SDStudio Google Reviews for portfolio Security & Risk Analysis

wordpress.org/plugins/sdstudio-portfolio-for-google-reviews

The plugin will help upload reviews from Google Reviews to your site for a portfolio of reviews about your work or services.

0 active installs v1.0.2 PHP 7.0+ WP 5.0+ Updated Sep 2, 2019
getgooglegraberportfolioreviews
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is SDStudio Google Reviews for portfolio Safe to Use in 2026?

Generally Safe

Score 85/100

SDStudio Google Reviews for portfolio has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The sdstudio-portfolio-for-google-reviews plugin version 1.0.2 exhibits a mixed security posture. While it demonstrates good practices such as using prepared statements for all SQL queries and not bundling external libraries, significant concerns arise from its attack surface and output sanitization. The plugin exposes a single AJAX handler that lacks any authentication or authorization checks, making it a prime target for unauthorized actions. Furthermore, a substantial portion of its output (54%) is not properly escaped, creating a risk of cross-site scripting (XSS) vulnerabilities, especially when combined with the unsanitized input paths identified in the taint analysis. The absence of any recorded historical vulnerabilities, while seemingly positive, could also suggest a lack of thorough security auditing or a history of limited exposure, rather than inherent robustness. Overall, the plugin has strengths in its database interaction but weaknesses in its handling of user input and AJAX requests, necessitating careful attention to secure coding practices.

Key Concerns

  • Unprotected AJAX handler
  • Significant unescaped output
  • Flows with unsanitized paths
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

SDStudio Google Reviews for portfolio Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

SDStudio Google Reviews for portfolio Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
6 escaped
Nonce Checks
0
Capability Checks
0
File Operations
2
External Requests
0
Bundled Libraries
0

Output Escaping

46% escaped13 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
save_sds_google_reviews (sdstudio_grfp.php:588)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

SDStudio Google Reviews for portfolio Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_php_html_parsersdstudio_grfp.php:403
WordPress Hooks 16
actionplugins_loadedCarbon Fields\SDStudio_Carbon_Fields_Functions.php:13
actioncarbon_fields_register_fieldsCarbon Fields\SDStudio_Carbon_Fields_Functions.php:20
actionplugins_loadedincludes\class-sdstudio_grfp.php:142
actionadmin_enqueue_scriptsincludes\class-sdstudio_grfp.php:157
actionadmin_enqueue_scriptsincludes\class-sdstudio_grfp.php:158
actionwp_enqueue_scriptsincludes\class-sdstudio_grfp.php:173
actionwp_enqueue_scriptsincludes\class-sdstudio_grfp.php:174
actionplugins_loadedsdstudio_grfp.php:90
actioninitsdstudio_grfp.php:147
actioninitsdstudio_grfp.php:193
actionadmin_headsdstudio_grfp.php:229
actiondo_meta_boxessdstudio_grfp.php:522
filteradmin_post_thumbnail_htmlsdstudio_grfp.php:537
actionsave_post_sds_google_reviewssdstudio_grfp.php:587
actionsave_sds_google_reviewssdstudio_grfp.php:651
actionadmin_head-post.phpsdstudio_grfp.php:652
Maintenance & Trust

SDStudio Google Reviews for portfolio Maintenance & Trust

Maintenance Signals

WordPress version tested5.0.25
Last updatedSep 2, 2019
PHP min version7.0
Downloads954

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

SDStudio Google Reviews for portfolio Developer Profile

s.dudchenko

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SDStudio Google Reviews for portfolio

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sdstudio-portfolio-for-google-reviews/css/style.css/wp-content/plugins/sdstudio-portfolio-for-google-reviews/js/main.js/wp-content/plugins/sdstudio-portfolio-for-google-reviews/Carbon Fields/vendor/autoload.php/wp-content/plugins/sdstudio-portfolio-for-google-reviews/Carbon Fields/SDStudio_Carbon_Fields_Functions.php/wp-content/plugins/sdstudio-portfolio-for-google-reviews/php-html-parser-master/vendor/autoload.php
Script Paths
/wp-content/plugins/sdstudio-portfolio-for-google-reviews/js/main.js
Version Parameters
sdstudio-portfolio-for-google-reviews/css/style.css?ver=sdstudio-portfolio-for-google-reviews/js/main.js?ver=

HTML / DOM Fingerprints

CSS Classes
sds_google_reviews_button_graber
HTML Comments
__Post_Type_SDStudio_Google_Reviews__Taxonomy_Google_Reviews_Categories@_Carbon_Fields@_php_html_parser
Data Attributes
data-swal_loader_alert_titledata-swal_loader_html_titledata-swal_success_alert_titledata-swal_success_alert_textdata-swal_error_alert_titledata-swal_error_alert_text
JS Globals
sdstudio_grfp_translite
REST Endpoints
/wp-json/wp/v2/sds_google_reviews/wp-json/wp/v2/category_google_reviews
FAQ

Frequently Asked Questions about SDStudio Google Reviews for portfolio