
Kiyoh Reviews Security & Risk Analysis
wordpress.org/plugins/kiyoh-reviewsIntegrate Kiyoh reviews with your WooCommerce store. Automatically send review invitations and display product reviews.
Is Kiyoh Reviews Safe to Use in 2026?
Generally Safe
Score 100/100Kiyoh Reviews has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "kiyoh-reviews" v1.0.0 plugin exhibits a generally strong security posture, with notable strengths in its handling of SQL queries and output escaping. The absence of known CVEs and recorded vulnerability history further suggests a stable and well-maintained codebase in these areas. The use of prepared statements for all SQL queries and a high percentage of properly escaped output are excellent security practices that significantly mitigate common web application vulnerabilities.
However, the plugin is not without its concerns. The static analysis reveals an attack surface consisting of two AJAX handlers, one of which lacks authentication checks. This unprotected AJAX endpoint represents a direct vulnerability that could be exploited by unauthenticated users, potentially leading to unintended actions or information disclosure depending on its functionality. While taint analysis found no flows, this is based on zero flows being analyzed, offering no assurance of security in that regard. The presence of bundled libraries, even if seemingly up-to-date, can introduce vulnerabilities if not managed carefully and could become a future concern.
Overall, the plugin's proactive approach to SQL and output sanitization is commendable. The primary weakness lies in the unprotected AJAX handler, which demands immediate attention. The lack of taint analysis and the potential for bundled library issues, while not immediate critical risks, indicate areas where further scrutiny would be beneficial for comprehensive security.
Key Concerns
- Unprotected AJAX handler
- Taint analysis not performed
- Bundled library (Freemius v1.0)
Kiyoh Reviews Security Vulnerabilities
Kiyoh Reviews Code Analysis
Bundled Libraries
Output Escaping
Kiyoh Reviews Attack Surface
AJAX Handlers 2
WordPress Hooks 25
Scheduled Events 2
Maintenance & Trust
Kiyoh Reviews Maintenance & Trust
Maintenance Signals
Community Trust
Kiyoh Reviews Alternatives
WPSSO Ratings and Reviews
wpsso-ratings-and-reviews
Adds Ratings and Reviews Features to the WordPress Comments System.
Reviewbird
reviewbird
Powerfully simple product review collection, moderation, and management for WooCommerce.
Site Reviews
site-reviews
Site Reviews is a complete review management solution that integrates with WooCommerce and SureCart and works similarly to reviews on Amazon, Tripadvi …
Photo Reviews for WooCommerce
woo-photo-reviews
Let customers attach photos to reviews, enhanced with filterable grids and overall ratings. Auto-send review reminders and coupon emails
ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema
reviewx
Drive woocommerce business growth with social proof: gather product reviews with multicriteria ratings, auto-reminder emails, discounts, and more.
Kiyoh Reviews Developer Profile
1 plugin · 10 total installs
How We Detect Kiyoh Reviews
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/kiyoh-reviews/assets/css/admin.css/wp-content/plugins/kiyoh-reviews/assets/js/admin-settings.js/wp-content/plugins/kiyoh-reviews/assets/js/admin-settings.jskiyoh-adminkiyoh-admin-settingsHTML / DOM Fingerprints
kiyoh-settings-sectiondata-tab-iddata-tab-namekiyohSettings