hReview Support for Editor Security & Risk Analysis

wordpress.org/plugins/hreview-support-for-editor

This is a plugin to allow the easy entry of microformat content for reviews (i.e. the hReview microformat) in WordPress pages and posts.

20 active installs v0.9 PHP + WP 2.5+ Updated Dec 27, 2011
editorhreview
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is hReview Support for Editor Safe to Use in 2026?

Generally Safe

Score 85/100

hReview Support for Editor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 14yr ago
Risk Assessment

The hreview-support-for-editor plugin, in version 0.9, presents a mixed security posture. While the static analysis indicates a commendably small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events, and a complete absence of dangerous functions and external HTTP requests, there are significant concerns. A critical weakness lies in the output escaping; 100% of the 13 identified output points are not properly escaped. This means that any data rendered by the plugin, if it originates from an untrusted source or contains malicious characters, could lead to cross-site scripting (XSS) vulnerabilities. The lack of nonce and capability checks on entry points, although the entry points themselves are zero, is a theoretical concern if any were introduced later without proper security measures. The plugin has no recorded vulnerability history, which is a positive sign, suggesting either good development practices in the past or that it hasn't been a target. However, this cannot compensate for the identified output escaping flaw. The overall security is weakened by this critical flaw despite the minimal attack surface and clean vulnerability history.

Key Concerns

  • All output points are unescaped
  • No nonce checks detected
  • No capability checks detected
Vulnerabilities
None known

hReview Support for Editor Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

hReview Support for Editor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
13
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

TinyMCE

Output Escaping

0% escaped13 total outputs
Attack Surface

hReview Support for Editor Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionadmin_footerhreview.php:37
actionwp_headhreview.php:38
actionmarker_csshreview.php:39
actioninithreview.php:40
actionadmin_menuhreview.php:41
filtermce_external_pluginshreview.php:47
filtermce_buttons_3hreview.php:48
actionadmin_footer-post.phphreview.php:51
actionadmin_footer-post-new.phphreview.php:52
Maintenance & Trust

hReview Support for Editor Maintenance & Trust

Maintenance Signals

WordPress version tested3.3.2
Last updatedDec 27, 2011
PHP min version
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

hReview Support for Editor Developer Profile

andrewescott

1 plugin · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect hReview Support for Editor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/hreview-support-for-editor/hreview.css/wp-content/plugins/hreview-support-for-editor/hreview-editor.css
Script Paths
/wp-content/plugins/hreview-support-for-editor/tinymceplugin/editor_plugin.js

HTML / DOM Fingerprints

CSS Classes
hreviewitemfnurlsummarydescriptionmyratingreviewer+2 more
Data Attributes
data-hreview-id
JS Globals
hreview_from_guiedInsertHReviewedInsertHReviewCodeedInsertHReviewAbortedInsertHReviewStarsedInsertHReviewDone
FAQ

Frequently Asked Questions about hReview Support for Editor