
Recotrust Security & Risk Analysis
wordpress.org/plugins/recotrust-integrationBy activating the plugin you enable the function to collect and visible customer reviews. This plugin requires an account on Recotrust.com
Is Recotrust Safe to Use in 2026?
Generally Safe
Score 85/100Recotrust has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "recotrust-integration" plugin version 1.0.6 exhibits a generally positive security posture based on the static analysis and vulnerability history provided. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the code signals indicate a strong adherence to secure coding practices, with no dangerous functions identified, all SQL queries using prepared statements, and a high percentage of properly escaped output. The lack of file operations and external HTTP requests also reduces potential attack vectors. The plugin's vulnerability history is clean, with no recorded CVEs, which is a significant strength.
Despite the overall positive assessment, there are minor areas for improvement. The presence of an external HTTP request, although not immediately indicative of a vulnerability without further context on its purpose, warrants careful review to ensure it's being handled securely. The most notable concern, however, is the complete absence of nonce checks and capability checks across all identified entry points (of which there are none in this specific analysis). While the current lack of entry points mitigates immediate risk, any future expansion of functionality that introduces new entry points without these fundamental security checks would create significant vulnerabilities.
In conclusion, "recotrust-integration" v1.0.6 appears to be a well-developed plugin from a security perspective, with a strong emphasis on secure coding principles. Its minimal attack surface and clean vulnerability history are commendable. However, the lack of any nonce or capability checks is a potential weakness that should be addressed proactively, especially if the plugin is expected to evolve and gain new functionalities.
Key Concerns
- No nonce checks implemented
- No capability checks implemented
- One external HTTP request detected
Recotrust Security Vulnerabilities
Recotrust Code Analysis
Output Escaping
Recotrust Attack Surface
WordPress Hooks 11
Maintenance & Trust
Recotrust Maintenance & Trust
Maintenance Signals
Community Trust
Recotrust Alternatives
WP Testimonials
testimonial-widgets
Display your Testimonials on your website fast and easily. 21 widget types, 25 widget styles available. (Free Plugin)
Widgets for Amazon Reviews
review-widgets-for-amazon
Embed Amazon reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Amazon reviews.
Widgets for Thumbtack Reviews
widgets-for-thumbtack-reviews
Embed Thumbtack reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Thumbtack reviews.
Widgets for Ebay Reviews
widgets-for-ebay-reviews
Embed Ebay reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Ebay reviews.
Widgets for Zillow Reviews
widgets-for-zillow-reviews
Embed Zillow reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Zillow reviews.
Recotrust Developer Profile
1 plugin · 10 total installs
How We Detect Recotrust
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/recotrust-integration/assets/javascript/ac-reco-plugin.js/wp-content/plugins/recotrust-integration/assets/css/ac-reco-plugin.css/wp-content/plugins/recotrust-integration/assets/javascript/ac-reco-plugin.jsac-reco-plugin-script?ver=ac-reco-plugin-style?ver=HTML / DOM Fingerprints
Ac_Reco_Plugin