
Rate Star Review Vote – AJAX Reviews, Votes, Star Ratings Security & Risk Analysis
wordpress.org/plugins/rate-star-reviewBoost engagement with AJAX-driven star ratings, reviews, vote buttons for content.
Is Rate Star Review Vote – AJAX Reviews, Votes, Star Ratings Safe to Use in 2026?
Generally Safe
Score 91/100Rate Star Review Vote – AJAX Reviews, Votes, Star Ratings has a strong security track record. Known vulnerabilities have been patched promptly.
The rate-star-review v1.6.4 plugin exhibits a mixed security posture. While it demonstrates good practices by utilizing prepared statements for all SQL queries and has no known critical or high severity vulnerabilities currently unpatched, there are significant concerns regarding its attack surface. A substantial portion of its AJAX handlers lack proper authentication checks, presenting a clear risk. The static analysis reveals that 6 out of 12 entry points are unprotected. Furthermore, 3 out of 6 analyzed taint flows have unsanitized paths, which, although not classified as critical or high severity in this analysis, warrants attention as it indicates potential input sanitization weaknesses. The vulnerability history shows 2 medium severity CVEs related to Cross-site Scripting in the past, suggesting that while these have been addressed, the plugin has had issues with input sanitization and output escaping previously. The plugin also has a moderate percentage of improperly escaped outputs (22%). Overall, the plugin has strengths in its database interaction and has addressed past vulnerabilities, but the unprotected AJAX endpoints and the presence of unsanitized taint flows are significant security weaknesses that need immediate attention.
Key Concerns
- AJAX handlers without authentication checks
- Taint flows with unsanitized paths
- Improperly escaped outputs
- Medium severity vulnerabilities in history
Rate Star Review Vote – AJAX Reviews, Votes, Star Ratings Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Rate Star Review Vote – AJAX Reviews, Votes, Star Ratings <= 1.6.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
Rate Star Review <= 1.5.1 - Reflected Cross-Site Scripting
Rate Star Review Vote – AJAX Reviews, Votes, Star Ratings Code Analysis
Output Escaping
Data Flow Analysis
Rate Star Review Vote – AJAX Reviews, Votes, Star Ratings Attack Surface
AJAX Handlers 6
Shortcodes 6
WordPress Hooks 5
Maintenance & Trust
Rate Star Review Vote – AJAX Reviews, Votes, Star Ratings Maintenance & Trust
Maintenance Signals
Community Trust
Rate Star Review Vote – AJAX Reviews, Votes, Star Ratings Alternatives
kk Star Ratings – Rate Post & Collect User Feedbacks
kk-star-ratings
kk Star Ratings allows blog visitors to involve and interact more effectively with your website by rating posts.
Iconic Rating
iconic-rating
Review or rating any post type, with stars or other awesome icons, adding some effects on hover (and tooltips).
Kento Star Rate
kento-star-rate
Ajax Five Star Ratings for Post, Page or Excerpt
Multi Rating & Review Matrix System
rating-review-matrix
IMPORTANT UPGRADE INFO 1.0.4 to 1.0.5
AJAX Thumbnail Rebuild
ajax-thumbnail-rebuild
AJAX Thumbnail Rebuild allows you to rebuild all thumbnails at once without script timeouts on your server.
Rate Star Review Vote – AJAX Reviews, Votes, Star Ratings Developer Profile
12 plugins · 1K total installs
How We Detect Rate Star Review Vote – AJAX Reviews, Votes, Star Ratings
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/rate-star-review/scripts/semantic/semantic.min.css/wp-content/plugins/rate-star-review/scripts/semantic/semantic.min.jshttps://cdn.jsdelivr.net/npm/fomantic-ui@2.8.7/dist/semantic.min.csshttps://cdn.jsdelivr.net/npm/fomantic-ui@2.8.7/dist/semantic.min.jsHTML / DOM Fingerprints
uiyellowlargestarratingreadonlycardright+2 moredata-ratingdata-max-ratingVWrateStarReview/wp-json/vwrsr_vote/wp-json/vwrsr_review/wp-json/vwrsr_reviews[videowhisper_vote][videowhisper_review][videowhisper_reviews][videowhisper_rating]