
Widgets for Amazon Reviews Security & Risk Analysis
wordpress.org/plugins/review-widgets-for-amazonEmbed Amazon reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Amazon reviews.
Is Widgets for Amazon Reviews Safe to Use in 2026?
Generally Safe
Score 100/100Widgets for Amazon Reviews has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'review-widgets-for-amazon' plugin v13.2.7 exhibits a concerning security posture due to a significant number of unprotected entry points. While the plugin demonstrates good practices in output escaping and SQL query preparation, the presence of three unprotected entry points (one AJAX handler and two REST API routes) creates a substantial attack surface. This means that unauthenticated users could potentially interact with these functions, leading to unintended actions or information disclosure.
The code analysis also flags the use of the `unserialize` function, which can be a significant security risk if not handled with extreme caution, as it can lead to Remote Code Execution (RCE) if untrusted data is unserialized. While the taint analysis did not reveal critical or high severity flows, the existence of one flow with an unsanitized path warrants attention, as it could potentially be exploited.
The plugin's vulnerability history is positive, showing no known CVEs. This suggests a history of good security development or at least a lack of discovered vulnerabilities. However, the current static analysis findings, particularly the unprotected entry points and the use of `unserialize`, overshadow this positive history. The plugin has strengths in its output escaping and SQL query preparation, but the critical weakness lies in its unprotected entry points and the potential risks associated with unserialization.
Key Concerns
- Unprotected AJAX handler
- Unprotected REST API routes
- Dangerous function: unserialize
- Flow with unsanitized path
Widgets for Amazon Reviews Security Vulnerabilities
Widgets for Amazon Reviews Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Widgets for Amazon Reviews Attack Surface
AJAX Handlers 1
REST API Routes 2
WordPress Hooks 36
Maintenance & Trust
Widgets for Amazon Reviews Maintenance & Trust
Maintenance Signals
Community Trust
Widgets for Amazon Reviews Alternatives
WP Testimonials
testimonial-widgets
Display your Testimonials on your website fast and easily. 21 widget types, 25 widget styles available. (Free Plugin)
Widgets for Thumbtack Reviews
widgets-for-thumbtack-reviews
Embed Thumbtack reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Thumbtack reviews.
Widgets for Ebay Reviews
widgets-for-ebay-reviews
Embed Ebay reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Ebay reviews.
Widgets for Zillow Reviews
widgets-for-zillow-reviews
Embed Zillow reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Zillow reviews.
Widgets for Capterra Reviews
review-widgets-for-capterra
Embed Capterra reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Capterra reviews.
Widgets for Amazon Reviews Developer Profile
32 plugins · 976K total installs
How We Detect Widgets for Amazon Reviews
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/review-widgets-for-amazon/assets/css/trustindex-owl.css/wp-content/plugins/review-widgets-for-amazon/assets/css/trustindex-style.css/wp-content/plugins/review-widgets-for-amazon/assets/js/trustindex-owl.js/wp-content/plugins/review-widgets-for-amazon/assets/js/trustindex-script.jshttps://cdn.trustindex.io/loader.jsreview-widgets-for-amazon/assets/css/trustindex-owl.css?ver=review-widgets-for-amazon/assets/css/trustindex-style.css?ver=review-widgets-for-amazon/assets/js/trustindex-owl.js?ver=review-widgets-for-amazon/assets/js/trustindex-script.js?ver=HTML / DOM Fingerprints
ti-close-notificationtrustindex-notification-rowCopyright 2019 Trustindex Kft (email: support@trustindex.io)data-ccm-injectedtrustindex_pm_amazonpluginManagerInstance/wp-json/trustindex/v1/api/wp-json/trustindex/v1/reviews[trustindex_amazon]