
Review Stars Count For WooCommerce Security & Risk Analysis
wordpress.org/plugins/review-stars-count-for-woocommerceThis plugin allows your visitors to see a visual overview of total stars/reviews given to a specific product.
Is Review Stars Count For WooCommerce Safe to Use in 2026?
Mostly Safe
Score 78/100Review Stars Count For WooCommerce is generally safe to use. 1 past CVE were resolved. Keep it updated.
The "review-stars-count-for-woocommerce" v2.0 plugin presents a concerning security posture, primarily due to a lack of proper authentication and validation checks on its entry points. All three identified AJAX handlers are unprotected, creating a significant attack surface that could be exploited by unauthenticated users. The plugin also demonstrates poor coding practices with 100% of its SQL queries not using prepared statements, and a very low percentage of output being properly escaped. Furthermore, taint analysis indicates flows with unsanitized paths, though no critical or high severity issues were reported in this specific analysis.
The plugin's vulnerability history is also a major red flag. It has one known medium-severity CVE, which is currently unpatched. The common vulnerability type being SQL Injection, coupled with the static analysis revealing raw SQL queries, strongly suggests a recurring pattern of insecure database interaction. This unpatched vulnerability and the overall lack of security best practices in the code point to a significant risk of compromise, potentially leading to data breaches or unauthorized modifications.
While the plugin has no identified dangerous functions, file operations, or external HTTP requests, and no bundled libraries that might be outdated, these strengths are heavily overshadowed by the critical deficiencies in authentication, data sanitization, and the presence of an unpatched vulnerability. The overall recommendation is to exercise extreme caution when using this plugin and to prioritize updating or replacing it.
Key Concerns
- Unprotected AJAX handlers
- Raw SQL without prepared statements
- Low output escaping percentage
- Unpatched medium CVE
- Flows with unsanitized paths
- No nonce checks on AJAX handlers
- No capability checks on AJAX handlers
Review Stars Count For WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Review Stars Count For WooCommerce <= 2.0 - Authenticated (Subscriber+) SQL Injection
Review Stars Count For WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Review Stars Count For WooCommerce Attack Surface
AJAX Handlers 3
WordPress Hooks 14
Maintenance & Trust
Review Stars Count For WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Review Stars Count For WooCommerce Alternatives
Photo Reviews for WooCommerce
woo-photo-reviews
Let customers attach photos to reviews, enhanced with filterable grids and overall ratings. Auto-send review reminders and coupon emails
ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema
reviewx
Drive woocommerce business growth with social proof: gather product reviews with multicriteria ratings, auto-reminder emails, discounts, and more.
Faview – Virtual Reviews for WooCommerce
woo-virtual-reviews
Faview - Virtual Reviews for WooCommerce generates and displays canned reviews to boost your customer engagement.
Customer Reviews Collector for WooCommerce
customer-reviews-collector-for-woocommerce
Collect reviews on Google, Facebook, Yelp, Trustindex and other platforms automatically, with the help of our system.
Ryviu – Product Reviews for WooCommerce
ryviu
Install Ryviu quickly and easily into your WordPress site. Boost eco-friendly eCommerce with trusted reviews and increased sales growth.
Review Stars Count For WooCommerce Developer Profile
8 plugins · 2K total installs
How We Detect Review Stars Count For WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/review-stars-count-for-woocommerce/css/custom-star-rating.css/wp-content/plugins/review-stars-count-for-woocommerce/css/animated.css/wp-content/plugins/review-stars-count-for-woocommerce/js/hover-intent.js/wp-content/plugins/review-stars-count-for-woocommerce/js/custom-star-rating.js/wp-content/plugins/review-stars-count-for-woocommerce/css/custom-star-rating-admin.csshttps://cdnjs.cloudflare.com/ajax/libs/font-awesome/4.7.0/css/font-awesome.min.cssreview-stars-count-for-woocommerce/js/hover-intent.js?ver=review-stars-count-for-woocommerce/js/custom-star-rating.js?ver=HTML / DOM Fingerprints
mg-activemg-cmnt-likemg-cmnt-unlikecmnt-lastlikeidloginUrlcommentIdauthcheckStarCount