
Reviews UP Security & Risk Analysis
wordpress.org/plugins/reviews-upThe Reviews UP Widget is a powerful and easy-to-use WordPress plugin that allows you to showcase customer reviews and testimonials directly on your we …
Is Reviews UP Safe to Use in 2026?
Generally Safe
Score 92/100Reviews UP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "reviews-up" plugin version 1.0.12 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is commendable. Furthermore, the high rate of output escaping (92%) indicates a good effort to prevent cross-site scripting vulnerabilities. The plugin's attack surface is limited to two shortcodes, with no immediately apparent unprotected entry points, and the vulnerability history being clean is a significant positive indicator.
However, a notable concern is the complete absence of nonce checks and capability checks. This implies that the shortcode functionality might be susceptible to CSRF attacks or unauthorized execution if specific conditions are met, especially if user-supplied data is processed without these fundamental security measures. While taint analysis shows no immediate critical or high severity flows, the lack of these checks creates a potential avenue for exploitation that wasn't captured by the taint analysis itself. The plugin's clean vulnerability history is a strength, but it doesn't entirely mitigate the risks associated with missing core security features.
In conclusion, "reviews-up" demonstrates good development practices in many areas, particularly regarding data sanitization and preventing common attack vectors. The clean vulnerability record is a positive sign. Nevertheless, the lack of nonce and capability checks presents a tangible risk that could be exploited if the shortcodes handle user-controlled data in a sensitive manner. Addressing these missing checks would significantly enhance the plugin's security.
Key Concerns
- Missing Nonce Checks
- Missing Capability Checks
- Unescaped Output (8% of outputs)
Reviews UP Security Vulnerabilities
Reviews UP Code Analysis
Output Escaping
Reviews UP Attack Surface
Shortcodes 2
WordPress Hooks 6
Maintenance & Trust
Reviews UP Maintenance & Trust
Maintenance Signals
Community Trust
Reviews UP Alternatives
Site Reviews
site-reviews
Site Reviews is a complete review management solution that integrates with WooCommerce and SureCart and works similarly to reviews on Amazon, Tripadvi …
Better Business Reviews – Trustpilot WordPress Plugin
better-business-reviews
Better Business Reviews allows you to display your business reviews from a Trustpilot profile.
Widgets for Google Business Reviews and Ratings
widgets-for-google-reviews-and-ratings
🛠️ Display Google Business Reviews on your WordPress website to build credibility, boost customer trust, and improve SEO with Google Rich Snippets
Review Stream
review-stream
Stream your latest and greatest reviews from around the Web to your Wordpress site and display them with SEO-friendly rich-snippet markup.
Starfish Review Generation & Marketing for WordPress
starfish-reviews
The best WordPress plugin for generating 5-star customer reviews on Google, Facebook, Tripadvisor, and many more platforms.
Reviews UP Developer Profile
1 plugin · 10 total installs
How We Detect Reviews UP
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/reviews-up/style.css/wp-content/plugins/reviews-up/assets/floating.jshttps://app.getreviewsup.com/api/jsHTML / DOM Fingerprints
video-containervideoinput__widershortcodemarginid="ru-widget-name='revup_options[floating_key]'name='revup_options[floating_enable]'name='revup_options[slider_key]'name='revup_options[fullscreen_key]'addRuWidget<div id="ru-widget-[ru-slider][ru-stack]