
Shinobi Reviews Security & Risk Analysis
wordpress.org/plugins/shinobi-reviewsA review plugin for gathering many customer reviews easily.
Is Shinobi Reviews Safe to Use in 2026?
Generally Safe
Score 85/100Shinobi Reviews has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The shinobi-reviews plugin v1.6.0 exhibits a generally good security posture based on the provided static analysis and vulnerability history. A significant strength is the complete absence of known CVEs, indicating a history of responsible development and patching, or simply a lack of historical exploitation. The code analysis also reveals positive signs such as 100% properly escaped output and a lack of dangerous functions or file operations. However, a notable concern arises from the SQL query analysis, where 100% of the single detected SQL query is not using prepared statements. While the attack surface is substantial with 36 AJAX handlers, all appear to have authentication checks, and there are no unsanitized taint flows. The limited capability checks (1) could be a potential area for improvement to further harden the plugin against privilege escalation if the single check is not sufficiently robust.
Despite the promising lack of historical vulnerabilities and good output sanitization, the raw SQL query represents a potential risk. If this query is exposed to user-controlled input without proper sanitization, it could lead to SQL injection vulnerabilities, even if the static analysis did not detect taint flows. The limited number of capability checks also warrants attention. Overall, the plugin is in a relatively strong security position due to its clean vulnerability history and robust output handling, but the un-prepared SQL query is a specific area that requires attention to mitigate potential risks.
Key Concerns
- Raw SQL query without prepared statements
Shinobi Reviews Security Vulnerabilities
Shinobi Reviews Code Analysis
SQL Query Safety
Output Escaping
Shinobi Reviews Attack Surface
AJAX Handlers 36
WordPress Hooks 20
Maintenance & Trust
Shinobi Reviews Maintenance & Trust
Maintenance Signals
Community Trust
Shinobi Reviews Alternatives
Loco Translate
loco-translate
Translate WordPress plugins and themes directly in your browser. Versatile PO file editor with integrated AI translation providers.
Site Reviews
site-reviews
Site Reviews is a complete review management solution that integrates with WooCommerce and SureCart and works similarly to reviews on Amazon, Tripadvi …
WP Ultimate Review
wp-ultimate-review
WP Ultimate Review is the perfect plugin to collect & display customers' feedback effortlessly on products, services, & content in WordPress.
Testimonial – Testimonial Slider and Showcase Plugin
testimonial-slider-and-showcase
Display customer testimonials beautifully with responsive slider and grid layouts. Build trust and boost conversions with this WordPress testimonial p …
Reviews and Rating – Google Reviews
g-business-reviews-rating
Completely restriction-free Google reviews and rating as Shortcode/Widget. Extensive display options; delicious themes; includes Structured Data.
Shinobi Reviews Developer Profile
1 plugin · 400 total installs
How We Detect Shinobi Reviews
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/shinobi-reviews/assets/admin/admin.js/wp-content/plugins/shinobi-reviews/assets/admin/admin.jsHTML / DOM Fingerprints
shinobiReviewsAdmin