Collect and Display Customer Reviews with Ease Security & Risk Analysis

wordpress.org/plugins/rewindr

Turn reviews into revenue! Rewindr empowers your WordPress and WooCommerce store to display rich, interactive customer feedback that builds trust and …

0 active installs v1.0.0 PHP + WP 5.0+ Updated Nov 21, 2024
reviewssocial-prooftestimonialsugcwoocommerce
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Collect and Display Customer Reviews with Ease Safe to Use in 2026?

Generally Safe

Score 92/100

Collect and Display Customer Reviews with Ease has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The rewindr plugin v1.0.0 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, file operations, and SQL queries without prepared statements is commendable. The high percentage of properly escaped output further indicates good development practices for preventing cross-site scripting vulnerabilities. The presence of a nonce check and a single external HTTP request are also noted as positive aspects.

However, a key area of concern is the complete lack of capability checks across all identified entry points, including the shortcode and the external HTTP request. While the attack surface is currently small and no direct vulnerabilities were found in taint analysis, this absence of authorization means that any user, regardless of their role or permissions, could potentially interact with these plugin features. This could lead to unintended actions or information leakage if the shortcode or the external request's behavior is sensitive.

The plugin's vulnerability history is clean, with no recorded CVEs. This is a very positive sign, suggesting a history of secure development or a lack of publicly known vulnerabilities. However, it's important to remember that a clean history does not guarantee future security. The lack of capability checks remains a significant weakness that could be exploited in the future, especially if the plugin's functionality expands or becomes more complex.

Key Concerns

  • No capability checks on entry points
Vulnerabilities
None known

Collect and Display Customer Reviews with Ease Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Collect and Display Customer Reviews with Ease Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
51 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

98% escaped52 total outputs
Attack Surface

Collect and Display Customer Reviews with Ease Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[rewindr_reviews] includes\class-rewindr.php:170
WordPress Hooks 10
actionplugins_loadedincludes\class-rewindr.php:136
actionadmin_enqueue_scriptsincludes\class-rewindr.php:149
actionadmin_enqueue_scriptsincludes\class-rewindr.php:150
actionadmin_initincludes\class-rewindr.php:151
actionadmin_menuincludes\class-rewindr.php:152
actionwoocommerce_order_status_completedincludes\class-rewindr.php:153
actionwp_enqueue_scriptsincludes\class-rewindr.php:166
actionwp_enqueue_scriptsincludes\class-rewindr.php:167
actionwoocommerce_after_single_productincludes\class-rewindr.php:168
actionwoocommerce_before_add_to_cart_buttonincludes\class-rewindr.php:169
Maintenance & Trust

Collect and Display Customer Reviews with Ease Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedNov 21, 2024
PHP min version
Downloads422

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

Collect and Display Customer Reviews with Ease Developer Profile

rewindr.io

1 plugin · 0 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Collect and Display Customer Reviews with Ease

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/rewindr/admin/css/rewindr-admin.css/wp-content/plugins/rewindr/admin/js/rewindr-admin.js
Script Paths
/wp-content/plugins/rewindr/admin/js/rewindr-admin.js
Version Parameters
rewindr-admin.css?ver=rewindr-admin.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- The code that runs during plugin activation. --><!-- The code that runs during plugin deactivation. --><!-- The core plugin class that is used to define internationalization, --><!-- admin-specific hooks, and public-facing site hooks. -->+14 more
FAQ

Frequently Asked Questions about Collect and Display Customer Reviews with Ease