
Rate This Site Security & Risk Analysis
wordpress.org/plugins/rate-this-siteCreate rate this site in your site.
Is Rate This Site Safe to Use in 2026?
Generally Safe
Score 85/100Rate This Site has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'rate-this-site' plugin v1.0 exhibits a mixed security posture. On the positive side, it has no known CVEs and doesn't perform file operations or external HTTP requests. However, the static analysis reveals significant areas of concern. A substantial portion of its output is not properly escaped, posing a risk of cross-site scripting (XSS) vulnerabilities. Furthermore, the taint analysis identified two flows with unsanitized paths, indicating potential for injection attacks, particularly given the absence of nonce checks and a single, potentially insufficient, capability check. The plugin's reliance on raw SQL queries, even with a high percentage of prepared statements, still presents a residual risk for SQL injection if the limited number of non-prepared queries handle user-supplied data.
While the plugin has a clean vulnerability history, this doesn't negate the risks identified in the current code analysis. The lack of proper output escaping and the unsanitized taint flows are critical weaknesses that could be exploited. The absence of nonce checks on its single entry point (the shortcode) is a notable oversight. Overall, the plugin has some good security foundations but suffers from critical flaws in input sanitization and output escaping, requiring immediate attention.
Key Concerns
- High percentage of unescaped output
- Taint flow with unsanitized path (High severity)
- Taint flow with unsanitized path (High severity)
- No nonce checks on entry points
- Limited capability checks on entry points
- SQL queries without prepared statements
Rate This Site Security Vulnerabilities
Rate This Site Release Timeline
Rate This Site Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Rate This Site Attack Surface
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
Rate This Site Maintenance & Trust
Maintenance Signals
Community Trust
Rate This Site Alternatives
Smart Sitemap Generator
smart-sitemap-generator
Smart Sitemap Generator is a simple plugin that allows you to intelligently generate XML Sitemap outputs of your posts, pages and products automatical …
All-in-One WP Migration and Backup
all-in-one-wp-migration
Trusted by 60M+ sites: The gold standard for WordPress migration and backup. Migrate, backup, and restore your WordPress site with one click.
ManageWP Worker
worker
A better way to manage dozens of WordPress websites.
WPvivid — Backup, Migration & Staging
wpvivid-backuprestore
Migrate, staging, backup WordPress, all in one.
Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns
essential-blocks
Gutenberg block editor with AI. 70+ Gutenberg blocks, patterns, WooCommerce blocks, post grid, gallery, menu with Gutenberg block library.
Rate This Site Developer Profile
11 plugins · 60 total installs
How We Detect Rate This Site
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/rate-this-site/assets/css/rate-this-site.cssHTML / DOM Fingerprints
front-rts-graph[wp-rate-this-site-plugin]