Reviews for WooCommerce Security & Risk Analysis

wordpress.org/plugins/reviews-for-woocommerce

This plugin provides different template to show WooCommerce reviews of any product.

10 active installs v1.0.5 PHP 7.4+ WP 4.0+ Updated Dec 12, 2025
customer-reviewsreview-plugintags-woocommerce-reviewswoocommerce-product-reviews
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Reviews for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Reviews for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The 'reviews-for-woocommerce' plugin, version 1.0.5, presents a generally strong security posture based on the provided static analysis. The plugin demonstrates excellent practices by ensuring all SQL queries are prepared statements and all output is properly escaped. The absence of dangerous functions, file operations, and external HTTP requests further contributes to a secure foundation. Notably, there are no known vulnerabilities (CVEs) associated with this plugin, nor are there any suspicious taint flows or unsanitized paths identified. This lack of historical vulnerabilities and clean static analysis suggests a developer with a good understanding of secure coding principles.

However, there are specific areas that warrant attention. The plugin lacks nonce checks and capability checks across its entry points, which could be a significant concern if any of its functionalities are sensitive or can be triggered by unauthenticated users. While the static analysis reports no unprotected entry points, the absence of these fundamental security mechanisms leaves room for potential exploitation, particularly in more complex attack scenarios. The presence of one shortcode without explicit authorization checks also contributes to this concern. A balanced conclusion is that while the plugin is technically sound in its data handling and SQL usage, its reliance on implicit authorization for its shortcode and the absence of standard WordPress security checks like nonces and capabilities are its primary weaknesses.

Key Concerns

  • Missing nonce checks on shortcode
  • Missing capability checks on shortcode
  • External HTTP requests without clear context
Vulnerabilities
None known

Reviews for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Reviews for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
27 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped27 total outputs
Attack Surface

Reviews for WooCommerce Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[revfwoo_review] includes\class-reviews-for-woocommerce.php:180
WordPress Hooks 6
actionplugins_loadedincludes\class-reviews-for-woocommerce.php:144
actionadmin_enqueue_scriptsincludes\class-reviews-for-woocommerce.php:159
actionadmin_enqueue_scriptsincludes\class-reviews-for-woocommerce.php:160
actionadmin_menuincludes\class-reviews-for-woocommerce.php:161
actionwp_enqueue_scriptsincludes\class-reviews-for-woocommerce.php:177
actionwp_enqueue_scriptsincludes\class-reviews-for-woocommerce.php:178
Maintenance & Trust

Reviews for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 12, 2025
PHP min version7.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Reviews for WooCommerce Developer Profile

ibsofts

5 plugins · 1K total installs

100
trust score
Avg Security Score
100/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect Reviews for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/reviews-for-woocommerce/css/reviews-for-woocommerce-admin.css/wp-content/plugins/reviews-for-woocommerce/js/reviews-for-woocommerce-admin.js
Version Parameters
reviews-for-woocommerce/css/reviews-for-woocommerce-admin.css?ver=reviews-for-woocommerce/js/reviews-for-woocommerce-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
rfw-headerrfw-header h1rfw-header .logo
Data Attributes
data-tab
JS Globals
REVFWOO
FAQ

Frequently Asked Questions about Reviews for WooCommerce