
Post Ratings Security & Risk Analysis
wordpress.org/plugins/post-ratingsSimple, developer-friendly, straightforward post rating plugin. Relies on post meta to store avg. rating / vote count.
Is Post Ratings Safe to Use in 2026?
Generally Safe
Score 85/100Post Ratings has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'post-ratings' v3.0 plugin exhibits a generally positive security posture, with no known vulnerabilities and a well-defined attack surface. The absence of SQL injection risks due to prepared statements and a lack of file operations or external HTTP requests are strong indicators of good development practices. However, a significant concern arises from the low percentage of properly escaped output. With 37 output operations and only 22% properly escaped, there's a high likelihood of Cross-Site Scripting (XSS) vulnerabilities being present, especially since taint analysis did not find any flows to analyze. The lack of explicit nonce checks on its AJAX handlers, while categorized as 'Unprotected: 0' in the attack surface, still presents a potential area for brute-force or automated attacks if not adequately protected by other means (e.g., capability checks). The plugin's clean vulnerability history is encouraging, suggesting it has been maintained with security in mind, but the current static analysis findings on output escaping warrant immediate attention.
Key Concerns
- Low percentage of properly escaped output
- Missing nonce checks on AJAX handlers
Post Ratings Security Vulnerabilities
Post Ratings Code Analysis
Output Escaping
Post Ratings Attack Surface
AJAX Handlers 2
Shortcodes 2
WordPress Hooks 18
Maintenance & Trust
Post Ratings Maintenance & Trust
Maintenance Signals
Community Trust
Post Ratings Alternatives
kk Star Ratings – Rate Post & Collect User Feedbacks
kk-star-ratings
kk Star Ratings allows blog visitors to involve and interact more effectively with your website by rating posts.
WP-PostRatings
wp-postratings
Adds an AJAX rating system for your WordPress site's content.
Kento Star Rate
kento-star-rate
Ajax Five Star Ratings for Post, Page or Excerpt
Pixelpost Importer
pixelpost-importer
Import your PixelPost database in WordPress (categories, posts, comments, and ratings).
Wp Post Rating
wp-post-rating
WP-POST-RATING is powerful rating plugin with ajax security requests.
Post Ratings Developer Profile
2 plugins · 800 total installs
How We Detect Post Ratings
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/post-ratings/assets/css/frontend.css/wp-content/plugins/post-ratings/assets/js/frontend.js/wp-content/plugins/post-ratings/assets/js/frontend.jspost-ratings/assets/css/frontend.css?ver=post-ratings/assets/js/frontend.js?ver=HTML / DOM Fingerprints
post-ratings-widget-wrapperpost-ratings-item-wrapperpost-ratings-averagepost-ratings-countpost-ratings-itempost-ratings-starpost-ratings-star-emptypost-ratings-star-filleddata-post-iddata-ratingdata-max-ratingdata-rate-noncepost_ratings_params[rate][top_rated]