
Rating by BestWebSoft Security & Risk Analysis
wordpress.org/plugins/rating-bwsAdd rating plugin to your WordPress website to receive feedback from your customers.
Is Rating by BestWebSoft Safe to Use in 2026?
Mostly Safe
Score 73/100Rating by BestWebSoft is generally safe to use. 3 past CVEs were resolved. Keep it updated.
The "rating-bws" plugin version 1.7 exhibits a mixed security posture. On the positive side, the static analysis reveals a strong adherence to secure coding practices, with a high percentage of SQL queries using prepared statements and properly escaped output. The plugin also incorporates a substantial number of nonce and capability checks, indicating an effort to protect against common web vulnerabilities. However, the plugin's vulnerability history is a significant concern. With three known CVEs, including one currently unpatched high-severity vulnerability, the plugin has a history of introducing serious security flaws. The types of past vulnerabilities (Deserialization, Resource Consumption, XSS) suggest potential for complex attacks if the unpatched vulnerability is exploitable. While the static analysis doesn't immediately reveal critical flaws in this specific version, the historical pattern necessitates caution. The unpatched high-severity vulnerability from April 17, 2025, is the most pressing issue and suggests that users are at immediate risk from known exploits. Therefore, despite some good development practices, the ongoing unpatched vulnerability overshadows these strengths, making the plugin a moderate to high-risk component.
Key Concerns
- Unpatched high severity CVE
- History of critical vulnerability types
- Moderate number of SQL queries
Rating by BestWebSoft Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Rating by BestWebSoft <= 1.7 - Authenticated (Subscriber+) PHP Object Injection
Rating by BestWebSoft <= 1.5 - Rating Denial of Service
Rating by BestWebSoft < 0.2 - Reflected Cross-Site Scripting
Rating by BestWebSoft Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Rating by BestWebSoft Attack Surface
AJAX Handlers 4
Shortcodes 4
WordPress Hooks 28
Maintenance & Trust
Rating by BestWebSoft Maintenance & Trust
Maintenance Signals
Community Trust
Rating by BestWebSoft Alternatives
WP Ultimate Review
wp-ultimate-review
WP Ultimate Review is the perfect plugin to collect & display customers' feedback effortlessly on products, services, & content in WordPress.
GD Rating System
gd-rating-system
Powerful, highly customizable and versatile ratings plugin to allow your users to vote for anything you want.
REVIEWS.io for WooCommerce
reviewscouk-for-woocommerce
REVIEWS.io, helps eCommerce merchants to collect & display verified product and company reviews. A Google Licensed partner.
Stars Rating
stars-rating
A plugin to turn comments into reviews by adding rating feature.
Five-Star Ratings Shortcode
five-star-ratings-shortcode
Simple lightweight shortcode to add 5-star ratings anywhere.
Rating by BestWebSoft Developer Profile
32 plugins · 17K total installs
How We Detect Rating by BestWebSoft
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/rating-bws/assets/css/rating-bws.css/wp-content/plugins/rating-bws/assets/js/rating-bws.js/wp-content/plugins/rating-bws/assets/js/rating-bws.jsrating-bws/assets/css/rating-bws.css?ver=rating-bws/assets/js/rating-bws.js?ver=HTML / DOM Fingerprints
rtng-starsrtng-ratingrtng-containerrtng-averagedata-rating-avgdata-rating-idrtng_params[rating-bws]