
Reviews Plus Security & Risk Analysis
wordpress.org/plugins/reviews-plusReviews Plus activates rich reviews for selected content. Turns comments into reviews and provides 100% SERP compatible reviews system.
Is Reviews Plus Safe to Use in 2026?
Generally Safe
Score 99/100Reviews Plus has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "reviews-plus" v1.4.1 plugin exhibits a mixed security posture. On the positive side, the static analysis indicates a relatively small attack surface with no identified unprotected AJAX handlers or REST API routes. The code also shows a reasonable effort towards security with a good percentage of SQL queries using prepared statements and a decent number of capability checks. However, the presence of unsanitized paths in the taint analysis is a significant concern, suggesting potential vulnerabilities where user input might be used in file operations or other sensitive functions without proper validation. The vulnerability history is also a red flag, with two medium-severity CVEs historically, including one related to Missing Authorization and another to Uncontrolled Resource Consumption. While currently unpatched vulnerabilities are zero, the past patterns indicate that the plugin has had issues in these critical areas.
Key Concerns
- Taint flows with unsanitized paths
- Past medium severity CVEs (2 total)
- Output escaping: 64% properly escaped (concern)
- SQL queries: 71% using prepared statements (concern)
Reviews Plus Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Reviews Plus <= 1.3.4 - Missing Authorization to Notice Dismissal
Reviews Plus < 1.2.14 - Denial of Service
Reviews Plus Release Timeline
Reviews Plus Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Reviews Plus Attack Surface
AJAX Handlers 2
Shortcodes 4
WordPress Hooks 71
Maintenance & Trust
Reviews Plus Maintenance & Trust
Maintenance Signals
Community Trust
Reviews Plus Alternatives
Builder for WooCommerce product reviews shortcodes – ReviewShort
woo-product-reviews-shortcode
Show WooCommerce customer feedback anywhere with WooCommerce reviews shortcodes, beautifully and ...
weeComments – Shop & Products Reviews
weecomments
Genera confianza en tu tienda online y aumenta las ventas con weecomments. http://weecomments.com Muestra un widget de opiniones de la tienda online, …
Site Reviews
site-reviews
Site Reviews is a complete review management solution that integrates with WooCommerce and SureCart and works similarly to reviews on Amazon, Tripadvi …
Reviews and Rating – Google Reviews
g-business-reviews-rating
Completely restriction-free Google reviews and rating as Shortcode/Widget. Extensive display options; delicious themes; includes Structured Data.
Gutena Star Ratings
gutena-star-ratings
Gutena Star Ratings is a great block that lets you add star rating to client testimonials and reviews. Not only the star rating will tell customers ho …
Reviews Plus Developer Profile
7 plugins · 11K total installs
How We Detect Reviews Plus
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/reviews-plus/css/reviews-plus.min.css/wp-content/plugins/reviews-plus/js/reviews-plus.min.js/wp-content/plugins/reviews-plus/css/reviews-plus-admin.min.css/wp-content/plugins/reviews-plus/js/reviews-plus-editor.min.js/wp-content/plugins/reviews-plus/js/reviews-plus-admin.min.jsreviews-plus/css/reviews-plus.min.css?ver=reviews-plus/js/reviews-plus.min.js?ver=reviews-plus/css/reviews-plus-admin.min.css?ver=reviews-plus/js/reviews-plus-editor.min.js?ver=reviews-plus/js/reviews-plus-admin.min.js?ver=HTML / DOM Fingerprints
reviews-areacatalog-headerreview-ratingrating-labelno-commentsdata-current_ratingic_revsreviews_object