Review Content Type Security & Risk Analysis

wordpress.org/plugins/review-content-type

Create and manage reviews easily with this feature-rich, extendable, powerful and free WordPress review plugin the right way.

10 active installs v1.0.4 PHP + WP 3.8+ Updated May 14, 2018
ratingsreviewreviewsrich-snippetsschema
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Review Content Type Safe to Use in 2026?

Generally Safe

Score 85/100

Review Content Type has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The 'review-content-type' plugin version 1.0.4 demonstrates a generally strong security posture based on the provided static analysis and vulnerability history. The absence of any reported CVEs and the plugin's static analysis showing zero unprotected entry points, dangerous functions, raw SQL queries, or file operations are significant strengths. Furthermore, the presence of nonce and capability checks indicates an awareness of common WordPress security practices.

However, the analysis does highlight a potential area for improvement. While the majority of output is properly escaped, 13% of the 181 total outputs are not. This could, in theory, lead to cross-site scripting (XSS) vulnerabilities if the unescaped data originates from an untrusted source. The taint analysis, while reporting zero critical or high severity flows, is limited in scope by the small number of flows analyzed. Therefore, while the current known risk appears low, the slight percentage of unescaped output warrants attention.

In conclusion, the 'review-content-type' plugin exhibits good security fundamentals with no known critical vulnerabilities and a well-defined, protected attack surface. The primary area of concern is the small but present percentage of unescaped output, which should be addressed to achieve a more robust security profile. The lack of past vulnerabilities is a positive indicator, but continuous vigilance and addressing minor code quality issues like output escaping are crucial for long-term security.

Key Concerns

  • Unescaped output detected
Vulnerabilities
None known

Review Content Type Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Review Content Type Release Timeline

v1.0.4Current
v1.0.3
v1.0.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

Review Content Type Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
23
158 escaped
Nonce Checks
2
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

87% escaped181 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

4 flows
save_review_data (includes\admin\class-rct-admin-meta-boxes.php:326)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Review Content Type Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 31
actionadd_meta_boxes_reviewincludes\admin\class-rct-admin-meta-boxes.php:16
actionsave_postincludes\admin\class-rct-admin-meta-boxes.php:17
actionadmin_initincludes\admin\class-rct-admin-permalink-settings.php:16
actionadmin_initincludes\admin\class-rct-admin-permalink-settings.php:17
filterenter_title_hereincludes\admin\class-rct-admin-post-types.php:16
filterpost_updated_messagesincludes\admin\class-rct-admin-post-types.php:17
filterbulk_post_updated_messagesincludes\admin\class-rct-admin-post-types.php:18
filterdashboard_glance_itemsincludes\admin\class-rct-admin-post-types.php:19
actionrestrict_manage_postsincludes\admin\class-rct-admin-post-types.php:22
actionadmin_menuincludes\admin\class-rct-admin.php:24
actioninitincludes\class-rct-post-types.php:16
actioninitincludes\class-rct-post-types.php:17
actionwp_enqueue_scriptsincludes\class-rct-scripts.php:32
actionwp_enqueue_scriptsincludes\class-rct-scripts.php:33
actionadmin_enqueue_scriptsincludes\class-rct-scripts.php:36
actionadmin_enqueue_scriptsincludes\class-rct-scripts.php:37
actionadmin_initincludes\class-rct-settings.php:78
filterrct_sanitize_review_data_min_price_fieldincludes\rct-functions.php:453
filterrct_sanitize_review_data_max_price_fieldincludes\rct-functions.php:454
filterthe_contentincludes\rct-template-functions.php:147
filterthe_contentincludes\rct-template-functions.php:152
actionrct_before_review_contentincludes\rct-template-functions.php:509
actionrct_before_review_contentincludes\rct-template-functions.php:518
actionrct_before_review_contentincludes\rct-template-functions.php:527
actionrct_before_review_contentincludes\rct-template-functions.php:536
actionrct_after_featured_imageincludes\rct-template-functions.php:545
actionrct_after_featured_imageincludes\rct-template-functions.php:554
actionrct_after_featured_imageincludes\rct-template-functions.php:559
actionplugins_loadedreview-content-type.php:73
actioninitreview-content-type.php:74
filterpost_type_linkreview-content-type.php:75
Maintenance & Trust

Review Content Type Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedMay 14, 2018
PHP min version
Downloads6K

Community Trust

Rating96/100
Number of ratings6
Active installs10
Developer Profile

Review Content Type Developer Profile

Chetan Chauhan

2 plugins · 40 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Review Content Type

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/review-content-type/assets/css/admin.css/wp-content/plugins/review-content-type/assets/css/frontend.css/wp-content/plugins/review-content-type/assets/js/admin.js/wp-content/plugins/review-content-type/assets/js/frontend.js
Script Paths
/wp-content/plugins/review-content-type/assets/js/admin.js/wp-content/plugins/review-content-type/assets/js/frontend.js
Version Parameters
review-content-type/assets/css/admin.css?ver=review-content-type/assets/css/frontend.css?ver=review-content-type/assets/js/admin.js?ver=review-content-type/assets/js/frontend.js?ver=

HTML / DOM Fingerprints

JS Globals
RCT_Admin
FAQ

Frequently Asked Questions about Review Content Type