
Rating Builder Security & Risk Analysis
wordpress.org/plugins/rating-builderA simple WordPress rating builder supports any post type. Build rating system for your post, product or any custom post.
Is Rating Builder Safe to Use in 2026?
Generally Safe
Score 85/100Rating Builder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "rating-builder" plugin version 1.0.3 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by utilizing prepared statements for all SQL queries and properly escaping a high percentage of its output. There are no known vulnerabilities or CVEs associated with this plugin, suggesting a generally well-maintained codebase.
However, significant security concerns are present due to the unprotected attack surface. The plugin exposes two AJAX handlers that lack any authentication or capability checks. This means any unauthenticated user could potentially trigger these handlers, opening the door to various exploits if these handlers are not inherently secure in their implementation (which static analysis alone cannot fully determine).
Despite the lack of identified taint flows and dangerous functions, the unprotected AJAX endpoints represent a critical weakness. While the plugin has a clean vulnerability history, this is not a guarantee of future security. The absence of nonces and capability checks on these entry points is a clear oversight. Overall, the plugin has a strong foundation in terms of SQL and output sanitization, but the critical lack of access control on its AJAX endpoints significantly elevates its risk profile.
Key Concerns
- AJAX handlers without auth checks
- AJAX handlers without capability checks
- No nonce checks on AJAX entry points
- Unescaped output (15% of total)
Rating Builder Security Vulnerabilities
Rating Builder Code Analysis
Output Escaping
Rating Builder Attack Surface
AJAX Handlers 2
WordPress Hooks 12
Maintenance & Trust
Rating Builder Maintenance & Trust
Maintenance Signals
Community Trust
Rating Builder Alternatives
Stars Rating
stars-rating
A plugin to turn comments into reviews by adding rating feature.
Rate
rate
Most ratings plugins contain too much code: inline JavaScript, messy markup, weird CSS. Rate is simple, hardly intrusive, and completely overridable.
Insert post from front-end with featured image
insert-post-from-front-end-with-featured-image
This plugin is created for insert post from front-end, Using this plugin we can insert any type of post from front-end with featured image.
Integration for BazaarVoice
integration-for-baazarvoice
An plugin that will integrate with the Bazaarvoice rating system.
weeComments – Shop & Products Reviews
weecomments
Genera confianza en tu tienda online y aumenta las ventas con weecomments. http://weecomments.com Muestra un widget de opiniones de la tienda online, …
Rating Builder Developer Profile
5 plugins · 300 total installs
How We Detect Rating Builder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/rating-builder/assets/dist/vendor/css/redq-rating-builder-style.css/wp-content/plugins/rating-builder/assets/dist/vendor/css/magnific-popup.css/wp-content/plugins/rating-builder/assets/dist/vendor/magnific-popup.js/wp-content/plugins/rating-builder/assets/dist/vendor/wp-rating-custom.js/wp-content/plugins/rating-builder/assets/dist/vendor/media-upload.js/wp-content/plugins/rating-builder/assets/dist/vendor/css/redq-review.css/wp-content/plugins/rating-builder/assets/dist/js/frontend-assets.json/wp-content/plugins/rating-builder/assets/dist/vendor/react.min.js/wp-content/plugins/rating-builder/assets/dist/vendor/react-dom.min.js/wp-content/plugins/rating-builder/assets/dist/vendor/wp-rating-custom.jsrating-builder/assets/dist/vendor/css/redq-rating-builder-style.css?ver=rating-builder/assets/dist/vendor/css/magnific-popup.css?ver=rating-builder/assets/dist/vendor/wp-rating-custom.js?ver=rating-builder/assets/dist/vendor/media-upload.js?ver=rating-builder/assets/dist/vendor/css/redq-review.css?ver=HTML / DOM Fingerprints
redq_rb_rating_builder_wrapperdata-post-iddata-rating-idRATING_FRONTENDRATING_BACKEND[rating_builder]