
Recommend Us Security & Risk Analysis
wordpress.org/plugins/recommend-usEmbed visitor or client recommendation or reviews about your startup or website to your website.
Is Recommend Us Safe to Use in 2026?
Generally Safe
Score 85/100Recommend Us has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "recommend-us" plugin v2.0.0 exhibits a generally good security posture due to the absence of known vulnerabilities and a commitment to secure coding practices like prepared SQL statements and no external HTTP requests. The static analysis also shows no dangerous functions or file operations, which are positive indicators. However, there are significant concerns regarding output escaping, with only 37% of outputs being properly escaped. This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, especially as the plugin has two shortcodes which are common entry points for user-supplied data that could be reflected in the output.
Further analysis reveals a concerning taint flow with an "unsanitized path," although it's not classified as critical or high severity. This, combined with the low percentage of proper output escaping, suggests that malicious input could potentially be processed or displayed without adequate sanitization, leading to unexpected behavior or security exploits. The lack of nonce and capability checks on the identified entry points (shortcodes) also means that actions triggered by these shortcodes might not be properly authorized or protected against CSRF attacks, although the static analysis didn't explicitly flag these as unprotected entry points. The plugin's vulnerability history of zero CVEs is a positive sign of its maintainers' diligence, but the current code analysis reveals areas that require immediate attention to maintain this clean record.
Key Concerns
- Low percentage of properly escaped output
- Taint flow with unsanitized paths
- Shortcodes lack capability checks
- Shortcodes lack nonce checks
Recommend Us Security Vulnerabilities
Recommend Us Release Timeline
Recommend Us Code Analysis
Output Escaping
Data Flow Analysis
Recommend Us Attack Surface
Shortcodes 2
WordPress Hooks 4
Maintenance & Trust
Recommend Us Maintenance & Trust
Maintenance Signals
Community Trust
Recommend Us Alternatives
WP Testimonials
testimonial-widgets
Display your Testimonials on your website fast and easily. 21 widget types, 25 widget styles available. (Free Plugin)
Widgets for Thumbtack Reviews
widgets-for-thumbtack-reviews
Embed Thumbtack reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Thumbtack reviews.
Widgets for Ebay Reviews
widgets-for-ebay-reviews
Embed Ebay reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Ebay reviews.
Responsive Testimonials
responsive-testimonials
A responsive, clean and easy way to display testimonials. Create testimonials, add authors and their jobs and copy-paste the shortcode into any page.
Widgets for Capterra Reviews
review-widgets-for-capterra
Embed Capterra reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Capterra reviews.
Recommend Us Developer Profile
10 plugins · 5K total installs
How We Detect Recommend Us
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/recommend-us/js/recommend-us.js/wp-content/plugins/recommend-us/css/glyphicons.css/wp-content/plugins/recommend-us/css/recommend-us.css/wp-content/plugins/recommend-us/js/recommend-us.jsrecommend-us/js/recommend-us.js?ver=recommend-us/css/glyphicons.css?ver=recommend-us/css/recommend-us.css?ver=HTML / DOM Fingerprints
ms_rcmnd_formlabel_starglyphiconglyphicon-star-emptyform_rowgrid_6alphaomega+3 moreid="ms_rcmnd_form_name="submitted"value="Y"id="rRating"name="rName"placeholder="Name *"+6 more<form action="" class="ms_rcmnd_form"<input type="hidden" name="submitted" value="Y" /><input type="hidden" name="rRating" id="rRating" value="0" /><div class="form_row">