
kk Star Ratings – Rate Post & Collect User Feedbacks Security & Risk Analysis
wordpress.org/plugins/kk-star-ratingskk Star Ratings allows blog visitors to involve and interact more effectively with your website by rating posts.
Is kk Star Ratings – Rate Post & Collect User Feedbacks Safe to Use in 2026?
Generally Safe
Score 96/100kk Star Ratings – Rate Post & Collect User Feedbacks has a strong security track record. Known vulnerabilities have been patched promptly.
The kk-star-ratings plugin version 5.4.10.4 exhibits a mixed security posture. The static analysis reveals a seemingly small attack surface, with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are directly exposed without authentication or proper permission checks. The absence of file operations and external HTTP requests further reduces immediate threat vectors. However, the code signals raise some concerns regarding SQL query security, with a significant portion not utilizing prepared statements, and a moderate percentage of output not being properly escaped. The presence of four known CVEs, including one high-severity vulnerability and three medium-severity ones, despite none being currently unpatched, indicates a history of security flaws. The common vulnerability types such as 'Code Injection', 'Race Condition', and 'Missing Authorization' are particularly worrying and suggest recurring issues in how the plugin handles user input and manages access control. While the plugin has recently addressed past vulnerabilities, its historical pattern warrants continued vigilance.
Key Concerns
- High number of known CVEs historically
- Medium severity vulnerabilities in history
- Significant SQL queries not prepared
- Moderate percentage of unescaped output
- Bundled outdated Freemius library v1.0
kk Star Ratings – Rate Post & Collect User Feedbacks Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
kk Star Ratings – Rate Post & Collect User Feedbacks <= 5.4.10 - Unauthenticated Arbitrary Shortcode Execution
kk Star Ratings <= 5.4.5 - Race Condition to Multiple User Voting
kk Star Ratings <= 5.4.5 - Missing Authorization
kk Star Ratings <= 5.4.3 - IP Spoofing to Protection Mechanism Bypass
kk Star Ratings – Rate Post & Collect User Feedbacks Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
kk Star Ratings – Rate Post & Collect User Feedbacks Attack Surface
WordPress Hooks 6
Maintenance & Trust
kk Star Ratings – Rate Post & Collect User Feedbacks Maintenance & Trust
Maintenance Signals
Community Trust
kk Star Ratings – Rate Post & Collect User Feedbacks Alternatives
Helpful – Article Feedback Plugin
daext-helpful
Easily add a "Was it helpful?" survey on your blog or knowledge base pages with this article feedback plugin.
Idea Factory
idea-factory
Front end submission and voting system.
WP likes
wp-likes
WP Likes lets your blog visitors 'like' your posts on the go.
Vote It Up
vote-it-up
The Vote It Up plugin enables visitors to vote for and against posts.
OpinionCamp – Poll Block
opinioncamp
OpinionCamp is a block-based poll plugin for WordPress that lets you collect polls, votes, and opinions directly inside the Gutenberg editor.
kk Star Ratings – Rate Post & Collect User Feedbacks Developer Profile
5 plugins · 260K total installs
How We Detect kk Star Ratings – Rate Post & Collect User Feedbacks
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/kk-star-ratings/lib/public/css/kk-star-ratings.css/wp-content/plugins/kk-star-ratings/lib/public/css/kk-star-ratings.min.css/wp-content/plugins/kk-star-ratings/lib/public/js/kk-star-ratings.js/wp-content/plugins/kk-star-ratings/lib/public/js/kk-star-ratings.min.js/wp-content/plugins/kk-star-ratings/lib/public/js/kksr-migrations.js/wp-content/plugins/kk-star-ratings/lib/public/js/kksr-migrations.min.jshttps://cdn.jsdelivr.net/npm/alpinejs@3.x.x/dist/cdn.min.jskk-star-ratings/version=5.4.10.4kksr-migrations/version=5.4.10.4HTML / DOM Fingerprints
kksr-star-ratingdata-kksr-disabledkk_star_ratings/wp-json/kk-star-ratings