Reviews for Google My Business Security & Risk Analysis

wordpress.org/plugins/reviews-for-google-my-business

Display Google My Business reviews on your website for free. Improve credibility with full customization, categories, and flexible shortcode.

20 active installs v1.0.7 PHP 8.0+ WP 6.8+ Updated Dec 22, 2025
google-my-businessgoogle-reviewsreviewssocial-prooftestimonials
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Reviews for Google My Business Safe to Use in 2026?

Generally Safe

Score 100/100

Reviews for Google My Business has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The plugin "reviews-for-google-my-business" v1.0.7 exhibits a generally strong security posture based on the provided static analysis. The absence of any recorded vulnerabilities, including critical or high severity ones, is a significant positive indicator. Furthermore, the code demonstrates good security practices with 100% output escaping and a high percentage of SQL queries using prepared statements. The presence of numerous nonce and capability checks on its entry points (AJAX handlers and shortcodes) further bolsters its defenses, indicating a proactive approach to preventing common web vulnerabilities. However, the static analysis does reveal one flow with unsanitized paths, which warrants further investigation. While the severity is not explicitly stated as critical or high in the taint analysis, any unsanitized path represents a potential vector for attackers. The presence of file operations and external HTTP requests also introduces inherent risks, although the analysis does not flag them as immediately exploitable without additional context.

Key Concerns

  • Flow with unsanitized paths
Vulnerabilities
None known

Reviews for Google My Business Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Reviews for Google My Business Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
4 prepared
Unescaped Output
1
244 escaped
Nonce Checks
13
Capability Checks
17
File Operations
2
External Requests
6
Bundled Libraries
0

SQL Query Safety

67% prepared6 total queries

Output Escaping

100% escaped245 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

4 flows1 with unsanitized paths
wgmbr_save_credentials (includes\admin.php:312)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Reviews for Google My Business Attack Surface

Entry Points10
Unprotected0

AJAX Handlers 9

authwp_ajax_wgmbr_refresh_locationsincludes\admin.php:227
authwp_ajax_wgmbr_clear_cacheincludes\admin.php:271
authwp_ajax_wgmbr_test_connectionincludes\admin.php:304
authwp_ajax_wgmbr_save_customizationincludes\admin.php:523
authwp_ajax_wgmbr_reset_customizationincludes\admin.php:549
authwp_ajax_wgmbr_sync_reviewsincludes\admin.php:614
authwp_ajax_wgmbr_create_categoryincludes\admin.php:671
authwp_ajax_wgmbr_delete_categoryincludes\admin.php:722
authwp_ajax_wgmbr_save_reviewincludes\admin.php:784

Shortcodes 1

[wgmbr_reviews] includes\shortcode.php:188
WordPress Hooks 11
actionadmin_menuincludes\admin.php:46
actionadmin_enqueue_scriptsincludes\admin.php:131
actionadmin_post_wgmbr_save_credentialsincludes\admin.php:361
actionadmin_post_wgmbr_save_locationincludes\admin.php:409
actionadmin_post_wgmbr_revokeincludes\admin.php:431
actionadmin_post_wgmbr_save_customizationincludes\admin.php:505
actioninitincludes\api.php:656
actioninitincludes\post-types.php:55
actioninitincludes\post-types.php:96
actionplugins_loadedreviews-for-google-my-business.php:95
actionbefore_delete_postreviews-for-google-my-business.php:107
Maintenance & Trust

Reviews for Google My Business Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 22, 2025
PHP min version8.0
Downloads404

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Reviews for Google My Business Developer Profile

Fanny Peneau

1 plugin · 20 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Reviews for Google My Business

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/reviews-for-google-my-business/assets/css/admin.css/wp-content/plugins/reviews-for-google-my-business/assets/js/admin.js/wp-content/plugins/reviews-for-google-my-business/assets/css/frontend.css/wp-content/plugins/reviews-for-google-my-business/assets/js/frontend.js
Version Parameters
reviews-for-google-my-business/assets/css/admin.css?ver=reviews-for-google-my-business/assets/js/admin.js?ver=reviews-for-google-my-business/assets/css/frontend.css?ver=reviews-for-google-my-business/assets/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
gmb-headergmb-reviews-containergmb-reviews-widget
HTML Comments
<!-- Reviews for Google My Business --><!-- Google My Business Reviews Widget --><!-- End Google My Business Reviews Widget -->
Data Attributes
data-gmb-widget-iddata-gmb-place-iddata-gmb-api-keydata-gmb-max-resultsdata-gmb-review-displaydata-gmb-carousel+6 more
JS Globals
wgmbr_params
Shortcode Output
[google_reviews[reviews_google_my_business
FAQ

Frequently Asked Questions about Reviews for Google My Business