
hReview Support for Editor Security & Risk Analysis
wordpress.org/plugins/hreview-support-for-editorThis is a plugin to allow the easy entry of microformat content for reviews (i.e. the hReview microformat) in WordPress pages and posts.
Is hReview Support for Editor Safe to Use in 2026?
Generally Safe
Score 85/100hReview Support for Editor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The hreview-support-for-editor plugin, in version 0.9, presents a mixed security posture. While the static analysis indicates a commendably small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events, and a complete absence of dangerous functions and external HTTP requests, there are significant concerns. A critical weakness lies in the output escaping; 100% of the 13 identified output points are not properly escaped. This means that any data rendered by the plugin, if it originates from an untrusted source or contains malicious characters, could lead to cross-site scripting (XSS) vulnerabilities. The lack of nonce and capability checks on entry points, although the entry points themselves are zero, is a theoretical concern if any were introduced later without proper security measures. The plugin has no recorded vulnerability history, which is a positive sign, suggesting either good development practices in the past or that it hasn't been a target. However, this cannot compensate for the identified output escaping flaw. The overall security is weakened by this critical flaw despite the minimal attack surface and clean vulnerability history.
Key Concerns
- All output points are unescaped
- No nonce checks detected
- No capability checks detected
hReview Support for Editor Security Vulnerabilities
hReview Support for Editor Code Analysis
Bundled Libraries
Output Escaping
hReview Support for Editor Attack Surface
WordPress Hooks 9
Maintenance & Trust
hReview Support for Editor Maintenance & Trust
Maintenance Signals
Community Trust
hReview Support for Editor Alternatives
Author hReview
author-hreview
Add Google Rich Snippets for reviews based on schema.org for a better WordPress SEO, customize search results with rating stars for more traffic and c …
Elementor Website Builder – More Than Just a Page Builder
elementor
The Elementor Website Builder has it all: drag and drop page builder, pixel perfect design, mobile responsive editing, and more. Get started now!
Classic Editor
classic-editor
Enables the previous "classic" editor and the old-style Edit Post screen with TinyMCE, Meta Boxes, etc. Supports all plugins that extend this screen.
Starter Templates – AI-Powered Templates for Elementor & Gutenberg
astra-sites
The growing library of 300+ ready-to-use templates that work with all WordPress themes including Astra, Hello, OceanWP, GeneratePress and more
Classic Widgets
classic-widgets
Enables the previous "classic" widgets settings screens in Appearance - Widgets and the Customizer. Disables the block editor from managing widgets.
hReview Support for Editor Developer Profile
1 plugin · 20 total installs
How We Detect hReview Support for Editor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/hreview-support-for-editor/hreview.css/wp-content/plugins/hreview-support-for-editor/hreview-editor.css/wp-content/plugins/hreview-support-for-editor/tinymceplugin/editor_plugin.jsHTML / DOM Fingerprints
hreviewitemfnurlsummarydescriptionmyratingreviewer+2 moredata-hreview-idhreview_from_guiedInsertHReviewedInsertHReviewCodeedInsertHReviewAbortedInsertHReviewStarsedInsertHReviewDone