
NS Product Rating for WooCommerce Security & Risk Analysis
wordpress.org/plugins/ns-product-rating-for-woocommerceAdd rating to your product and view a report
Is NS Product Rating for WooCommerce Safe to Use in 2026?
Generally Safe
Score 85/100NS Product Rating for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "ns-product-rating-for-woocommerce" v1.2.5 exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries, utilizing prepared statements exclusively, and has no recorded vulnerabilities or CVEs in its history, suggesting a commitment to security. The absence of file operations and dangerous functions further strengthens its security foundation.
However, several concerns arise from the static analysis. The presence of two unprotected AJAX handlers presents a significant attack surface, as actions triggered by these handlers could be executed by unauthenticated users. While the taint analysis shows no critical or high-severity unsanitized paths, the fact that all four analyzed flows have unsanitized paths is a notable weakness. Additionally, only 9% of output operations are properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities, especially given the number of outputs and the potential for malicious data to be injected through the unprotected AJAX endpoints.
In conclusion, while the plugin benefits from a clean vulnerability history and secure SQL practices, the unprotected AJAX endpoints and widespread output escaping issues create substantial security risks. The plugin needs urgent attention to address these weaknesses to prevent potential exploitation.
Key Concerns
- Unprotected AJAX handlers
- Low percentage of properly escaped output
- Flows with unsanitized paths
- Lack of capability checks
NS Product Rating for WooCommerce Security Vulnerabilities
NS Product Rating for WooCommerce Release Timeline
NS Product Rating for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
NS Product Rating for WooCommerce Attack Surface
AJAX Handlers 4
WordPress Hooks 21
Maintenance & Trust
NS Product Rating for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
NS Product Rating for WooCommerce Alternatives
WP Rate And Review
wp-rate-and-review
WP Rate And Review enhances your WooCommerce product pages by displaying attractive and customizable rating and review summaries.
Crowdsignal Dashboard – Polls, Surveys & more
polldaddy
Manage your Crowdsignal polls, surveys, quizzes, and ratings directly from the WordPress dashboard.
WP-PostRatings
wp-postratings
Adds an AJAX rating system for your WordPress site's content.
Trusted Shops Easy Integration for WooCommerce
trusted-shops-easy-integration-for-woocommerce
Show that your customers love you with reviews in your online store and boost your business with the free Trusted Shops Easy Integration Plugin for Wo …
Like Button Rating ♥ LikeBtn
likebtn-like-button
Add Like button to posts, pages, comments, WooCommerce, BuddyPress, bbPress, UM, custom posts! Sort content by likes! Get instant stats and insights!
NS Product Rating for WooCommerce Developer Profile
24 plugins · 4K total installs
How We Detect NS Product Rating for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ns-product-rating-for-woocommerce/ns_product_rating_woocommerce.style.phpHTML / DOM Fingerprints
ns_product_rating_woocommerce_nonce