Reviewer Rich Snippets Security & Risk Analysis

wordpress.org/plugins/reviewer-rich-snippets

Increase the visibility of your review in the search engines by adding additional markup.

10 active installs v1.0.0 PHP + WP 4.0+ Updated Nov 9, 2017
google-starsreviewerrich-snippetsstar-ratingsstructured-data
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Reviewer Rich Snippets Safe to Use in 2026?

Generally Safe

Score 85/100

Reviewer Rich Snippets has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The reviewer-rich-snippets plugin version 1.0.0 exhibits a concerning security posture despite a clean vulnerability history and a seemingly small attack surface. The static analysis reveals a complete lack of output escaping for all identified output points. This means any data rendered by the plugin to the user interface is not being properly sanitized, creating a significant risk of Cross-Site Scripting (XSS) vulnerabilities. While the absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is positive, the lack of proper output escaping is a critical oversight that can be easily exploited. The zero AJAX handlers, REST API routes, shortcodes, and cron events suggest a limited functional scope, which might contribute to the lack of recorded vulnerabilities. However, the presence of any unescaped output can be exploited independently of other entry points. Therefore, the plugin's current state presents a moderate to high risk due to the critical flaw in output sanitization, outweighing its otherwise clean record and limited attack vectors.

Key Concerns

  • No output escaping for all identified outputs
Vulnerabilities
None known

Reviewer Rich Snippets Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Reviewer Rich Snippets Release Timeline

v1.0.0Current
Code Analysis
Analyzed Mar 17, 2026

Reviewer Rich Snippets Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped6 total outputs
Attack Surface

Reviewer Rich Snippets Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionplugins_loadedclass-reviewer-rich-snippets.php:159
actionreviewer\review\headincludes\template-functions.php:21
actioninitincludes\template-functions.php:24
Maintenance & Trust

Reviewer Rich Snippets Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedNov 9, 2017
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Reviewer Rich Snippets Developer Profile

Jeroen Sormani

10 plugins · 92K total installs

84
trust score
Avg Security Score
94/100
Avg Patch Time
35 days
View full developer profile
Detection Fingerprints

How We Detect Reviewer Rich Snippets

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/reviewer-rich-snippets/assets/css/reviewer-rich-snippets.css/wp-content/plugins/reviewer-rich-snippets/assets/js/reviewer-rich-snippets.js
Script Paths
/wp-content/plugins/reviewer-rich-snippets/assets/js/reviewer-rich-snippets.js
Version Parameters
reviewer-rich-snippets/assets/css/reviewer-rich-snippets.css?ver=reviewer-rich-snippets/assets/js/reviewer-rich-snippets.js?ver=

HTML / DOM Fingerprints

CSS Classes
reviewer-rich-snippets-wrapper
Data Attributes
itemprop="review"itemscopeitemtype="http://schema.org/Review"itemprop="itemReviewed"itemprop="description"itemprop="author"+7 more
Shortcode Output
<div itemprop="review" itemscope itemtype="http://schema.org/Review"><meta itemprop="itemReviewed" content="<meta itemprop="description" content="<meta itemprop="author" content="
FAQ

Frequently Asked Questions about Reviewer Rich Snippets