Reviews for Elementor Security & Risk Analysis

wordpress.org/plugins/reviews-for-elementor

This plugin will create a testimonial Reviews from Google API for Elementor.

0 active installs v1.1.1 PHP + WP 3.0.1+ Updated Nov 15, 2019
elementorelementor-google-reviewsgooglegoogle-reviews-for-elementorreviews
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Reviews for Elementor Safe to Use in 2026?

Generally Safe

Score 85/100

Reviews for Elementor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The 'reviews-for-elementor' plugin v1.1.1 exhibits a generally strong security posture with several good practices in place. Notably, the static analysis shows no critical or high severity taint flows, no dangerous functions, and all SQL queries utilize prepared statements. The plugin also implements nonce and capability checks, indicating an awareness of common WordPress security vulnerabilities. The absence of any recorded CVEs further supports this positive assessment.

However, a significant concern arises from the output escaping. With 56% of outputs properly escaped, this leaves a considerable portion (44%) vulnerable to Cross-Site Scripting (XSS) attacks. This is a common and impactful vulnerability type that could be exploited if user-provided data is not properly sanitized before being displayed. The plugin also makes external HTTP requests, which, while not inherently insecure, introduce potential risks if the target endpoints are compromised or if the data sent/received is not handled securely.

In conclusion, while the plugin demonstrates a commendable effort in securing its core functionalities and minimizing attack vectors, the unescaped output presents a tangible risk. The vulnerability history is currently clean, but the static analysis highlights a clear area for improvement in output sanitization to prevent potential XSS vulnerabilities.

Key Concerns

  • Significant portion of outputs not properly escaped
  • External HTTP requests present
Vulnerabilities
None known

Reviews for Elementor Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Reviews for Elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
35
44 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
3
Bundled Libraries
1

Bundled Libraries

DataTables

Output Escaping

56% escaped79 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
fetch_google_rfe_reviews (admin\Reviews_for_Elementor_Admin.php:81)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Reviews for Elementor Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_fetch_google_reviewsadmin\Reviews_for_Elementor_Admin.php:46
WordPress Hooks 15
actionplugins_loadedadmin\Reviews_for_Elementor_Admin.php:7
actionadmin_menuadmin\Reviews_for_Elementor_Admin.php:39
actionadmin_initadmin\Reviews_for_Elementor_Admin.php:40
actionadmin_initadmin\Reviews_for_Elementor_Admin.php:41
actionadmin_initadmin\Reviews_for_Elementor_Admin.php:42
actionadmin_enqueue_scriptsadmin\Reviews_for_Elementor_Admin.php:43
actionadmin_initadmin\Reviews_for_Elementor_Admin.php:45
filterexcerpt_moreelementor-modules\testimonial-grid-widget.php:951
filterexcerpt_lengthelementor-modules\testimonial-grid-widget.php:952
actionwp_enqueue_scriptsReviews_for_Elementor.php:33
actionelementor/frontend/before_enqueue_scriptsReviews_for_Elementor.php:34
actionelementor/frontend/before_register_scriptsReviews_for_Elementor.php:40
actionelementor/elements/categories_registeredReviews_for_Elementor.php:53
actionelementor/widgets/widgets_registeredReviews_for_Elementor.php:66
actioninitReviews_for_Elementor.php:143
Maintenance & Trust

Reviews for Elementor Maintenance & Trust

Maintenance Signals

WordPress version tested5.3.21
Last updatedNov 15, 2019
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Reviews for Elementor Developer Profile

WordPress Hilfe & Support Nahiro.net

4 plugins · 110 total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
1472 days
View full developer profile
Detection Fingerprints

How We Detect Reviews for Elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/reviews-for-elementor/assets/js/widgets.js/wp-content/plugins/reviews-for-elementor/assets/css/widgets.css/wp-content/plugins/reviews-for-elementor/assets/css/style_reviews.css/wp-content/plugins/reviews-for-elementor/assets/js/bdt-uikit.js/wp-content/plugins/reviews-for-elementor/assets/js/bdt-uikit-icons.js
Script Paths
/wp-content/plugins/reviews-for-elementor/assets/js/widgets.js/wp-content/plugins/reviews-for-elementor/assets/js/bdt-uikit.js/wp-content/plugins/reviews-for-elementor/assets/js/bdt-uikit-icons.js
Version Parameters
reviews-for-elementor/assets/js/widgets.js?ver=reviews-for-elementor/assets/css/widgets.css?ver=reviews-for-elementor/assets/css/style_reviews.css?ver=reviews-for-elementor/assets/js/bdt-uikit.js?ver=reviews-for-elementor/assets/js/bdt-uikit-icons.js?ver=

HTML / DOM Fingerprints

CSS Classes
elementor-widget-testimonial-grid-widget
Data Attributes
data-elementor-iddata-elementor-post-typedata-elementor-type
JS Globals
RFE_PLG_URL
FAQ

Frequently Asked Questions about Reviews for Elementor