
Review Fetcher Security & Risk Analysis
wordpress.org/plugins/review-fetcherDisplay your Google Business reviews in a beautiful responsive grid using a simple shortcode. Clean, lightweight, and easy to use.
Is Review Fetcher Safe to Use in 2026?
Generally Safe
Score 100/100Review Fetcher has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The review-fetcher plugin v1.4.1 demonstrates a generally strong security posture based on the provided static analysis. The absence of dangerous functions, all SQL queries utilizing prepared statements, and 100% proper output escaping are excellent security practices that significantly reduce the risk of common vulnerabilities like SQL injection and cross-site scripting. The plugin also has a clean vulnerability history with no known CVEs, suggesting a commitment to security by its developers or a lack of past exploitation. The limited attack surface, consisting of only one shortcode with no apparent unauthenticated entry points, further contributes to its favorable security profile.
However, a notable area of concern is the complete lack of nonce checks and capability checks. While the static analysis indicates no unauthenticated entry points for AJAX or REST API, the absence of these fundamental security mechanisms means that if any new entry points were accidentally introduced or if an existing one was overlooked, these actions could be performed by any authenticated user, regardless of their role or permissions. This presents a potential weakness that could be exploited if the plugin's functionality were to be expanded or modified without adequate security considerations.
In conclusion, review-fetcher v1.4.1 exhibits strong coding practices for its current features. Its primary weakness lies in the omission of essential security checks (nonces and capabilities) which, while not immediately exploitable given the current attack surface, represent a potential risk for future development or if undiscovered entry points exist. The lack of vulnerability history is a positive indicator but should not be seen as a guarantee of future immunity.
Key Concerns
- Missing nonce checks
- Missing capability checks
Review Fetcher Security Vulnerabilities
Review Fetcher Code Analysis
Output Escaping
Review Fetcher Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
Review Fetcher Maintenance & Trust
Maintenance Signals
Community Trust
Review Fetcher Alternatives
CustomView: Display Reviews Your Way for Google Reviews
customview-display-reviews-your-way-for-google-reviews
Display your business's Google Reviews anywhere on your WordPress site using the [customview_reviews] shortcode.
RicReviews
ricreviews
Display Google Places reviews on your WordPress site using a simple shortcode. Fetches reviews from Google Places API (New).
Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More
reviews-feed
No API key required. Display Yelp and Google reviews for any business in a clean, customizable feed on your site.
Rich Showcase for Google Reviews
widget-google-reviews
Display up to 10 Google reviews in less than a minute. Continue collecting new reviews. No limits on connected places, widgets, shortcodes and blocks.
WP Google Review Slider
wp-google-places-review-slider
Display Google reviews on your site and even show user images! No address, no problem! Also works with Service Area Businesses and Products! Lightwei …
Review Fetcher Developer Profile
1 plugin · 0 total installs
How We Detect Review Fetcher
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/review-fetcher/assets/google-logo.png/wp-content/plugins/review-fetcher/assets/Ai.pngHTML / DOM Fingerprints
grplugin-google-ratinggrplugin-review-containergrplugin-review-cardgrplugin-review-headergrplugin-avatargrplugin-review-header-infogrplugin-review-ratinggrplugin-aligned-list+3 moregrplugin_api_keygrplugin_place_idgrplugin_review_countgrplugin_ai_review_summarygrplugin_openai_key[grplugin_reviews_grid]