
Proofratings Security & Risk Analysis
wordpress.org/plugins/proofratingsDisplay social proof ratings on your website. Boost your website sales and conversion rate.
Is Proofratings Safe to Use in 2026?
Generally Safe
Score 100/100Proofratings has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'proofratings' plugin v1.1.9 exhibits a concerning security posture primarily due to a significant number of unprotected entry points. With 11 out of 16 total entry points lacking authentication or permission checks, this plugin exposes a large attack surface to unauthenticated users, increasing the risk of unauthorized actions. While the plugin demonstrates good practices in using prepared statements for SQL queries and has a history free of reported vulnerabilities, these strengths are overshadowed by the critical lack of access control on its AJAX handlers and REST API routes. The taint analysis did not reveal critical or high severity vulnerabilities, which is positive, but the presence of unsanitized paths in the analyzed flows warrants attention, especially given the unprotected entry points. The plugin's lack of bundled libraries and a clean vulnerability history are notable strengths, but the fundamental security flaws in its access control mechanisms present a substantial risk that needs to be addressed.
Key Concerns
- Unprotected AJAX handlers
- Unprotected REST API routes
- Unsanitized paths in taint analysis
- Low capability check coverage
Proofratings Security Vulnerabilities
Proofratings Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Proofratings Attack Surface
AJAX Handlers 7
REST API Routes 4
Shortcodes 5
WordPress Hooks 41
Maintenance & Trust
Proofratings Maintenance & Trust
Maintenance Signals
Community Trust
Proofratings Alternatives
Reviews Widgets for Google & 45+ platforms by Repuso
social-testimonials-and-reviews-widget
Collect social proof reviews, showcase on your website. Boost your website sales and conversion rate.
Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More
reviews-feed
No API key required. Display Yelp and Google reviews for any business in a clean, customizable feed on your site.
Rich Showcase for Google Reviews
widget-google-reviews
Display up to 10 Google reviews in less than a minute. Continue collecting new reviews. No limits on connected places, widgets, shortcodes and blocks.
Strong Testimonials
strong-testimonials
An easy-to-use testimonial plugin to collect and show customer feedback in WordPress
Site Reviews
site-reviews
Site Reviews is a complete review management solution that integrates with WooCommerce and SureCart and works similarly to reviews on Amazon, Tripadvi …
Proofratings Developer Profile
1 plugin · 0 total installs
How We Detect Proofratings
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/proofratings/assets/css/proofratings-dashboard.css/wp-content/plugins/proofratings/assets/js/popper.min.js/wp-content/plugins/proofratings/assets/js/tippy.js/wp-content/plugins/proofratings/assets/js/proofratings-dashboard.js/wp-content/plugins/proofratings/assets/js/popper.min.js/wp-content/plugins/proofratings/assets/js/tippy.js/wp-content/plugins/proofratings/assets/js/proofratings-dashboard.jsproofratings/assets/css/proofratings-dashboard.css?ver=proofratings/assets/js/proofratings-dashboard.js?ver=HTML / DOM Fingerprints
screen-proofratingsdata-daysproofratings