
Revi.io – Customer and Product Reviews Security & Risk Analysis
wordpress.org/plugins/revi-io-customer-and-product-reviewsCollect and display verified product and store reviews in WooCommerce, build customer trust, and stand out on Google Search and Shopping.
Is Revi.io – Customer and Product Reviews Safe to Use in 2026?
Generally Safe
Score 99/100Revi.io – Customer and Product Reviews has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'revi-io-customer-and-product-reviews' plugin version 6.6.1 presents a mixed security posture. While it shows strengths in its use of prepared statements for SQL queries (91%) and a relatively low number of direct entry points (8 total, 1 unprotected), several concerning signals warrant attention. The presence of an `unserialize` function is a critical risk due to its potential for remote code execution if user-controlled data is not rigorously sanitized before unserialization. Furthermore, a significant portion of the analyzed taint flows (6 out of 7) have unsanitized paths, indicating a potential for various injection vulnerabilities, even though no critical or high severity taint flows were flagged in this specific analysis. The plugin also exhibits a lack of capability checks on its entry points, with 1 out of 2 AJAX handlers and 1 out of 1 REST API routes lacking permission callbacks, opening them up to unauthorized access.
The plugin's vulnerability history indicates a past medium-severity Cross-Site Scripting (XSS) vulnerability. While there are currently no unpatched vulnerabilities, the existence of a previous XSS issue, combined with the taint analysis showing unsanitized paths and the static analysis revealing potentially unescaped output (34% not properly escaped), suggests a recurring theme of input sanitization weaknesses. The plugin's relatively small attack surface and good SQL practice are positive, but the potential for RCE via unserialize, the high number of unsanitized taint flows, and the lack of authorization checks on critical entry points significantly elevate the risk profile.
Key Concerns
- Unprotected REST API route
- Unprotected AJAX handler
- Use of unserialize function
- High number of unsanitized taint flows
- Low percentage of properly escaped output
- No capability checks on entry points
- Past medium severity CVE (XSS)
Revi.io – Customer and Product Reviews Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Revi.io <= 5.7.3 - Reflected Cross-Site Scripting
Revi.io – Customer and Product Reviews Release Timeline
Revi.io – Customer and Product Reviews Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Revi.io – Customer and Product Reviews Attack Surface
AJAX Handlers 2
REST API Routes 1
Shortcodes 5
WordPress Hooks 26
Maintenance & Trust
Revi.io – Customer and Product Reviews Maintenance & Trust
Maintenance Signals
Community Trust
Revi.io – Customer and Product Reviews Alternatives
ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema
reviewx
Drive woocommerce business growth with social proof: gather product reviews with multicriteria ratings, auto-reminder emails, discounts, and more.
WPSSO Ratings and Reviews
wpsso-ratings-and-reviews
Adds Ratings and Reviews Features to the WordPress Comments System.
Photo Reviews for WooCommerce
woo-photo-reviews
Let customers attach photos to reviews, enhanced with filterable grids and overall ratings. Auto-send review reminders and coupon emails
Customer Reviews Collector for WooCommerce
customer-reviews-collector-for-woocommerce
Collect reviews on Google, Facebook, Yelp, Trustindex and other platforms automatically, with the help of our system.
Yotpo: Product & Photo Reviews for WooCommerce
yotpo-social-reviews-for-woocommerce
Collect product reviews, photo reviews, site reviews & ratings
Revi.io – Customer and Product Reviews Developer Profile
1 plugin · 300 total installs
How We Detect Revi.io – Customer and Product Reviews
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/revi-io-customer-and-product-reviews/assets/css/admin.css/wp-content/plugins/revi-io-customer-and-product-reviews/assets/css/style.css/wp-content/plugins/revi-io-customer-and-product-reviews/assets/css/revi-widget.css/wp-content/plugins/revi-io-customer-and-product-reviews/assets/js/admin.js/wp-content/plugins/revi-io-customer-and-product-reviews/assets/js/frontend.js/wp-content/plugins/revi-io-customer-and-product-reviews/assets/js/revi-widget.js/wp-content/plugins/revi-io-customer-and-product-reviews/blocks/revi-block.js/wp-content/plugins/revi-io-customer-and-product-reviews/assets/css/editor.css/wp-content/plugins/revi-io-customer-and-product-reviews/assets/js/admin.js/wp-content/plugins/revi-io-customer-and-product-reviews/assets/js/frontend.js/wp-content/plugins/revi-io-customer-and-product-reviews/assets/js/revi-widget.js/wp-content/plugins/revi-io-customer-and-product-reviews/blocks/revi-block.jsrevi-io-customer-and-product-reviews/assets/css/admin.css?ver=revi-io-customer-and-product-reviews/assets/css/style.css?ver=revi-io-customer-and-product-reviews/assets/css/revi-widget.css?ver=revi-io-customer-and-product-reviews/assets/js/admin.js?ver=revi-io-customer-and-product-reviews/assets/js/frontend.js?ver=revi-io-customer-and-product-reviews/assets/js/revi-widget.js?ver=revi-io-customer-and-product-reviews/blocks/revi-block.js?ver=revi-io-customer-and-product-reviews/assets/css/editor.css?ver=HTML / DOM Fingerprints
revi-starsrevi-widgetrevi-widget-content<!-- Revi.io Product Reviews --><!-- Revi.io Widget --><!-- Revi.io Product Schema -->data-revi-widget-typedata-product-idrevi_blockrevi_frontend_params/wp-json/revi/v1/get_reviews/wp-json/revi/v1/submit_review[revi_reviews][revi_widget]