
Rate this Author Security & Risk Analysis
wordpress.org/plugins/rate-this-authorThis is a very simple and lightweight Plugin for rating authors by visitors.
Is Rate this Author Safe to Use in 2026?
Generally Safe
Score 100/100Rate this Author has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "rate-this-author" v1.4 plugin presents a significant security risk due to a lack of robust access control for its AJAX endpoints. The static analysis reveals a substantial attack surface with 6 AJAX handlers, all of which lack authentication checks. This means any user, including unauthenticated ones, can trigger these actions, potentially leading to unauthorized modifications or data exposure.
The taint analysis further exacerbates this concern, showing 6 flows with unsanitized paths, all categorized as high severity. This indicates that user-supplied input is being processed in a way that could lead to serious security vulnerabilities, such as cross-site scripting (XSS) or even remote code execution, if not properly handled. The low percentage of properly escaped output (16%) also suggests a high likelihood of XSS vulnerabilities.
While the plugin has no recorded vulnerability history, this does not imply it is secure. The current state of the code, with its unprotected AJAX endpoints and unsanitized data flows, creates a fertile ground for new vulnerabilities to emerge. The complete absence of nonce checks on AJAX handlers is a major oversight. The plugin's sole capability check is insufficient given the number of unprotected entry points. The overall security posture is poor, with critical weaknesses in input validation and access control outweighing any perceived strengths.
Key Concerns
- AJAX handlers without auth checks
- High severity taint flows (6)
- Low output escaping percentage
- No nonce checks on AJAX
- Limited capability checks
- SQL queries not using prepared statements
Rate this Author Security Vulnerabilities
Rate this Author Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Rate this Author Attack Surface
AJAX Handlers 6
WordPress Hooks 8
Maintenance & Trust
Rate this Author Maintenance & Trust
Maintenance Signals
Community Trust
Rate this Author Alternatives
Author Post Ratings
author-post-ratings
Allows a post author to assign a simple 1-5 star rating to a post, page, or custom post type, which will then be displayed on the post.
GD Rating System
gd-rating-system
Powerful, highly customizable and versatile ratings plugin to allow your users to vote for anything you want.
REVIEWS.io for WooCommerce
reviewscouk-for-woocommerce
REVIEWS.io, helps eCommerce merchants to collect & display verified product and company reviews. A Google Licensed partner.
Stars Rating
stars-rating
A plugin to turn comments into reviews by adding rating feature.
Five-Star Ratings Shortcode
five-star-ratings-shortcode
Simple lightweight shortcode to add 5-star ratings anywhere.
Rate this Author Developer Profile
1 plugin · 10 total installs
How We Detect Rate this Author
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/rate-this-author/main_rtl.css/wp-content/plugins/rate-this-author/main.css/wp-content/plugins/rate-this-author/mScroll/jquery.mCustomScrollbar.css/wp-content/plugins/rate-this-author/jquery-js.js/wp-content/plugins/rate-this-author/rating_simple.js/wp-content/plugins/rate-this-author/mScroll/jquery.mCustomScrollbar.concat.min.js/wp-content/plugins/rate-this-author/includes/admin/admin_rtl.css/wp-content/plugins/rate-this-author/includes/admin/admin.css+1 morehttp://fonts.googleapis.com/css?family=Open+Sans:300italic,400italic,700italic,400,700,300//fonts.googleapis.com/css?family=Open+Sans:300italic,400italic,700italic,400,700,300rate-this-author/main_rtl.css?ver=rate-this-author/main.css?ver=rate-this-author/mScroll/jquery.mCustomScrollbar.css?ver=rate-this-author/jquery-js.js?ver=rate-this-author/rating_simple.js?ver=rate-this-author/mScroll/jquery.mCustomScrollbar.concat.min.js?ver=rate-this-author/includes/admin/admin_rtl.css?ver=rate-this-author/includes/admin/admin.css?ver=rate-this-author/includes/admin/admin.js?ver=HTML / DOM Fingerprints
rate_this_authorwhite_contenthidepoppop_up_formform_titleauthor_namestripe-lineerror_msg+3 moreid="thumbnail_upload"name="visitor_name"id="visitor_name"name="visitor_email"id="visitor_email"dynamicPathurl