GlowReviews – Smart Feedback & Testimonials Security & Risk Analysis

wordpress.org/plugins/glowreviews

Collect and display customer feedback with star ratings, image uploads, and WordPress user integration.

0 active installs v1.0.1 PHP 7.4+ WP 5.2+ Updated Feb 17, 2026
customerfeedbackratingsreviewstestimonials
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is GlowReviews – Smart Feedback & Testimonials Safe to Use in 2026?

Generally Safe

Score 100/100

GlowReviews – Smart Feedback & Testimonials has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The plugin 'glowreviews' v1.0.1 demonstrates a strong security posture based on the provided static analysis. It exhibits good practices by having no identified dangerous functions, file operations, or external HTTP requests. All SQL queries are properly prepared, and a high percentage of output is correctly escaped, suggesting a good effort to prevent common vulnerabilities like SQL injection and cross-site scripting (XSS). The presence of numerous nonce and capability checks on its entry points, including all AJAX handlers and shortcodes, further strengthens its defense against unauthorized access and malicious manipulation.

The taint analysis reveals no high-severity issues, and the plugin has no recorded vulnerability history (CVEs). This indicates a history of secure development or diligent patching. The low number of total flows analyzed (3) and the absence of unsanitized paths in these flows further contribute to a positive security assessment. However, the presence of 10 AJAX handlers, even with checks, represents a significant attack surface. While the analysis states 0 unprotected handlers, a large number of handlers always carries a potential for complex interactions that might be overlooked.

In conclusion, 'glowreviews' v1.0.1 appears to be a well-secured plugin. Its strengths lie in the diligent use of prepared statements, output escaping, and robust authorization checks on its entry points. The lack of any historical vulnerabilities or critical taint flows is a significant positive. The only minor area of potential concern is the sheer number of AJAX handlers, which, despite being protected, necessitates careful review to ensure no complex or chained vulnerabilities exist. Overall, the plugin presents a low security risk.

Vulnerabilities
None known

GlowReviews – Smart Feedback & Testimonials Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

GlowReviews – Smart Feedback & Testimonials Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
20
245 escaped
Nonce Checks
22
Capability Checks
5
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

92% escaped265 total outputs
Data Flows
All sanitized

Data Flow Analysis

3 flows
save_testimonial_meta (includes\class-testimonials-post-type.php:172)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

GlowReviews – Smart Feedback & Testimonials Attack Surface

Entry Points14
Unprotected0

AJAX Handlers 10

authwp_ajax_glowrev-submit-feedbackincludes\class-feedback-handler-new.php:42
noprivwp_ajax_glowrev-submit-feedbackincludes\class-feedback-handler-new.php:43
authwp_ajax_glowrev_test_sessionincludes\class-feedback-handler-new.php:44
noprivwp_ajax_glowrev_test_sessionincludes\class-feedback-handler-new.php:45
authwp_ajax_glowrev_test_successincludes\class-feedback-handler-new.php:46
noprivwp_ajax_glowrev_test_successincludes\class-feedback-handler-new.php:47
authwp_ajax_glowrev_clear_sessionincludes\class-feedback-handler-new.php:48
noprivwp_ajax_glowrev_clear_sessionincludes\class-feedback-handler-new.php:49
authwp_ajax_glowrev_clear_debug_logincludes\class-feedback-handler-new.php:50
noprivwp_ajax_glowrev_clear_debug_logincludes\class-feedback-handler-new.php:51

Shortcodes 4

[glowrev_glowreviews_feedback_form] includes\class-feedback-handler-new.php:61
[glowrev-feedback-form] includes\class-feedback-handler-new.php:63
[glowrev_glowreviews_display] includes\class-testimonials-display-new.php:17
[glowrev-display-testimonials] includes\class-testimonials-display-new.php:19
WordPress Hooks 22
actionadmin_initglowreviews.php:228
actionadmin_initglowreviews.php:229
actiontemplate_redirectglowreviews.php:232
actionparse_requestglowreviews.php:235
actionwp_enqueue_scriptsglowreviews.php:252
actionplugins_loadedglowreviews.php:254
actionadmin_menuincludes\class-admin-settings.php:29
actionadmin_initincludes\class-admin-settings.php:30
actionadmin_enqueue_scriptsincludes\class-admin-settings.php:31
actionadmin_initincludes\class-admin-settings.php:32
actioninitincludes\class-documentation.php:17
actionadmin_enqueue_scriptsincludes\class-documentation.php:18
actionadmin_menuincludes\class-documentation.php:25
actionwp_enqueue_scriptsincludes\class-feedback-handler-new.php:41
filterscript_loader_tagincludes\class-script-attributes.php:18
filterwp_script_attributesincludes\class-script-attributes.php:81
actionwp_enqueue_scriptsincludes\class-testimonials-display-new.php:20
actioninitincludes\class-testimonials-post-type.php:16
actionadd_meta_boxesincludes\class-testimonials-post-type.php:17
actionsave_post_glowrev_testimonialincludes\class-testimonials-post-type.php:18
actionadmin_enqueue_scriptsincludes\class-testimonials-post-type.php:19
filterpost_row_actionsincludes\class-testimonials-post-type.php:20
Maintenance & Trust

GlowReviews – Smart Feedback & Testimonials Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 17, 2026
PHP min version7.4
Downloads477

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

GlowReviews – Smart Feedback & Testimonials Developer Profile

motiraj

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect GlowReviews – Smart Feedback & Testimonials

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/glowreviews/assets/css/glowreviews-admin.css/wp-content/plugins/glowreviews/assets/css/glowreviews-frontend.css/wp-content/plugins/glowreviews/assets/js/glowreviews-admin.js/wp-content/plugins/glowreviews/assets/js/glowreviews-frontend.js
Script Paths
/wp-content/plugins/glowreviews/assets/js/glowreviews-admin.js/wp-content/plugins/glowreviews/assets/js/glowreviews-frontend.js
Version Parameters
/wp-content/plugins/glowreviews/assets/css/glowreviews-admin.css?ver=/wp-content/plugins/glowreviews/assets/css/glowreviews-frontend.css?ver=/wp-content/plugins/glowreviews/assets/js/glowreviews-admin.js?ver=/wp-content/plugins/glowreviews/assets/js/glowreviews-frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
glowreviews-containerglowreviews-testimonial
HTML Comments
<!-- START GLOWREVIEWS TESTIMONIAL --><!-- END GLOWREVIEWS TESTIMONIAL -->
Data Attributes
data-glowreviews-id
JS Globals
glowreviews
Shortcode Output
[glowreviews]
FAQ

Frequently Asked Questions about GlowReviews – Smart Feedback & Testimonials