
Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More Security & Risk Analysis
wordpress.org/plugins/reviews-feedNo API key required. Display Yelp and Google reviews for any business in a clean, customizable feed on your site.
Is Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More Safe to Use in 2026?
Generally Safe
Score 99/100Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More has a strong security track record. Known vulnerabilities have been patched promptly.
The 'reviews-feed' v2.4.6 plugin exhibits a mixed security posture. While it demonstrates good practices such as a high percentage of SQL prepared statements and proper output escaping, significant concerns arise from its attack surface and taint analysis. The presence of 3 AJAX handlers without authentication checks represents a direct pathway for potential unauthorized actions, especially when considered alongside the taint analysis which revealed 6 high-severity flows with unsanitized paths. These unsanitized paths could lead to various vulnerabilities if exploited by an attacker. The plugin's vulnerability history, though currently showing no unpatched CVEs, has previously included medium-severity Cross-Site Request Forgery (CSRF) and Missing Authorization issues. This pattern suggests a recurring need for robust authorization and input validation. Overall, the plugin has strengths in data handling but requires immediate attention to its unprotected entry points and identified high-severity taint flows to mitigate substantial risks.
Key Concerns
- 3 AJAX handlers without auth checks
- 6 high severity taint flows (unsanitized paths)
- Previous medium CVEs (CSRF, Missing Authorization)
Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More <= 1.1.2 - Cross-Site Request Forgery
Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More <= 1.1.2 - Missing Authorization to Authenticated (Subscriber+) Limited Settings Update
Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More Attack Surface
AJAX Handlers 52
Shortcodes 2
WordPress Hooks 32
Scheduled Events 1
Maintenance & Trust
Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More Maintenance & Trust
Maintenance Signals
Community Trust
Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More Alternatives
Rich Showcase for Google Reviews
widget-google-reviews
Display up to 10 Google reviews in less than a minute. Continue collecting new reviews. No limits on connected places, widgets, shortcodes and blocks.
Reviews Widgets for Google, Yelp & TripAdvisor
fb-reviews-widget
Combine Facebook recommendations with Google, Yelp and TripAdvisor reviews in a widget, block or shortcode. Build a trusted website!
Reviews Block for Google
google-places-reviews
Easily display Google business reviews on your WordPress website with a simple and intuitive block.
Widgets for Google Business Reviews and Ratings
widgets-for-google-reviews-and-ratings
🛠️ Display Google Business Reviews on your WordPress website to build credibility, boost customer trust, and improve SEO with Google Rich Snippets
Widget for Google Reviews
business-reviews-wp
Shortcode and widget for Google Reviews. Display Google Business Reviews on your WordPress website to increase user confidence and SEO.
Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More Developer Profile
94 plugins · 23.5M total installs
How We Detect Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/reviews-feed/assets/css/sbr-styles.css/wp-content/plugins/reviews-feed/assets/css/sbr-styles.min.css/wp-content/plugins/reviews-feed/assets/js/sbr-blocks.js/wp-content/plugins/reviews-feed/assets/js/sbr-blocks.jssbr-block-styles?ver=sbr-feed-block?ver=HTML / DOM Fingerprints
sbr-notice-alertCopyright 2024 Smash Balloon LLC (email : hey@smashballoon.com)This program is free software; you can redistribute it and/or modifyThis program is distributed in the hope that it will be useful,See the+13 moredata-block="sbr/sbr-feed-block"sbr_block_editor[reviews-feed