Iconic Rating Security & Risk Analysis
wordpress.org/plugins/iconic-ratingReview or rating any post type, with stars or other awesome icons, adding some effects on hover (and tooltips).
Is Iconic Rating Safe to Use in 2026?
Generally Safe
Score 85/100Iconic Rating has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The Iconic-Rating plugin version 1.0.0 exhibits significant security concerns despite a clean vulnerability history. The static analysis reveals a limited attack surface of two AJAX handlers, but crucially, both lack authentication checks, presenting a direct pathway for unauthorized actions. The absence of nonce checks further exacerbates this, making these handlers vulnerable to Cross-Site Request Forgery (CSRF) attacks. While the plugin doesn't utilize dangerous functions, perform file operations, or make external HTTP requests, its handling of SQL queries is alarming. A single SQL query is present and is not using prepared statements, posing a risk of SQL injection. Additionally, a mere 4% of output is properly escaped, indicating a high probability of Cross-Site Scripting (XSS) vulnerabilities across various outputs. The plugin's vulnerability history is notably clean, which is a positive indicator, but it cannot mitigate the direct risks identified in the code itself. The lack of robust security measures in place, especially concerning authentication and output sanitization, significantly weakens its security posture.
Key Concerns
- AJAX handlers without auth checks
- AJAX handlers without nonce checks
- Raw SQL without prepared statements
- Low percentage of properly escaped output
Iconic Rating Security Vulnerabilities
Iconic Rating Code Analysis
SQL Query Safety
Output Escaping
Iconic Rating Attack Surface
AJAX Handlers 2
WordPress Hooks 7
Maintenance & Trust
Iconic Rating Maintenance & Trust
Maintenance Signals
Community Trust
Iconic Rating Alternatives
Guaranteed Reviews Company (Société des Avis Garantis)
woo-guaranteed-reviews-company
Collect and display product and website reviews through Guaranteed Reviews Company / Société des Avis Garantis.
Rate Star Review Vote – AJAX Reviews, Votes, Star Ratings
rate-star-review
Boost engagement with AJAX-driven star ratings, reviews, vote buttons for content.
Product Reviews from rateit.cool for Woocommerce
rateitcool
Together to more sales. 65% more sales with many product reviews for each product. Show the product reviews everywhere you want.
Multi Rating & Review Matrix System
rating-review-matrix
IMPORTANT UPGRADE INFO 1.0.4 to 1.0.5
Generate Reviews
generate-reviews
This plugin can generate reviews using shortcode but exclusively for clients of Five Star Reviews Site. (https://www.fivestarreviewssite.com/)
Iconic Rating Developer Profile
4 plugins · 110 total installs
How We Detect Iconic Rating
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/iconic-rating/css/hover2d-min.css/wp-content/plugins/iconic-rating/css/style.css/wp-content/plugins/iconic-rating/js/iconicr.js/wp-content/plugins/iconic-rating/css/admin_style.css/wp-content/plugins/iconic-rating/js/backend.js//maxcdn.bootstrapcdn.com/font-awesome/4.4.0/css/font-awesome.min.cssiconicr_hvr_styleiconicr_styleiconicr_jsiconicr_admin_stylebackend_jsHTML / DOM Fingerprints
iconicr-voteiconicr-rating-div<!-- AJAX for visitors and users --><!-- HANDLER function --><!-- ***************************** --><!-- HANDLE AJAX requests -->+5 moredata-iddata-actioniconicr_reqs_callbackiconicr_get_options