Reviews Easy Security & Risk Analysis

wordpress.org/plugins/reviewseasy

Easy add and beautiful view your reviews

10 active installs v1.0.8 PHP + WP 4.1+ Updated Dec 17, 2016
review-postreviewsreviews-carouselreviews-easy
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Reviews Easy Safe to Use in 2026?

Generally Safe

Score 85/100

Reviews Easy has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The static analysis of the 'reviewseasy' v1.0.8 plugin reveals a seemingly robust security posture with no identified attack surface, dangerous functions, or SQL injection vulnerabilities. The absence of external HTTP requests, file operations, and cron events further contributes to a reduced threat landscape. However, a significant concern arises from the low percentage (27%) of properly escaped output. This indicates a high likelihood of Cross-Site Scripting (XSS) vulnerabilities, where user-supplied data might be rendered unescaped in the browser, allowing attackers to inject malicious scripts.

The plugin's vulnerability history is clean, with no recorded CVEs. This, combined with the lack of critical taint flows, suggests that developers have either been proactive in addressing potential issues or the plugin's functionality hasn't attracted significant malicious attention. Nevertheless, the identified output escaping deficiency is a critical flaw that must be addressed. A lack of capability checks and nonce checks, while not directly evidenced as vulnerabilities in this static analysis, are important security controls that are absent, especially if any new entry points are introduced in future versions.

In conclusion, while 'reviewseasy' v1.0.8 demonstrates strengths in avoiding common vulnerability classes like SQL injection and a clean historical record, the poor output escaping practices represent a clear and present danger of XSS attacks. The absence of nonce and capability checks also introduces potential weaknesses that could be exploited if new entry points are added without proper authorization mechanisms. Prioritizing the proper escaping of all output is paramount for the security of this plugin.

Key Concerns

  • Low output escaping (27%)
  • Missing capability checks
  • Missing nonce checks
Vulnerabilities
None known

Reviews Easy Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Reviews Easy Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
11
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

27% escaped15 total outputs
Attack Surface

Reviews Easy Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionwidgets_initreviews-easy.php:21
actionwp_enqueue_scriptsreviews-easy.php:37
actionwp_enqueue_scriptsreviews-easy.php:38
actioninitreviews-easy.php:39
actioninitreviews-easy.php:40
filtertemplate_includereviews-easy.php:41
actiontemplate_redirectreviews-easy.php:42
actionadmin_enqueue_scriptsreviews-easy.php:43
Maintenance & Trust

Reviews Easy Maintenance & Trust

Maintenance Signals

WordPress version tested4.5.33
Last updatedDec 17, 2016
PHP min version
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Reviews Easy Developer Profile

AndreyS.

3 plugins · 60 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Reviews Easy

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/reviewseasy/style/jcarousel.re_style.css/wp-content/plugins/reviewseasy/style/style.css/wp-content/plugins/reviewseasy/js/jquery.jcarousel.min.js/wp-content/plugins/reviewseasy/js/jcarousel.re_script.js/wp-content/plugins/reviewseasy/js/upload-media.js
Script Paths
js/jquery.jcarousel.min.jsjs/jcarousel.re_script.jsjs/upload-media.js
Version Parameters
reviewseasy/style/jcarousel.re_style.css?ver=reviewseasy/style/style.css?ver=reviewseasy/js/jquery.jcarousel.min.js?ver=reviewseasy/js/jcarousel.re_script.js?ver=reviewseasy/js/upload-media.js?ver=

HTML / DOM Fingerprints

CSS Classes
jcarousel-skin-re
FAQ

Frequently Asked Questions about Reviews Easy