
Widgets for Foursquare Reviews Security & Risk Analysis
wordpress.org/plugins/review-widgets-for-foursquareEmbed Foursquare reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Foursquare reviews.
Is Widgets for Foursquare Reviews Safe to Use in 2026?
Generally Safe
Score 100/100Widgets for Foursquare Reviews has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "review-widgets-for-foursquare" plugin v13.2.7 exhibits several concerning security weaknesses, despite some positive indicators. The plugin presents a significant attack surface with three identified entry points, all of which are unprotected by authentication or permission checks. This means that any unauthenticated user could potentially interact with these points, leading to unintended actions or information disclosure. The static analysis also revealed a "dangerous function" `unserialize`, which, if combined with unsanitized user input, could lead to serious vulnerabilities like Remote Code Execution. While the plugin demonstrates good practices in SQL query preparation and output escaping, the lack of security on its entry points and the presence of `unserialize` are critical flaws. The vulnerability history being clean is a positive sign, suggesting the developers may be responsive or that the plugin hasn't been a target. However, the current code analysis indicates potential for severe issues that haven't manifested as publicly known vulnerabilities yet. The overall risk is elevated due to the unprotected entry points and the `unserialize` function, overshadowing the good practices observed in other areas.
Key Concerns
- Unprotected AJAX handler
- Unprotected REST API route (callback missing)
- Unprotected REST API route (callback missing)
- Dangerous function 'unserialize' present
- Flow with unsanitized path (taint analysis)
Widgets for Foursquare Reviews Security Vulnerabilities
Widgets for Foursquare Reviews Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Widgets for Foursquare Reviews Attack Surface
AJAX Handlers 1
REST API Routes 2
WordPress Hooks 36
Maintenance & Trust
Widgets for Foursquare Reviews Maintenance & Trust
Maintenance Signals
Community Trust
Widgets for Foursquare Reviews Alternatives
Review Widgets for Szallas.hu
review-widgets-for-szallas-hu
Szállás.hu review widgets. Show your szallas.hu reviews on your WordPress website to build trust and increase your SEO.
WP Testimonials
testimonial-widgets
Display your Testimonials on your website fast and easily. 21 widget types, 25 widget styles available. (Free Plugin)
Widgets for Amazon Reviews
review-widgets-for-amazon
Embed Amazon reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Amazon reviews.
Widgets for Thumbtack Reviews
widgets-for-thumbtack-reviews
Embed Thumbtack reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Thumbtack reviews.
Widgets for Ebay Reviews
widgets-for-ebay-reviews
Embed Ebay reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Ebay reviews.
Widgets for Foursquare Reviews Developer Profile
32 plugins · 976K total installs
How We Detect Widgets for Foursquare Reviews
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/review-widgets-for-foursquare/css/admin.css/wp-content/plugins/review-widgets-for-foursquare/css/frontend.css/wp-content/plugins/review-widgets-for-foursquare/js/admin.js/wp-content/plugins/review-widgets-for-foursquare/js/frontend.jshttps://cdn.trustindex.io/loader.jsreview-widgets-for-foursquare/css/admin.css?ver=review-widgets-for-foursquare/css/frontend.css?ver=review-widgets-for-foursquare/js/admin.js?ver=review-widgets-for-foursquare/js/frontend.js?ver=HTML / DOM Fingerprints
trustindex-notification-rowCopyright 2019 Trustindex Kft (email: support@trustindex.io)data-ccm-injectedtrustindex_pm_foursquareTrustindexPlugin_foursquareti_woocommerce_notice/wp-json/trustindex/v1/sync