
Rating Plus Security & Risk Analysis
wordpress.org/plugins/rating-plusA simple and clean rating widget plugin allowing to add a sexy rate button to the widgets area.
Is Rating Plus Safe to Use in 2026?
Generally Safe
Score 85/100Rating Plus has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "rating-plus" plugin v1.0.1 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by avoiding direct SQL queries without prepared statements and having no recorded vulnerability history, which suggests a history of responsible development. The absence of known CVEs and common vulnerability types is also a strong indicator of a relatively secure past. However, the static analysis reveals significant concerns, particularly the complete lack of output escaping for all identified output points. This presents a high risk of cross-site scripting (XSS) vulnerabilities, as user-supplied data or data manipulated by attackers could be rendered directly in the browser without sanitization, potentially leading to arbitrary code execution in the user's session.
While the attack surface appears small and has no explicitly unprotected entry points according to this analysis, the critical flaw in output sanitization overshadows these positive aspects. The bundled outdated Select2 library, although not directly flagged as a vulnerability in this report, represents a potential attack vector if it contains unpatched vulnerabilities that could be exploited through other means not immediately apparent in this static analysis. The absence of taint analysis data is noted but doesn't detract from the identified XSS risk. In conclusion, while the plugin has a clean history and avoids some common pitfalls, the severe lack of output escaping is a critical security weakness that requires immediate attention.
Key Concerns
- 0% output escaping
- Bundled outdated library (Select2 v3.5.2)
Rating Plus Security Vulnerabilities
Rating Plus Code Analysis
Bundled Libraries
Output Escaping
Rating Plus Attack Surface
WordPress Hooks 4
Maintenance & Trust
Rating Plus Maintenance & Trust
Maintenance Signals
Community Trust
Rating Plus Alternatives
Strong Testimonials
strong-testimonials
An easy-to-use testimonial plugin to collect and show customer feedback in WordPress
kk Star Ratings – Rate Post & Collect User Feedbacks
kk-star-ratings
kk Star Ratings allows blog visitors to involve and interact more effectively with your website by rating posts.
Site Reviews
site-reviews
Site Reviews is a complete review management solution that integrates with WooCommerce and SureCart and works similarly to reviews on Amazon, Tripadvi …
Testimonial – Testimonial Slider and Showcase Plugin
testimonial-slider-and-showcase
Display customer testimonials beautifully with responsive slider and grid layouts. Build trust and boost conversions with this WordPress testimonial p …
WP-PostRatings
wp-postratings
Adds an AJAX rating system for your WordPress site's content.
Rating Plus Developer Profile
1 plugin · 10 total installs
How We Detect Rating Plus
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/rating-plus/assets/css/select2.css/wp-content/plugins/rating-plus/assets/js/select2.js/wp-content/plugins/rating-plus/assets/js/select2.jsrating-plus/assets/css/select2.css?ver=rating-plus/assets/js/select2.js?ver=HTML / DOM Fingerprints
rp-widgetrp-icon-selectselect2-containerlb-fiselect2-resultsselect2-celledwidget-control-actionsdata-select2-idrpIconSelectFormatjQuery