Review Slider for WooCommerce Security & Risk Analysis

wordpress.org/plugins/review-slider-for-woocommerce

Show off your WooCommerce reviews on your Homepage. Allows you to display review slider or grid of all your reviews for your WooCommerce products!

500 active installs v1.5 PHP + WP 3.0.1+ Updated Dec 3, 2025
review-slider-for-woocommercewoocommerce-review-sliderwoocommerce-reviews
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Review Slider for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Review Slider for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The 'review-slider-for-woocommerce' plugin v1.5 exhibits a mixed security posture. While it demonstrates good practices in terms of output escaping (83% properly escaped) and has no recorded vulnerabilities or critical taint flows, there are significant areas of concern regarding its attack surface and internal security checks. The presence of three unprotected AJAX handlers presents a direct entry point for potential attackers to interact with the plugin's functionality without proper authentication or authorization. Furthermore, a substantial percentage of SQL queries (65%) are not using prepared statements, which can leave the plugin vulnerable to SQL injection attacks if user-supplied data is not rigorously sanitized before being included in queries. The absence of critical or high-severity issues in taint analysis and vulnerability history is a positive indicator, suggesting the core logic might be relatively sound. However, the unprotected AJAX endpoints and the reliance on non-prepared SQL statements are fundamental weaknesses that could be exploited.

Key Concerns

  • Unprotected AJAX handlers
  • SQL queries without prepared statements
Vulnerabilities
None known

Review Slider for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Review Slider for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
13
7 prepared
Unescaped Output
30
146 escaped
Nonce Checks
4
Capability Checks
5
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

35% prepared20 total queries

Output Escaping

83% escaped176 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
<review_list> (admin\partials\review_list.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
3 unprotected

Review Slider for WooCommerce Attack Surface

Entry Points4
Unprotected3

AJAX Handlers 3

authwp_ajax_srfw_get_resultsincludes\class-review-slider-for-woocommerce.php:280
authwp_ajax_srfw_hide_reviewincludes\class-review-slider-for-woocommerce.php:283
authwp_ajax_srfw_find_reviewsincludes\class-review-slider-for-woocommerce.php:286

Shortcodes 1

[srfw_usetemplate] public\class-review-slider-for-woocommerce-public.php:124
WordPress Hooks 16
actionadmin_enqueue_scriptsincludes\class-review-slider-for-woocommerce.php:266
actionadmin_enqueue_scriptsincludes\class-review-slider-for-woocommerce.php:268
actionadmin_initincludes\class-review-slider-for-woocommerce.php:274
actionadmin_menuincludes\class-review-slider-for-woocommerce.php:277
actionadmin_noticesincludes\class-review-slider-for-woocommerce.php:289
actionadmin_initincludes\class-review-slider-for-woocommerce.php:292
actionadmin_initincludes\class-review-slider-for-woocommerce.php:295
actioncomment_postincludes\class-review-slider-for-woocommerce.php:298
actionedit_commentincludes\class-review-slider-for-woocommerce.php:299
actiondeleted_commentincludes\class-review-slider-for-woocommerce.php:300
actiontransition_comment_statusincludes\class-review-slider-for-woocommerce.php:301
actionwp_enqueue_scriptsincludes\class-review-slider-for-woocommerce.php:318
actionwp_enqueue_scriptsincludes\class-review-slider-for-woocommerce.php:319
actioninitpublic\class-review-slider-for-woocommerce-template_action.php:3
actionwprev_srfw_plugin_actionpublic\class-review-slider-for-woocommerce-template_action.php:24
actionsrfw_daily_eventreview-slider-for-woocommerce.php:88
Maintenance & Trust

Review Slider for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 3, 2025
PHP min version
Downloads6K

Community Trust

Rating94/100
Number of ratings12
Active installs500
Developer Profile

Review Slider for WooCommerce Developer Profile

jgwhite33

11 plugins · 48K total installs

74
trust score
Avg Security Score
93/100
Avg Patch Time
201 days
View full developer profile
Detection Fingerprints

How We Detect Review Slider for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/review-slider-for-woocommerce/public/css/srfw-public_template1.css/wp-content/plugins/review-slider-for-woocommerce/admin/css/srfw_admin.css/wp-content/plugins/review-slider-for-woocommerce/admin/css/srfw_w3.css/wp-content/plugins/review-slider-for-woocommerce/admin/js/srfw_simple-popup.min.js/wp-content/plugins/review-slider-for-woocommerce/admin/js/srfw_review_list_page.js/wp-content/plugins/review-slider-for-woocommerce/admin/js/srfw_templates_posts_page.js
Script Paths
js/srfw_simple-popup.min.jsjs/srfw_review_list_page.jsjs/srfw_templates_posts_page.js
Version Parameters
review-slider-for-woocommerce/public/css/srfw-public_template1.css?ver=review-slider-for-woocommerce/admin/css/srfw_admin.css?ver=review-slider-for-woocommerce/admin/css/srfw_w3.css?ver=js/srfw_simple-popup.min.js?ver=js/srfw_review_list_page.js?ver=js/srfw_templates_posts_page.js?ver=

HTML / DOM Fingerprints

CSS Classes
srfw_main_slider
Data Attributes
data-srfw-id
JS Globals
adminjs_script_vars
FAQ

Frequently Asked Questions about Review Slider for WooCommerce