Simple 5 Star Rating Security & Risk Analysis

wordpress.org/plugins/simple-5-star-rating

This plugin will help readers to interact with you by giving stars to your content. On the basis of star reviews you can plan your further writing con …

0 active installs v1.0 PHP 5.3+ WP 4.9.0+ Updated Jul 3, 2020
google-ratingratingschema-ratingstar-ratingvotes
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Simple 5 Star Rating Safe to Use in 2026?

Generally Safe

Score 85/100

Simple 5 Star Rating has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The security posture of the "simple-5-star-rating" plugin version 1.0 presents significant concerns due to its unprotected entry points. All four identified AJAX handlers lack authentication checks, exposing them to potential unauthorized access and manipulation. While the static analysis did not reveal dangerous functions, external requests, or file operations, the absence of nonces and capability checks on these AJAX handlers is a critical oversight. The plugin also exhibits poor SQL query hygiene, with all four queries being unescaped and not using prepared statements, which is a strong indicator of potential SQL injection vulnerabilities. Despite this, the plugin has no recorded vulnerability history, suggesting either a lack of past scrutiny or a fortunate absence of exploitation. However, the current code practices, particularly the unprotected AJAX endpoints and raw SQL, outweigh this historical lack of issues, indicating a substantial risk that requires immediate attention.

Key Concerns

  • AJAX handlers without authentication checks
  • SQL queries not using prepared statements
  • AJAX handlers without nonce checks
  • AJAX handlers without capability checks
  • Unescaped output
Vulnerabilities
None known

Simple 5 Star Rating Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Simple 5 Star Rating Code Analysis

Dangerous Functions
0
Raw SQL Queries
4
0 prepared
Unescaped Output
2
8 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared4 total queries

Output Escaping

80% escaped10 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
tihomInsertRating (simple-5-star-rating.php:96)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
4 unprotected

Simple 5 Star Rating Attack Surface

Entry Points4
Unprotected4

AJAX Handlers 4

authwp_ajax_star_ratingsimple-5-star-rating.php:36
noprivwp_ajax_star_ratingsimple-5-star-rating.php:37
authwp_ajax_initial_datasimple-5-star-rating.php:39
noprivwp_ajax_initial_datasimple-5-star-rating.php:40
WordPress Hooks 1
filterthe_contentsimple-5-star-rating.php:30
Maintenance & Trust

Simple 5 Star Rating Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedJul 3, 2020
PHP min version5.3
Downloads1K

Community Trust

Rating60/100
Number of ratings2
Active installs0
Developer Profile

Simple 5 Star Rating Developer Profile

tihombhardwaj

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Simple 5 Star Rating

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/simple-5-star-rating/css/mycss.css/wp-content/plugins/simple-5-star-rating/js/dataInsertJ.js
Script Paths
/wp-content/plugins/simple-5-star-rating/js/dataInsertJ.js
Version Parameters
simple-5-star-rating/css/mycss.css?ver=1.0.0

HTML / DOM Fingerprints

CSS Classes
fa-starfa-star-half-fullcheckedtihom_rating_divtihom-rating-post-idtihom-rating-plugin-urltihom-rating-text
Data Attributes
id='tihom_rating_div'id='tihom-rating-post-id'id='tihom-rating-plugin-url'id='one'id='two'id='three'+3 more
JS Globals
insertrating_ajax
REST Endpoints
/wp-json/wp/v2/posts
Shortcode Output
<div id='tihom_rating_div'></div>
FAQ

Frequently Asked Questions about Simple 5 Star Rating