
Review Disclaimer Security & Risk Analysis
wordpress.org/plugins/review-disclaimerUse a shortcode to quickly insert product or service review disclaimers inside your posts.
Is Review Disclaimer Safe to Use in 2026?
Use With Caution
Score 63/100Review Disclaimer has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The 'review-disclaimer' plugin version 2.0.3 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by not making external HTTP requests, performing file operations, or utilizing dangerous functions. Its use of prepared statements for all SQL queries is commendable. However, significant concerns arise from the complete lack of nonce and capability checks across all identified entry points, including the single shortcode. This leaves the plugin highly vulnerable to various attacks that can be executed without user authentication or specific permissions.
The vulnerability history reveals a past medium severity Cross-site Scripting (XSS) vulnerability, and critically, this vulnerability remains unpatched. The presence of an unpatched medium-severity XSS vulnerability, combined with the absence of authentication and capability checks, creates a substantial risk. This indicates a potential for attackers to inject malicious scripts, which could lead to session hijacking, data theft, or defacement, especially given the lack of proper output escaping on some generated content.
In conclusion, while the plugin avoids some common pitfalls like raw SQL and dangerous functions, the absence of fundamental security checks and the existence of an unpatched XSS vulnerability represent critical weaknesses. Users should be highly cautious, and the developers need to address these issues promptly to secure the plugin.
Key Concerns
- Unpatched medium severity CVE
- Missing capability checks on entry points
- Missing nonce checks on entry points
- Improper output escaping on some content
Review Disclaimer Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Review Disclaimer <= 2.0.3 - Authenticated (Administrator+) Stored Cross-Site Scripting
Review Disclaimer Code Analysis
Output Escaping
Review Disclaimer Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
Review Disclaimer Maintenance & Trust
Maintenance Signals
Community Trust
Review Disclaimer Alternatives
Shortcode Preview Block
shortcode-with-preview-block
Shows preview of any shortcode on editor side. It renders shortcode in the editor side so editor does not need to visit front side.
MW WP Form
mw-wp-form
MW WP Form is shortcode base contact form plugin. This plugin have many features. For example you can use many validation rules, inquiry data saving, …
Latest Post Shortcode
latest-post-shortcode
The "Latest Post Shortcode" allows you to create a dynamic content selection from your posts by combining, limiting, and filtering what you need.
Star Rating Block
star-rating-block
The Star Rating block allows you to display author-assigned star ratings within your content.
Stars Rating
stars-rating
A plugin to turn comments into reviews by adding rating feature.
Review Disclaimer Developer Profile
15 plugins · 13K total installs
How We Detect Review Disclaimer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/review-disclaimer/index.js/wp-content/plugins/review-disclaimer/index.jsreview-disclaimer/index.js?ver=HTML / DOM Fingerprints
review-disclaimer-block<div class="review-disclaimer-block">