flow with unsanitized paths is a concern, especially when combined with the unprotected entry points. The lack of any recorded historical vulnerabilities might suggest either diligent security practices in the past or a lack of past security scrutiny. Overall, the plugin has robust internal coding practices for data handling and output, but its exposed interface presents a significant risk due to the absence of authentication.

Key Concerns

  • AJAX handler without auth checks
  • REST API route without permission callback
  • REST API route without permission callback
  • Flow with unsanitized paths
  • Unprotected entry points
Vulnerabilities
None known

Widgets for Reviews & Recommendations Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Widgets for Reviews & Recommendations Release Timeline

v13.2.9Current
v13.2.8
v13.2.7
v13.2.6
v13.2.5
v13.1
v13.0
v12.9
v12.8
v12.7.6
v12.6.1
v12.5
v12.4.7
v12.3
v12.2
v12.1.2
v12.0
v11.9
v10.9.1
Code Analysis
Analyzed Mar 16, 2026

Widgets for Reviews & Recommendations Code Analysis

Dangerous Functions
1
Raw SQL Queries
1
54 prepared
Unescaped Output
3
1330 escaped
Nonce Checks
39
Capability Checks
4
File Operations
3
External Requests
9
Bundled Libraries
0

Dangerous Functions Found

unserialize$wpRepoResponse = unserialize(wp_remote_retrieve_body($wpResponse));trustindex-plugin.class.php:7330

SQL Query Safety

98% prepared55 total queries

Output Escaping

100% escaped1333 total outputs
Data Flows · Security
1 unsanitized

Data Flow Analysis

6 flows1 with unsanitized paths
<admin> (include\admin.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
3 unprotected

Widgets for Reviews & Recommendations Attack Surface

Entry Points3
Unprotected3

AJAX Handlers 1

authwp_ajax_list_trustindex_widgetsfree-facebook-reviews-and-recommendations-widgets.php:110

REST API Routes 2

GET/wp-json/trustindex/v1/get-widgetstrustindex-plugin.class.php:7472
GET/wp-json/trustindex/v1/setup-completetrustindex-plugin.class.php:7477
WordPress Hooks 36
actionadmin_initfree-facebook-reviews-and-recommendations-widgets.php:28
actionplugins_loadedfree-facebook-reviews-and-recommendations-widgets.php:31
actionwp_headfree-facebook-reviews-and-recommendations-widgets.php:32
actionwp_insert_sitefree-facebook-reviews-and-recommendations-widgets.php:61
actionadmin_menufree-facebook-reviews-and-recommendations-widgets.php:73
filterplugin_action_linksfree-facebook-reviews-and-recommendations-widgets.php:74
filterplugin_row_metafree-facebook-reviews-and-recommendations-widgets.php:75
actionwidgets_initfree-facebook-reviews-and-recommendations-widgets.php:77
actionwidgets_initfree-facebook-reviews-and-recommendations-widgets.php:78
actioninitfree-facebook-reviews-and-recommendations-widgets.php:80
actioninitfree-facebook-reviews-and-recommendations-widgets.php:86
filterscript_loader_tagfree-facebook-reviews-and-recommendations-widgets.php:87
actionelementor/controls/controls_registeredfree-facebook-reviews-and-recommendations-widgets.php:93
actionelementor/widgets/registerfree-facebook-reviews-and-recommendations-widgets.php:97
actionelementor/widgets/widgets_registeredfree-facebook-reviews-and-recommendations-widgets.php:103
actioninitfree-facebook-reviews-and-recommendations-widgets.php:109
actionadmin_enqueue_scriptsfree-facebook-reviews-and-recommendations-widgets.php:111
actionrest_api_initfree-facebook-reviews-and-recommendations-widgets.php:112
actionadmin_noticesfree-facebook-reviews-and-recommendations-widgets.php:145
actionadmin_noticesfree-facebook-reviews-and-recommendations-widgets.php:147
filterrocket_minify_excluded_external_jsinclude\cache-plugin-filters.php:13
filterrocket_exclude_jsinclude\cache-plugin-filters.php:14
filterrocket_delay_js_exclusionsinclude\cache-plugin-filters.php:15
filterlitespeed_optimize_js_excludesinclude\cache-plugin-filters.php:16
filtersgo_javascript_combine_excluded_external_pathsinclude\cache-plugin-filters.php:17
filtersgo_css_combine_excludeinclude\cache-plugin-filters.php:18
filterrocket_rucss_safelistinclude\cache-plugin-filters.php:58
filterscript_loader_taginclude\cache-plugin-filters.php:63
filterstyle_loader_taginclude\cache-plugin-filters.php:78
actionenqueue_block_editor_assetsstatic\block-editor\block-editor.php:10
actioninitstatic\block-editor\block-editor.php:11
filterfilesystem_methodtrustindex-plugin.class.php:1049
actionadmin_noticestrustindex-plugin.class.php:1067
actionhttp_api_curltrustindex-plugin.class.php:6383
filtermce_external_pluginstrustindex-plugin.class.php:7209
filtermce_buttonstrustindex-plugin.class.php:7210
Maintenance & Trust

Widgets for Reviews & Recommendations Maintenance & Trust

Maintenance Signals

WordPress version tested7.0
Last updatedApr 14, 2026
PHP min version7.4
Downloads493K

Community Trust

Rating92/100
Number of ratings100
Active installs8K
Developer Profile

Widgets for Reviews & Recommendations Developer Profile

Trustindex

34 plugins · 975K total installs

87
trust score
Avg Security Score
98/100
Avg Patch Time
71 days
View full developer profile
Detection Fingerprints

How We Detect Widgets for Reviews & Recommendations

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/free-facebook-reviews-and-recommendations-widgets/css/style.css/wp-content/plugins/free-facebook-reviews-and-recommendations-widgets/css/custom.css/wp-content/plugins/free-facebook-reviews-and-recommendations-widgets/js/frontend.js/wp-content/plugins/free-facebook-reviews-and-recommendations-widgets/js/reviews.js
Generator Patterns
Trustindex.io
Script Paths
https://cdn.trustindex.io/loader.js
Version Parameters
free-facebook-reviews-and-recommendations-widgets/css/style.css?ver=free-facebook-reviews-and-recommendations-widgets/css/custom.css?ver=free-facebook-reviews-and-recommendations-widgets/js/frontend.js?ver=free-facebook-reviews-and-recommendations-widgets/js/reviews.js?ver=trustindex-loader-js

HTML / DOM Fingerprints

CSS Classes
trustindex-widget
HTML Comments
Copyright 2019 Trustindex Kft (email: support@trustindex.io)
Data Attributes
data-ccm-injected
JS Globals
TrustindexPlugin_facebookTrustindexWidget
REST Endpoints
/wp-json/trustindex-plugin/v1/get-reviews/wp-json/trustindex-plugin/v1/get-recommendations
Shortcode Output
[trustindex no-reviews-message="No reviews yet."][trustindex][trustindex fb_type="page" page_id="YOUR_PAGE_ID"][trustindex fb_type="recommendations" page_id="YOUR_PAGE_ID"]
FAQ

Frequently Asked Questions about Widgets for Reviews & Recommendations