
My Review Security & Risk Analysis
wordpress.org/plugins/my-reviewMy Review plugin helps you format your post as a review.
Is My Review Safe to Use in 2026?
Generally Safe
Score 85/100My Review has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "my-review" plugin v1.2 exhibits a concerning security posture primarily due to a complete lack of output escaping. While the static analysis reveals no dangerous functions, SQL injection vulnerabilities via prepared statements, file operations, external requests, or taint flows, and the vulnerability history is clean, the absence of output escaping is a critical weakness. This means any user-provided input that is displayed back to users could potentially be exploited to inject malicious code, such as JavaScript, leading to cross-site scripting (XSS) attacks. The plugin also has no detectable attack surface points, which is a strength, but this could be misleading if the plugin relies on internal functions or indirectly exposed data that isn't flagged as an entry point by the static analysis. Given the lack of direct vulnerabilities found in code and history, the immediate risks are lower, but the unescaped output represents a significant latent vulnerability that needs immediate attention.
Key Concerns
- Output escaping is not implemented
My Review Security Vulnerabilities
My Review Release Timeline
My Review Code Analysis
Output Escaping
My Review Attack Surface
WordPress Hooks 5
Maintenance & Trust
My Review Maintenance & Trust
Maintenance Signals
Community Trust
My Review Alternatives
Public Post Preview
public-post-preview
Allow anonymous users to preview a draft of a post before it is published.
Performant Translations
performant-translations
Making internationalization/localization in WordPress faster than ever before.
Public Post Preview Configurator
public-post-preview-configurator
Enables you to configure the 'public post preview' plugin with a user interface.
Preferred Languages
preferred-languages
Choose languages for displaying WordPress in, in order of preference.
Post Draft Preview
post-draft-preview
Allow non logged-in users to check a draft of unpublished post by using secret link
My Review Developer Profile
1 plugin · 10 total installs
How We Detect My Review
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/my-review/rw.cssHTML / DOM Fingerprints
<!-- rw_good --><!-- /rw_good --><!-- rw_bad --><!-- /rw_bad -->+4 more