
Rating Assessor Security & Risk Analysis
wordpress.org/plugins/rating-assessorA custom rating system plugin with multi-question assessments, score calculation, graphical result display, and email notifications.
Is Rating Assessor Safe to Use in 2026?
Generally Safe
Score 100/100Rating Assessor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "rating-assessor" plugin v1.0 demonstrates a generally positive security posture based on the provided static analysis and vulnerability history. The absence of known CVEs, critical taint flows, and direct SQL queries is a strong indicator of good development practices. The fact that all SQL queries utilize prepared statements and there are no file operations or external HTTP requests further enhances its security profile. The presence of a nonce check is also a positive sign for AJAX handlers.
However, there are areas for improvement. The low percentage of properly escaped output (40%) suggests a potential risk of cross-site scripting (XSS) vulnerabilities if user-supplied data is not sufficiently sanitized before being displayed to users. Additionally, the complete lack of capability checks on the AJAX handlers means that any user, regardless of their role or permissions, could potentially trigger these functions. While the attack surface is small, the absence of permission checks on entry points is a notable concern.
In conclusion, the plugin benefits from a clean vulnerability history and the use of prepared statements for database interactions. The primary weaknesses lie in the insufficient output escaping and the lack of capability checks on AJAX actions, which could expose the application to certain types of attacks if exploited. Addressing these areas would significantly bolster the plugin's overall security.
Key Concerns
- Insufficient output escaping (40%)
- No capability checks on AJAX handlers
Rating Assessor Security Vulnerabilities
Rating Assessor Code Analysis
Output Escaping
Rating Assessor Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 8
Maintenance & Trust
Rating Assessor Maintenance & Trust
Maintenance Signals
Community Trust
Rating Assessor Alternatives
Easy Rating Assessor
easy-rating-assessor
A custom rating system plugin with multi-question assessments, score calculation, graphical result display, and email notifications.
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker
quiz-master-next
Create quizzes, surveys, and tests easily on WordPress with this versatile plugin. Perfect for engaging any audience and gathering valuable insights!
PressPrimer Quiz – AI Quiz Maker, Exam Builder & LMS Assessment Plugin
pressprimer-quiz
Enterprise-grade quiz builder plugin with AI question generation, LMS integration, and beautiful themes. Free forever.
3task Polls – Surveys, Quizzes & Voting
3task-polls
Create polls, surveys, quizzes and voting for WordPress. AJAX-based, GDPR-compliant, Gutenberg block included. 4 poll types and 5 themes.
PlayQuizNow
playquiznow
Embed interactive quizzes from PlayQuizNow into your WordPress site with a shortcode or Gutenberg block.
Rating Assessor Developer Profile
9 plugins · 980 total installs
How We Detect Rating Assessor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/rating-assessor/assets/css/style.css/wp-content/plugins/rating-assessor/assets/js/rating-form.js/wp-content/plugins/rating-assessor/assets/js/rating-form.jsHTML / DOM Fingerprints
wpra-rating-formwpra-stepwpra-step-0wpra-nextwpra-step-1wpra-step-2wpra-step-3wpra-step-4+3 morewpra_assigned_setwpra_question_metawpra_ajax<div id="wpra-rating-form"><form id="ratingForm"><div class="wpra-step wpra-step-0"><button type="button" class="wpra-next">Start Now</button>