Review Map by RevuKangaroo Security & Risk Analysis

wordpress.org/plugins/review-map-by-revukangaroo

Show off your customer's online reviews with Review Map by Revukangaroo.

20 active installs v1.7 PHP + WP 4.1+ Updated Sep 27, 2021
business-reviewsgoogle-reviewsnegative-review-blockerreview-filteryelp-reviews
63
C · Use Caution
CVEs total1
Unpatched1
Last CVEMar 20, 2026
Safety Verdict

Is Review Map by RevuKangaroo Safe to Use in 2026?

Use With Caution

Score 63/100

Review Map by RevuKangaroo has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Mar 20, 2026Updated 4yr ago
Risk Assessment

The static analysis of the "review-map-by-revukangaroo" plugin v1.7 indicates a generally strong security posture with no identified critical or high-severity vulnerabilities in the code analysis or taint flows. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events suggests a minimal attack surface. Furthermore, the code adheres to good practices by using prepared statements for all SQL queries and implementing nonce and capability checks. However, a concern arises from the output escaping, where only 67% of outputs are properly escaped, leaving a potential for cross-site scripting (XSS) vulnerabilities if the unescaped outputs are user-controllable. The plugin also performs file operations and external HTTP requests, which, while not inherently insecure, are potential vectors that require careful handling and sanitization of any user-supplied input related to these operations. The plugin's vulnerability history is a significant strength, with zero recorded CVEs across all severities, indicating a history of secure development or effective patching. In conclusion, while the plugin demonstrates robust security practices in several key areas and benefits from a clean vulnerability history, the unescaped output remains a notable weakness that could be exploited.

Key Concerns

  • Insecure output escaping
Vulnerabilities
1 published

Review Map by RevuKangaroo Security Vulnerabilities

CVEs by Year

1 CVE in 2026 · unpatched
2026
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2026-4161medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Review Map by RevuKangaroo <= 1.7 - Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Settings

Mar 20, 2026Unpatched
Version History

Review Map by RevuKangaroo Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

Review Map by RevuKangaroo Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
9
18 escaped
Nonce Checks
1
Capability Checks
1
File Operations
1
External Requests
1
Bundled Libraries
0

Output Escaping

67% escaped27 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
reviewmapby_revkang_admin (review-map-by-revuKangaroo.php:140)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Review Map by RevuKangaroo Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
filterpage_attributes_dropdown_pages_argsreview-map-by-revuKangaroo.php:47
filtertheme_page_templatesreview-map-by-revuKangaroo.php:56
filterwp_insert_post_datareview-map-by-revuKangaroo.php:63
filtertemplate_includereview-map-by-revuKangaroo.php:69
actionplugins_loadedreview-map-by-revuKangaroo.php:127
actionadmin_menureview-map-by-revuKangaroo.php:318
actionadmin_print_stylesreview-map-by-revuKangaroo.php:335
Maintenance & Trust

Review Map by RevuKangaroo Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedSep 27, 2021
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Review Map by RevuKangaroo Developer Profile

revukangaroo

2 plugins · 50 total installs

76
trust score
Avg Security Score
74/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Review Map by RevuKangaroo

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/review-map-by-revukangaroo/assets/css/style.css/wp-content/plugins/review-map-by-revukangaroo/assets/js/custom.js/wp-content/plugins/review-map-by-revukangaroo/assets/js/schema.js
Script Paths
/wp-content/plugins/review-map-by-revukangaroo/assets/js/custom.js/wp-content/plugins/review-map-by-revukangaroo/assets/js/schema.js
Version Parameters
review-map-by-revukangaroo/assets/css/style.css?ver=review-map-by-revukangaroo/assets/js/custom.js?ver=review-map-by-revukangaroo/assets/js/schema.js?ver=

HTML / DOM Fingerprints

CSS Classes
form_map_api
Data Attributes
schema_api_keyscity_apicities_apistate_apishow_map_apishow_posts_api+3 more
FAQ

Frequently Asked Questions about Review Map by RevuKangaroo