Product Reviews from rateit.cool for Woocommerce Security & Risk Analysis

wordpress.org/plugins/rateitcool

Together to more sales. 65% more sales with many product reviews for each product. Show the product reviews everywhere you want.

10 active installs v1.0.3 PHP + WP 3.5.1+ Updated Oct 17, 2017
reviewsuser-generated-contentwoocommercewoocommerce-product-reviewswoocommerce-reviews
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Product Reviews from rateit.cool for Woocommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Product Reviews from rateit.cool for Woocommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The rateitcool plugin v1.0.3 exhibits a mixed security posture. On the positive side, the plugin demonstrates strong adherence to secure coding practices by utilizing prepared statements for all its SQL queries and implementing nonce and capability checks on its entry points. The complete absence of known CVEs and a history free of past vulnerabilities are also significant strengths, suggesting a generally well-maintained codebase. However, a critical concern arises from the static analysis results: 100% of its 25 output operations are not properly escaped. This lack of output sanitization presents a significant risk for cross-site scripting (XSS) vulnerabilities, as user-supplied data displayed on the frontend could be executed as malicious scripts.

Further analysis reveals a concerning taint flow. Out of two flows analyzed, one involved an unsanitized path, indicating a potential for data to be processed without adequate security measures. While the severity of this specific flow wasn't categorized as critical or high, the presence of an unsanitized path in conjunction with widespread unescaped output points to a significant risk of code injection or other data manipulation vulnerabilities if user input is incorporated into these insecure output contexts. The plugin's limited attack surface (zero AJAX, REST API, shortcodes, and cron events) is a mitigating factor, but the identified output escaping and taint analysis issues require immediate attention to ensure user data and the website's integrity are protected.

Key Concerns

  • Unescaped output across all operations
  • Flow with unsanitized path
Vulnerabilities
None known

Product Reviews from rateit.cool for Woocommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Product Reviews from rateit.cool for Woocommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
25
0 escaped
Nonce Checks
3
Capability Checks
4
File Operations
3
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

0% escaped25 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
wc_proccess_rateitcool_settings (templates\wc-rateitcool-settings.php:327)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Product Reviews from rateit.cool for Woocommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 15
actionplugins_loadedwc_rateitcool.php:13
actioninitwc_rateitcool.php:14
actionwp_headwc_rateitcool.php:23
actionadmin_menuwc_rateitcool.php:45
actionwp_enqueue_scriptswc_rateitcool.php:50
actiontemplate_redirectwc_rateitcool.php:51
actionadmin_enqueue_scriptswc_rateitcool.php:65
actionwoocommerce_order_details_after_order_tablewc_rateitcool.php:69
actionwoocommerce_order_items_tablewc_rateitcool.php:125
filtercomments_openwc_rateitcool.php:195
actionwoocommerce_after_single_productwc_rateitcool.php:198
actionwoocommerce_product_tabswc_rateitcool.php:201
actionwoocommerce_single_product_summarywc_rateitcool.php:204
actionwoocommerce_after_shop_loop_item_titlewc_rateitcool.php:209
filterwoocommerce_tab_manager_integration_tab_allowedwc_rateitcool.php:560
Maintenance & Trust

Product Reviews from rateit.cool for Woocommerce Maintenance & Trust

Maintenance Signals

WordPress version tested4.1.42
Last updatedOct 17, 2017
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Product Reviews from rateit.cool for Woocommerce Developer Profile

Thomas Gravel

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Product Reviews from rateit.cool for Woocommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/rateitcool/rateitcool.php/wp-content/plugins/rateitcool/classes/class-wc-rateitcool-export-reviews.php/wp-content/plugins/rateitcool/lib/rateitcool-api/RateItCool.php/wp-content/plugins/rateitcool/assets/images/logo_small.png
Version Parameters
rateitcool/rateitcool.php?ver=rateitcool/assets/images/logo_small.png?ver=

HTML / DOM Fingerprints

CSS Classes
rateit-cool-feedback-formrate-it-cool-feedback-formrateit-cool-shop-reviewsstar-ratingrate-it-cool-review-summaryrateit-cool-star-textfeedback-titlefeedback-content+5 more
Data Attributes
data-feedbackidname="shopfeedbackform"name="gpntype"name="gpnvalue"name="language"name="stars"+6 more
Shortcode Output
<meta name="rateit-cool-site-verification" content="<div class="rateit-cool-feedback-form"><a href="#" data-feedbackid="rateit-cool-shop-reviews"><div style="display:none;" id="rateit-cool-shop-reviews"><h3>
FAQ

Frequently Asked Questions about Product Reviews from rateit.cool for Woocommerce