
Get Google Reviews Security & Risk Analysis
wordpress.org/plugins/get-google-reviewsGet your Google Reviews and display them on your website. Easily and without needing an API key.
Is Get Google Reviews Safe to Use in 2026?
Generally Safe
Score 100/100Get Google Reviews has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'get-google-reviews' v1.3.0 plugin exhibits a mixed security posture. On the positive side, it has no recorded vulnerabilities or CVEs, suggesting a generally well-maintained codebase. The code analysis shows a reasonable use of prepared statements for SQL queries and a decent percentage of output escaping, along with nonce and capability checks for critical operations. The absence of dangerous functions and taint analysis showing no unsanitized paths further contribute to a notion of careful development.
However, there are notable areas of concern. The plugin exposes one AJAX handler without authentication, which presents a significant attack vector. While the total number of entry points is low, this single unprotected entry point could be exploited if it handles sensitive data or operations. The limited number of file operations and external HTTP requests is good, but the presence of any file operation or external request without clear sanitization or authorization is a potential risk. The output escaping, while over 60%, still leaves nearly 40% of outputs potentially unescaped, which could lead to cross-site scripting (XSS) vulnerabilities if user-controlled data is involved.
In conclusion, while the plugin's lack of historical vulnerabilities is a strong positive, the presence of an unprotected AJAX endpoint and imperfect output escaping are critical weaknesses that require immediate attention. The overall security is adequate for a plugin with no known vulnerabilities, but these specific issues lower its score and represent a tangible risk to users.
Key Concerns
- AJAX handler without auth check
- Output escaping not properly implemented (34%)
Get Google Reviews Security Vulnerabilities
Get Google Reviews Release Timeline
Get Google Reviews Code Analysis
SQL Query Safety
Output Escaping
Get Google Reviews Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 11
Scheduled Events 2
Maintenance & Trust
Get Google Reviews Maintenance & Trust
Maintenance Signals
Community Trust
Get Google Reviews Alternatives
Reviews Block for Google
google-places-reviews
Easily display Google business reviews on your WordPress website with a simple and intuitive block.
Widget for Google Reviews
business-reviews-wp
Shortcode and widget for Google Reviews. Display Google Business Reviews on your WordPress website to increase user confidence and SEO.
Free Google Reviews widget by OpenWidget
free-google-reviews-widget-by-openwidget
⭐️ Embed Google reviews into your WordPress site. Improve trust, sales & SEO of your Wordpress site with Google reviews.
Smart Showcase for Google Reviews
smart-showcase-for-google-reviews
Smart Showcase for Google Reviews is a WordPress plugin that lets businesses display Google customer reviews on their websites easily.
Widgets for Google Reviews
wp-reviews-plugin-for-google
Embed Google reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Google reviews.
Get Google Reviews Developer Profile
1 plugin · 70 total installs
How We Detect Get Google Reviews
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/get-google-reviews/css/diggr-admin.css/wp-content/plugins/get-google-reviews/js/diggr-admin.js/wp-content/plugins/get-google-reviews/js/diggr-ajax-get-cid.js/wp-content/plugins/get-google-reviews/js/diggr-admin.js/wp-content/plugins/get-google-reviews/js/diggr-ajax-get-cid.jsget-google-reviews/css/diggr-admin.css?ver=get-google-reviews/js/diggr-admin.js?ver=get-google-reviews/js/diggr-ajax-get-cid.js?ver=HTML / DOM Fingerprints
<!-- Currently plugin version. --><!-- The plugin bootstrap file --><!-- The code that runs during plugin activation. --><!-- The code that runs during plugin deactivation. -->+9 moredata-plugin-name="get-google-reviews"data-plugin-version="1.3.0"diggr_ajax_data