
Revora Security & Risk Analysis
wordpress.org/plugins/revoraLightweight, category-based review system with AJAX submission, spam detection, admin moderation, and beautiful Elementor widgets.
Is Revora Safe to Use in 2026?
Generally Safe
Score 100/100Revora has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "revora" plugin version 1.0.0 exhibits a generally good security posture with strong practices in SQL query preparation and output escaping. The plugin demonstrates a commitment to security by implementing a significant number of nonce and capability checks. However, a notable concern arises from the presence of one AJAX handler that lacks authentication checks, potentially opening a vector for unauthorized actions. The taint analysis reveals three high-severity flows with unsanitized paths, indicating potential risks where user-supplied data is not properly validated before being used in sensitive operations. The absence of any known historical CVEs is a positive indicator, suggesting a history of responsible development or a lack of significant past security issues. Despite these strengths, the identified unprotected AJAX endpoint and high-severity taint flows represent specific areas requiring immediate attention to mitigate potential vulnerabilities.
Key Concerns
- AJAX handler without authentication
- High severity taint flows with unsanitized paths
Revora Security Vulnerabilities
Revora Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Revora Attack Surface
AJAX Handlers 6
Shortcodes 2
WordPress Hooks 12
Maintenance & Trust
Revora Maintenance & Trust
Maintenance Signals
Community Trust
Revora Alternatives
Site Reviews
site-reviews
Site Reviews is a complete review management solution that integrates with WooCommerce and SureCart and works similarly to reviews on Amazon, Tripadvi …
WP Testimonials
testimonial-widgets
Display your Testimonials on your website fast and easily. 21 widget types, 25 widget styles available. (Free Plugin)
Better Business Reviews – Trustpilot WordPress Plugin
better-business-reviews
Better Business Reviews allows you to display your business reviews from a Trustpilot profile.
Gutena Star Ratings
gutena-star-ratings
Gutena Star Ratings is a great block that lets you add star rating to client testimonials and reviews. Not only the star rating will tell customers ho …
Review & testimonial widgets
trustmary
Add reviews to your website with Trustmary’s review and testimonial widgets: Google Review Widget, Facebook Review Widget, Tripadvisor Review Widget, …
Revora Developer Profile
1 plugin · 0 total installs
How We Detect Revora
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/revora/assets/css/revora-frontend.css/wp-content/plugins/revora/assets/css/revora-card-variants.css/wp-content/plugins/revora/assets/js/revora-frontend.js/wp-content/plugins/revora/assets/css/revora-admin.css/wp-content/plugins/revora/assets/js/revora-admin.js/wp-content/plugins/revora/assets/css/revora-deactivation.css/wp-content/plugins/revora/assets/js/revora-deactivation.js/wp-content/plugins/revora/assets/js/revora-frontend.js/wp-content/plugins/revora/assets/js/revora-admin.js/wp-content/plugins/revora/assets/js/revora-deactivation.jsrevora-frontendrevora-card-variantsrevora-adminrevora-deactivationHTML / DOM Fingerprints
revora-review-formrevora-review-listrevora-admin-wrap<!-- Revora review form --><!-- Revora review list --><!-- Revora admin settings page -->data-revora-post-iddata-revora-noncerevora_varsrevoraAdminrevoraDeactivation/wp-json/revora/v1/submit-review/wp-json/revora/v1/get-reviews[revora_form][revora_reviews]