
Review Deck Security & Risk Analysis
wordpress.org/plugins/review-deckManage and display customer reviews using shortcodes. Includes form, list, slider, masonry, column, summary, and floating widget display options.
Is Review Deck Safe to Use in 2026?
Generally Safe
Score 100/100Review Deck has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "review-deck" plugin v1.0.7 exhibits a generally good security posture, with no recorded vulnerabilities or CVEs. The static analysis indicates a strong adherence to security best practices, as evidenced by a high percentage of properly escaped outputs, a significant use of prepared statements for SQL queries, and the presence of nonce and capability checks on most entry points. This suggests the developers are conscious of common WordPress security pitfalls.
However, the taint analysis reveals a notable concern: 9 out of 17 analyzed flows have unsanitized paths, with 8 classified as high severity. This indicates a potential for attackers to inject malicious data that is not properly validated or sanitized before being processed, which could lead to various vulnerabilities depending on the context. While there are no directly exploitable critical issues flagged by the taint analysis, these high-severity unsanitized flows represent a significant risk that warrants investigation and remediation.
In conclusion, the plugin's lack of historical vulnerabilities is a positive sign, and its implementation of security features like prepared statements and output escaping is commendable. Nevertheless, the high number of unsanitized taint flows is a critical weakness that outweighs the otherwise strong security foundation. Addressing these unsanitized paths should be the highest priority to ensure the plugin's security.
Key Concerns
- High severity unsanitized taint flows
- Unsanitized paths in taint flows
- SQL queries not using prepared statements
Review Deck Security Vulnerabilities
Review Deck Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Review Deck Attack Surface
AJAX Handlers 15
Shortcodes 8
WordPress Hooks 50
Scheduled Events 1
Maintenance & Trust
Review Deck Maintenance & Trust
Maintenance Signals
Community Trust
Review Deck Alternatives
Customer Reviews for WooCommerce
customer-reviews-woocommerce
Customer Reviews for WooCommerce plugin helps you get more sales with social proof. Set up automated review reminders and increase conversion rate.
WP Social Ninja – Embed Social Feeds, User Reviews & Chat Widgets
wp-social-reviews
Add Facebook feeds, Instagram feeds, TikTok feeds, Facebook reviews, WhatsApp Chat, Messenger chat, Testimonial, and others using a single dashboard.
Photo Reviews for WooCommerce
woo-photo-reviews
Let customers attach photos to reviews, enhanced with filterable grids and overall ratings. Auto-send review reminders and coupon emails
ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema
reviewx
Drive woocommerce business growth with social proof: gather product reviews with multicriteria ratings, auto-reminder emails, discounts, and more.
Customer Reviews Collector for WooCommerce
customer-reviews-collector-for-woocommerce
Collect reviews on Google, Facebook, Yelp, Trustindex and other platforms automatically, with the help of our system.
Review Deck Developer Profile
8 plugins · 5K total installs
How We Detect Review Deck
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/review-deck/assets/css/rvdk-frontend.css/wp-content/plugins/review-deck/assets/js/rvdk-frontend.jsreview-deck/assets/css/rvdk-frontend.css?ver=review-deck/assets/js/rvdk-frontend.js?ver=HTML / DOM Fingerprints
rvdk-reviews-listrvdk-review-form-containerrvdk-reviews-sliderrvdk-trust-badgervdk-product-reviewsdata-rvdk-page-iddata-rvdk-per-pagedata-rvdk-sort-orderdata-rvdk-show-formdata-rvdk-per-rowdata-rvdk-autoplay+3 more[review_deck_reviews_list[review_deck_review_form[review_deck_reviews_slider[review_deck_trust_badge