Reviews Sorted Security & Risk Analysis

wordpress.org/plugins/reviews-sorted

Collect and display verified customer reviews with star ratings, schema markup, and Google reviews on your site.

20 active installs v2.4.3 PHP 7.4+ WP 5.6+ Updated Mar 2, 2026
customer-reviewsgoogle-reviewsreviewsschema-markupstar-rating
78
B · Generally Safe
CVEs total1
Unpatched1
Last CVEDec 11, 2025
Safety Verdict

Is Reviews Sorted Safe to Use in 2026?

Mostly Safe

Score 78/100

Reviews Sorted is generally safe to use. 1 past CVE were resolved. Keep it updated.

1 known CVE 1 unpatched Last CVE: Dec 11, 2025Updated 1mo ago
Risk Assessment

The "reviews-sorted" plugin version 2.4.3 exhibits a generally positive security posture due to its consistent use of prepared statements for all SQL queries and a high percentage of properly escaped output. The presence of nonce and capability checks on its entry points further reinforces good security practices. However, there are notable areas for concern. The taint analysis revealed two flows with unsanitized paths, specifically categorized as high severity. While the static analysis did not directly pinpoint a vulnerability from these flows, their presence indicates potential for sensitive data exposure or unexpected behavior if not handled carefully. The plugin's vulnerability history, while showing only one medium severity CVE, is concerning because it is currently unpatched. The nature of the previous vulnerability being Cross-site Scripting (XSS) suggests that unsanitized input handling could be a recurring issue. Therefore, while the plugin is built on a solid foundation of secure coding principles, the identified taint flows and the unpatched XSS vulnerability warrant attention and mitigation to ensure comprehensive security.

Key Concerns

  • High severity unsanitized taint flows
  • Unpatched medium severity CVE
Vulnerabilities
1

Reviews Sorted Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-13969medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Reviews Sorted <= 2.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'space' Shortcode Attribute

Dec 11, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Reviews Sorted Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
23 prepared
Unescaped Output
4
666 escaped
Nonce Checks
7
Capability Checks
5
File Operations
2
External Requests
3
Bundled Libraries
0

SQL Query Safety

100% prepared23 total queries

Output Escaping

99% escaped670 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

7 flows2 with unsanitized paths
review_sorted_save_settings (admin\admin-ui-setup.php:43)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Reviews Sorted Attack Surface

Entry Points11
Unprotected0

AJAX Handlers 3

authwp_ajax_reviews_sorted_verify_keyadmin\admin-ui-setup.php:151
authwp_ajax_rs_reviews_submitfunctions\do.php:40
noprivwp_ajax_rs_reviews_submitfunctions\do.php:41

Shortcodes 8

[reviews-form] functions\do.php:46
[reviews-slider] functions\do.php:47
[reviews-average] functions\do.php:48
[reviews-carousel] functions\do.php:49
[reviews-grid] functions\do.php:50
[reviews-list] functions\do.php:51
[reviews-masonry] functions\do.php:52
[reviews-testimonials] functions\do.php:53
WordPress Hooks 12
actionadmin_menuadmin\admin-ui-setup.php:40
actionadmin_postadmin\admin-ui-setup.php:42
actionplugins_loadedadmin\basic-setup.php:130
filteradmin_footer_textadmin\basic-setup.php:171
filterupdate_footeradmin\basic-setup.php:188
actionwp_enqueue_scriptsfunctions\do.php:43
actionadmin_enqueue_scriptsfunctions\do.php:54
actionwp_headfunctions\do.php:56
actionadmin_initreviews-sorted.php:53
actionadmin_noticesreviews-sorted.php:74
actionadmin_initreviews-sorted.php:80
actionadmin_initreviews-sorted.php:171
Maintenance & Trust

Reviews Sorted Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 2, 2026
PHP min version7.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Reviews Sorted Developer Profile

Eurisko

1 plugin · 20 total installs

79
trust score
Avg Security Score
78/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Reviews Sorted

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/reviews-sorted/assets/css/style.css/wp-content/plugins/reviews-sorted/assets/css/reviews-sorted-responsive.css/wp-content/plugins/reviews-sorted/assets/js/reviews-sorted.js
Script Paths
/wp-content/plugins/reviews-sorted/assets/js/reviews-sorted.js
Version Parameters
reviews-sorted/assets/css/style.css?ver=reviews-sorted/assets/css/reviews-sorted-responsive.css?ver=reviews-sorted/assets/js/reviews-sorted.js?ver=

HTML / DOM Fingerprints

CSS Classes
review-sorted-notice
Data Attributes
data-rs-id
JS Globals
ReviewsSortedFrontend
FAQ

Frequently Asked Questions about Reviews Sorted