
Widgets for Yelp Reviews Security & Risk Analysis
wordpress.org/plugins/reviews-widgets-for-yelpEmbed Yelp reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Yelp reviews.
Is Widgets for Yelp Reviews Safe to Use in 2026?
Generally Safe
Score 100/100Widgets for Yelp Reviews has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "reviews-widgets-for-yelp" plugin v13.2.7 exhibits a mixed security posture. On the positive side, the plugin demonstrates strong adherence to output escaping practices, with 100% of outputs being properly escaped. It also makes extensive use of prepared statements for SQL queries, indicating a good understanding of preventing SQL injection. The significant number of nonce and capability checks further suggests an effort to secure its functionalities. However, there are significant concerns regarding the plugin's attack surface. Notably, all three identified entry points (1 AJAX handler, 2 REST API routes) lack proper authentication and permission checks. This presents a clear risk of unauthorized access and potential abuse of these functionalities. While the vulnerability history is clean, with no recorded CVEs, this does not negate the immediate risks posed by the exposed entry points. The presence of the `unserialize` function, while not immediately flagged as a critical issue in the taint analysis, warrants careful consideration as it can be a vector for remote code execution if used with untrusted input. In conclusion, the plugin has strengths in output sanitization and data access, but the lack of authentication on key entry points creates a substantial security weakness that needs immediate attention.
Key Concerns
- Unprotected AJAX handlers
- Unprotected REST API routes
- Dangerous function 'unserialize' used
Widgets for Yelp Reviews Security Vulnerabilities
Widgets for Yelp Reviews Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Widgets for Yelp Reviews Attack Surface
AJAX Handlers 1
REST API Routes 2
WordPress Hooks 36
Maintenance & Trust
Widgets for Yelp Reviews Maintenance & Trust
Maintenance Signals
Community Trust
Widgets for Yelp Reviews Alternatives
Widget for Yelp Reviews
widget-yelp-reviews
Yelp reviews widget and shortcode! Shows Yelp business reviews on your WordPress website to increase user trust and SEO.
Reviews Widgets for Google, Yelp & TripAdvisor
fb-reviews-widget
Combine Facebook recommendations with Google, Yelp and TripAdvisor reviews in a widget, block or shortcode. Build a trusted website!
WP Testimonials
testimonial-widgets
Display your Testimonials on your website fast and easily. 21 widget types, 25 widget styles available. (Free Plugin)
Yelp Reviews Ticker
yelp-reviews-ticker
Yelp Reviews Ticker is an easy to use widget that allows you to show your business yelp reviews.
Review Map by RevuKangaroo
review-map-by-revukangaroo
Show off your customer's online reviews with Review Map by Revukangaroo.
Widgets for Yelp Reviews Developer Profile
32 plugins · 976K total installs
How We Detect Widgets for Yelp Reviews
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/reviews-widgets-for-yelp/assets/css/reviews-widget.css/wp-content/plugins/reviews-widgets-for-yelp/assets/css/reviews-widget-frontend.css/wp-content/plugins/reviews-widgets-for-yelp/assets/js/reviews-widget-frontend.js/wp-content/plugins/reviews-widgets-for-yelp/assets/js/reviews-widget.jshttps://cdn.trustindex.io/loader.jsreviews-widgets-for-yelp/assets/css/reviews-widget.css?ver=reviews-widgets-for-yelp/assets/css/reviews-widget-frontend.css?ver=reviews-widgets-for-yelp/assets/js/reviews-widget-frontend.js?ver=reviews-widgets-for-yelp/assets/js/reviews-widget.js?ver=HTML / DOM Fingerprints
ti-reviews-widget-wrapperti-reviews-widget-frontend-wrapperti-widget-yelp-badgeti-reviews-widget-single-reviewti-reviews-widget-wrapperti-widget-yelp-bodyti-reviews-widget-avatarti-reviews-widget-username+14 moreCopyright 2019 Trustindex Kft (email: support@trustindex.io)data-ccm-injectedtrustindex_pm_yelpTrustindexPlugin_yelptiReviewsWidgetsFrontend/wp-json/trustindex/v1/widgets