
Widgets for WordPress Reviews Security & Risk Analysis
wordpress.org/plugins/reviews-widgetsEmbed Wordpress Plugin reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Wordpress reviews.
Is Widgets for WordPress Reviews Safe to Use in 2026?
Generally Safe
Score 100/100Widgets for WordPress Reviews has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "reviews-widgets" v13.2.7 plugin exhibits a mixed security posture. On the positive side, it demonstrates strong practices in output escaping and a high percentage of SQL queries using prepared statements, indicating a good understanding of preventing common web vulnerabilities like Cross-Site Scripting (XSS) and SQL Injection. The complete lack of known CVEs and recorded vulnerabilities is also a positive sign of its development history. However, significant concerns arise from its attack surface. With 3 identified entry points, all of which lack authentication or capability checks, the plugin is highly susceptible to unauthorized access and manipulation. The presence of the `unserialize` function, though not explicitly linked to a critical taint flow in this analysis, remains a potential risk if user-controlled data is unserialized without stringent sanitization, as it can lead to remote code execution. The single unsanitized path flow, while not classified as critical or high, warrants further investigation to understand its potential impact.
Key Concerns
- REST API routes without permission callbacks
- AJAX handlers without auth checks
- Unsanitized path flow found
- Dangerous function 'unserialize' used
Widgets for WordPress Reviews Security Vulnerabilities
Widgets for WordPress Reviews Release Timeline
Widgets for WordPress Reviews Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Widgets for WordPress Reviews Attack Surface
AJAX Handlers 1
REST API Routes 2
WordPress Hooks 36
Maintenance & Trust
Widgets for WordPress Reviews Maintenance & Trust
Maintenance Signals
Community Trust
Widgets for WordPress Reviews Alternatives
Rich Showcase for Google Reviews
widget-google-reviews
Display up to 10 Google reviews in less than a minute. Continue collecting new reviews. No limits on connected places, widgets, shortcodes and blocks.
WP Testimonials
testimonial-widgets
Display your Testimonials on your website fast and easily. 21 widget types, 25 widget styles available. (Free Plugin)
Feedspace Review Widgets
feedspace
Display customer testimonials and reviews on your WordPress website with beautiful, customizable widgets.
Simple WP Testimonials
simple-wp-testimonials
Simple WP Testimonials is a plugin that allows you to manage and display testimonials for your blog.
CausalFunnel Reviews Widget
causalfunnel-reviews-widget
Reviews Widget For Website – Simple & Elegant Review Management Tool
Widgets for WordPress Reviews Developer Profile
34 plugins · 975K total installs
How We Detect Widgets for WordPress Reviews
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/reviews-widgets/assets/css/reviews-widgets-backend.css/wp-content/plugins/reviews-widgets/assets/css/reviews-widgets-frontend.css/wp-content/plugins/reviews-widgets/assets/js/reviews-widgets-backend.js/wp-content/plugins/reviews-widgets/assets/js/reviews-widgets-frontend.jshttps://cdn.trustindex.io/loader.jsreviews-widgets/assets/css/reviews-widgets-backend.css?ver=reviews-widgets/assets/css/reviews-widgets-frontend.css?ver=reviews-widgets/assets/js/reviews-widgets-backend.js?ver=reviews-widgets/assets/js/reviews-widgets-frontend.js?ver=HTML / DOM Fingerprints
ti-site-datatrustindex-notification-rowti-hide-notificationCopyright 2019 Trustindex Kft (email: support@trustindex.io)data-ccm-injectedtrustindex_pm_wordpressPluginTrustindexPlugin_wordpressPlugin/wp-json/trustindex-api/v1/feed/wp-json/trustindex-api/v1/feed/template/wp-json/trustindex-api/v1/feed/content/wp-json/trustindex-api/v1/feed/css/wp-json/trustindex-api/v1/feed/scripts/wp-json/trustindex-api/v1/feed/settings