
Show Product Reviews and Ratings Security & Risk Analysis
wordpress.org/plugins/show-product-review-and-ratingsWith this plugin you will rank much higher on Google!
Is Show Product Reviews and Ratings Safe to Use in 2026?
Generally Safe
Score 85/100Show Product Reviews and Ratings has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'show-product-review-and-ratings' plugin version 1.0 exhibits a strong initial security posture based on static analysis, with no identified dangerous functions, a complete reliance on prepared statements for SQL queries, and a high percentage of properly escaped output. The absence of file operations and external HTTP requests further contributes to a reduced attack surface. Furthermore, the plugin has a clean vulnerability history, with no recorded CVEs, suggesting a history of secure development practices or a lack of targeted exploitation. However, the static analysis reveals several areas that, while not directly flagged as vulnerabilities in this version, represent potential future risks or weaknesses if not addressed. The lack of nonce checks and capability checks across all identified entry points, particularly the four shortcodes, is a significant concern. Shortcodes are direct entry points into the plugin's functionality, and without proper authentication and authorization checks, they could be exploited, especially if they handle user-provided data or perform sensitive operations. The taint analysis not reporting any flows is positive, but this might be due to the limited scope of the analysis or the absence of specific data inputs in the tested version. The combination of these factors, while currently resulting in a low immediate risk due to the absence of known vulnerabilities and dangerous code patterns, highlights potential security gaps that require attention for long-term security.
Key Concerns
- Missing nonce checks on entry points
- Missing capability checks on entry points
- Shortcodes as potential entry points without checks
Show Product Reviews and Ratings Security Vulnerabilities
Show Product Reviews and Ratings Release Timeline
Show Product Reviews and Ratings Code Analysis
Output Escaping
Show Product Reviews and Ratings Attack Surface
Shortcodes 4
WordPress Hooks 1
Maintenance & Trust
Show Product Reviews and Ratings Maintenance & Trust
Maintenance Signals
Community Trust
Show Product Reviews and Ratings Alternatives
TrustMate.io – WooCommerce integration
trustmate-io-integration-for-woocommerce
TrustMate - Reviews for your shop and products at you WooCommerce site. Generate valuable traffic and profit more than others!
Auto Approve Product reviews
auto-approve-product-reviews
Auto-approve product reviews with a minimum rating chosen by you
WC Product Tabs Plus
wc-product-tabs-plus
Advance tab management for WooCommerce Product tabs
Inline Review
inline-review
Simple inline reviews that you can place in a post.
Affiliblocks
affiliblocks
Create beautiful affiliate product review blocks with ratings, pros/cons, and comparison features.
Show Product Reviews and Ratings Developer Profile
1 plugin · 0 total installs
How We Detect Show Product Reviews and Ratings
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/show-product-review-and-ratings/css/show-review-rating.cssshow-product-review-and-ratings/css/show-review-rating.css?ver=HTML / DOM Fingerprints
hrclassstar-rating[pdmi_show_all_product_reviews][pdmi_show_shop_average_rating_stars][pdmi_get_average_rating_score][pdmi_get_total_number_reviews]