Review Showcase for TikTok Security & Risk Analysis

wordpress.org/plugins/review-showcase-for-tiktok

Display stunning TikTok video testimonials and reviews in a fast, mobile-responsive, SEO-optimized grid or carousel to boost trust and conversions.

0 active installs v1.0.4 PHP 7.4+ WP 5.6+ Updated Sep 16, 2025
carouselreviewssocial-prooftiktokvideo-testimonials
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Review Showcase for TikTok Safe to Use in 2026?

Generally Safe

Score 100/100

Review Showcase for TikTok has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The plugin 'review-showcase-for-tiktok' v1.0.4 exhibits a generally strong security posture based on the provided static analysis. The absence of AJAX handlers and REST API routes without proper authentication checks, coupled with a minimal attack surface consisting solely of one shortcode, are positive indicators. Furthermore, the code demonstrates good output sanitization practices with 97% of outputs properly escaped and a healthy number of nonce and capability checks present. The complete lack of dangerous functions, file operations, and external HTTP requests further contributes to its perceived security. The plugin also has no recorded vulnerability history, which is a very positive sign of its development and maintenance quality.

However, a notable concern arises from the handling of SQL queries. The analysis shows one SQL query that does not utilize prepared statements, presenting a potential risk for SQL injection vulnerabilities, albeit a single instance. While taint analysis shows no flows, indicating no complex data manipulation vulnerabilities were detected, the raw SQL query remains a point of attention. The overall security is good, but this single instance of non-prepared SQL query necessitates attention to prevent potential exploitation, especially if the data used in the query is user-supplied or comes from an untrusted source.

Key Concerns

  • Raw SQL query without prepared statements
Vulnerabilities
None known

Review Showcase for TikTok Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Review Showcase for TikTok Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
1
37 escaped
Nonce Checks
3
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

97% escaped38 total outputs
Attack Surface

Review Showcase for TikTok Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[tiktok_review_showcase] src\Shortcode\Showcase.php:19
WordPress Hooks 10
actionplugins_loadedreview-showcase-for-tiktok.php:24
actionadd_meta_boxessrc\Admin\MetaBox.php:19
actionsave_postsrc\Admin\MetaBox.php:20
actioninitsrc\PostType\Review.php:20
filtermanage_edit-tiktok_review_columnssrc\PostType\Review.php:21
actionmanage_tiktok_review_posts_custom_columnsrc\PostType\Review.php:22
actionrestrict_manage_postssrc\PostType\Review.php:23
filterparse_querysrc\PostType\Review.php:24
filtermanage_edit-tiktok_review_sortable_columnssrc\PostType\Review.php:25
actionpre_get_postssrc\PostType\Review.php:26
Maintenance & Trust

Review Showcase for TikTok Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 16, 2025
PHP min version7.4
Downloads292

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Review Showcase for TikTok Developer Profile

Maidul

10 plugins · 1K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
126 days
View full developer profile
Detection Fingerprints

How We Detect Review Showcase for TikTok

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/review-showcase-for-tiktok/assets/css/swiper-bundle.min.css/wp-content/plugins/review-showcase-for-tiktok/assets/js/swiper-bundle.min.js/wp-content/plugins/review-showcase-for-tiktok/assets/css/style.css/wp-content/plugins/review-showcase-for-tiktok/assets/js/showcase.js
Script Paths
https://www.tiktok.com/embed.js
Version Parameters
review-showcase-for-tiktok/assets/css/swiper-bundle.min.css?ver=review-showcase-for-tiktok/assets/js/swiper-bundle.min.js?ver=review-showcase-for-tiktok/assets/css/style.css?ver=review-showcase-for-tiktok/assets/js/showcase.js?ver=

HTML / DOM Fingerprints

CSS Classes
revishfo-showcase-wrapper
Data Attributes
data-tiktok-embed
JS Globals
tiktokEmbed
Shortcode Output
[tiktok_review_showcase]
FAQ

Frequently Asked Questions about Review Showcase for TikTok