Reviewify — Review Discounts & Photo/Video Reviews for WooCommerce Security & Risk Analysis

wordpress.org/plugins/review-for-discount

Reviewify helps you collect photo & video reviews, reward customers with coupons, and automate WooCommerce review emails.

40 active installs v1.0.9 PHP 7.4+ WP 5.0+ Updated Apr 6, 2026
customer-reviewsdiscount-couponsphoto-reviewproduct-reviewreview-for-discount
97
A · Safe
CVEs total1
Unpatched0
Last CVEJan 6, 2026
Download
Safety Verdict

Is Reviewify — Review Discounts & Photo/Video Reviews for WooCommerce Safe to Use in 2026?

Generally Safe

Score 97/100

Reviewify — Review Discounts & Photo/Video Reviews for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Jan 6, 2026Updated 1mo ago
Risk Assessment

The 'review-for-discount' plugin v1.0.8 exhibits a concerning security posture due to its exposed attack surface and SQL query practices. While the plugin demonstrates strong output escaping and a lack of critical taint flows, the presence of two AJAX handlers without authorization checks is a significant risk. This directly exposes these entry points to potential unauthorized access and manipulation by unauthenticated users, which could lead to unintended actions or data compromise. The historical vulnerability data, including a past high-severity CVE related to missing authorization, reinforces this concern and suggests a recurring pattern of authorization weaknesses. Despite the positive aspects of code escaping, the fundamental lack of security controls on entry points and the use of raw SQL queries present a substantial risk that needs immediate attention. The plugin's strengths in output handling are overshadowed by its vulnerabilities in access control and data handling, indicating a need for significant security improvements.

Key Concerns

  • Unprotected AJAX handlers
  • Raw SQL queries without prepared statements
  • History of High severity CVE (Missing Authorization)
Vulnerabilities
1 published

Reviewify — Review Discounts & Photo/Video Reviews for WooCommerce Security Vulnerabilities

CVEs by Year

1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

High
1

1 total CVE

CVE-2025-14070high · 7.5Missing Authorization

Reviewify <= 1.0.7 - Missing Authorization to Authenticated (Contributor+) Arbitrary WooCommerce Coupon Creation

Jan 6, 2026 Patched in 1.0.8 (2d)
Version History

Reviewify — Review Discounts & Photo/Video Reviews for WooCommerce Release Timeline

v1.0.9Current
v1.0.8
v1.0.71 CVE
v1.0.61 CVE
v1.0.51 CVE
v1.0.41 CVE
v1.0.31 CVE
v1.0.21 CVE
v1.0.11 CVE
v1.0.01 CVE
Code Analysis
Analyzed Mar 16, 2026

Reviewify — Review Discounts & Photo/Video Reviews for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
3
0 prepared
Unescaped Output
0
123 escaped
Nonce Checks
5
Capability Checks
2
File Operations
0
External Requests
1
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

0% prepared3 total queries

Output Escaping

100% escaped123 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
xswcrd_settings_save (admin\class-xswcrd-review-discounts-settings.php:136)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Reviewify — Review Discounts & Photo/Video Reviews for WooCommerce Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_send_test_emailincludes\class-xswcrd-review-discounts.php:141
authwp_ajax_xs_send_mailincludes\class-xswcrd-review-discounts.php:142
WordPress Hooks 20
actionsave_postadmin\class-xswcrd-review-discounts-admin.php:337
filterwoocommerce_settings_tabs_arrayadmin\class-xswcrd-review-discounts-settings.php:37
actionwoocommerce_sections_xswcrd_settingsadmin\class-xswcrd-review-discounts-settings.php:38
actionwoocommerce_settings_xswcrd_settingsadmin\class-xswcrd-review-discounts-settings.php:39
actionwoocommerce_settings_save_xswcrd_settingsadmin\class-xswcrd-review-discounts-settings.php:40
actionadmin_enqueue_scriptsincludes\class-xswcrd-review-discounts.php:132
actionadmin_enqueue_scriptsincludes\class-xswcrd-review-discounts.php:133
actionadmin_menuincludes\class-xswcrd-review-discounts.php:135
actioninitincludes\class-xswcrd-review-discounts.php:136
actionadd_meta_boxesincludes\class-xswcrd-review-discounts.php:137
actionsave_postincludes\class-xswcrd-review-discounts.php:138
filtermanage_xswc-review-discount_posts_columnsincludes\class-xswcrd-review-discounts.php:139
actionmanage_xswc-review-discount_posts_custom_columnincludes\class-xswcrd-review-discounts.php:140
filterwoocommerce_get_settings_pagesincludes\class-xswcrd-review-discounts.php:143
actioncomment_postincludes\class-xswcrd-review-discounts.php:155
actionwp_set_comment_statusincludes\class-xswcrd-review-discounts.php:156
actionwoocommerce_thankyouincludes\class-xswcrd-review-discounts.php:157
actionadmin_initreview-for-review.php:35
actionadmin_noticesreview-for-review.php:40
actionbefore_woocommerce_initreview-for-review.php:64
Maintenance & Trust

Reviewify — Review Discounts & Photo/Video Reviews for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 6, 2026
PHP min version7.4
Downloads4K

Community Trust

Rating100/100
Number of ratings2
Active installs40
Developer Profile

Reviewify — Review Discounts & Photo/Video Reviews for WooCommerce Developer Profile

Xfinitysoft

9 plugins · 4K total installs

99
trust score
Avg Security Score
98/100
Avg Patch Time
6 days
View full developer profile
Detection Fingerprints

How We Detect Reviewify — Review Discounts & Photo/Video Reviews for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/review-for-discount/admin/css/select2.min.css/wp-content/plugins/review-for-discount/admin/css/wc-review-discounts-admin.css/wp-content/plugins/review-for-discount/admin/js/select2.full.min.js/wp-content/plugins/review-for-discount/admin/js/wc-review-discounts-admin.js
Script Paths
admin/js/select2.full.min.jsadmin/js/wc-review-discounts-admin.js
Version Parameters
review-for-discount/admin/css/select2.min.css?ver=review-for-discount/admin/css/wc-review-discounts-admin.css?ver=review-for-discount/admin/js/select2.full.min.js?ver=review-for-discount/admin/js/wc-review-discounts-admin.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-nonce="xswcrd_test_email"
JS Globals
xswcrd
FAQ

Frequently Asked Questions about Reviewify — Review Discounts & Photo/Video Reviews for WooCommerce