Simple Woo Reviews Lite Security & Risk Analysis

wordpress.org/plugins/simple-woo-reviews-lite

Showcase store product reviews to customers and boost your conversion rates. Displaying customer feedback in a new way helps increase store sales.

10 active installs v1.0.3 PHP 7.0+ WP 5.0+ Updated Jan 28, 2026
customer-reviewsproduct-reviewsreviewswoocommercewoocommerce-reviews
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Simple Woo Reviews Lite Safe to Use in 2026?

Generally Safe

Score 100/100

Simple Woo Reviews Lite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The "simple-woo-reviews-lite" v1.0.3 plugin exhibits a mixed security posture. While it boasts a clean vulnerability history with no recorded CVEs and a high percentage of properly escaped outputs (91%), concerns arise from its attack surface. A significant portion of its AJAX handlers (6 out of 8) lack authentication checks, presenting a considerable risk for unauthorized actions. Furthermore, the taint analysis revealed 5 flows with unsanitized paths, although thankfully none were flagged as critical or high severity. This indicates a potential for data manipulation or injection vulnerabilities if malicious input is provided, despite the absence of immediate critical findings.

The lack of any recorded vulnerabilities in its history is a positive sign, suggesting the developers are generally diligent. However, the presence of unsanitized paths in taint analysis and numerous unprotected AJAX endpoints indicate areas where security best practices could be strengthened. The plugin also makes external HTTP requests, which, while not inherently insecure, can be a vector if not handled with strict validation and sanitization of the data being sent or received.

In conclusion, while the plugin has a promising vulnerability history and good output escaping, the unprotected AJAX endpoints and unsanitized taint flows represent the most immediate risks. Addressing these directly would significantly improve the plugin's overall security. The absence of critical taint flows and dangerous functions is a strong point, but the unprotected entry points remain a key area for improvement.

Key Concerns

  • Unprotected AJAX handlers
  • Taint flows with unsanitized paths
  • External HTTP requests
  • SQL queries without prepared statements
Vulnerabilities
None known

Simple Woo Reviews Lite Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Simple Woo Reviews Lite Release Timeline

v1.0.3Current
v1.0.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 17, 2026

Simple Woo Reviews Lite Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
2 prepared
Unescaped Output
21
221 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
2
Bundled Libraries
0

SQL Query Safety

50% prepared4 total queries

Output Escaping

91% escaped242 total outputs
Data Flows · Security
5 unsanitized

Data Flow Analysis

5 flows5 with unsanitized paths
swr_get_newly_added_commment (admin\partials\class-simple-woo-reviews-posttype.php:513)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
6 unprotected

Simple Woo Reviews Lite Attack Surface

Entry Points11
Unprotected6

AJAX Handlers 8

authwp_ajax_swr_get_wc_reviewsadmin\class-simple-woo-reviews-admin.php:69
authwp_ajax_swr_get_review_dataadmin\partials\class-simple-woo-reviews-posttype.php:72
authwp_ajax_swr_load_more_reviewspublic\partials\simple-woo-reviews-shortcodes-manager.php:84
noprivwp_ajax_swr_load_more_reviewspublic\partials\simple-woo-reviews-shortcodes-manager.php:85
authwp_ajax_swr_get_order_productspublic\partials\simple-woo-reviews-wc-account-manager.php:107
noprivwp_ajax_swr_get_order_productspublic\partials\simple-woo-reviews-wc-account-manager.php:108
authwp_ajax_swr_save_order_product_reviewpublic\partials\simple-woo-reviews-wc-account-manager.php:109
noprivwp_ajax_swr_save_order_product_reviewpublic\partials\simple-woo-reviews-wc-account-manager.php:110

Shortcodes 3

[swr-reviews] public\partials\simple-woo-reviews-shortcodes-manager.php:76
[swr-reviews-slider] public\partials\simple-woo-reviews-shortcodes-manager.php:77
[swr-reviews-count] public\partials\simple-woo-reviews-shortcodes-manager.php:78
WordPress Hooks 43
actionadmin_menuadmin\partials\class-simple-woo-reviews-admin-settings.php:23
filterplugin_action_linksadmin\partials\class-simple-woo-reviews-admin-settings.php:24
filterlist_table_primary_columnadmin\partials\class-simple-woo-reviews-posttype.php:42
filterpost_row_actionsadmin\partials\class-simple-woo-reviews-posttype.php:44
filterget_edit_post_linkadmin\partials\class-simple-woo-reviews-posttype.php:46
filterwp_untrash_post_statusadmin\partials\class-simple-woo-reviews-posttype.php:48
actioninitadmin\partials\class-simple-woo-reviews-posttype.php:51
actionpre_get_postsadmin\partials\class-simple-woo-reviews-posttype.php:53
actiontrashed_commentadmin\partials\class-simple-woo-reviews-posttype.php:57
actionuntrashed_commentadmin\partials\class-simple-woo-reviews-posttype.php:59
actiondeleted_commentadmin\partials\class-simple-woo-reviews-posttype.php:61
actionedit_commentadmin\partials\class-simple-woo-reviews-posttype.php:63
actioncomment_postadmin\partials\class-simple-woo-reviews-posttype.php:65
actiontransition_comment_statusadmin\partials\class-simple-woo-reviews-posttype.php:67
actionswr_after_saving_order_product_reviewadmin\partials\class-simple-woo-reviews-posttype.php:69
actionplugins_loadedincludes\class-simple-woo-reviews.php:140
actionadmin_enqueue_scriptsincludes\class-simple-woo-reviews.php:155
actionadmin_enqueue_scriptsincludes\class-simple-woo-reviews.php:156
actionwp_enqueue_scriptsincludes\class-simple-woo-reviews.php:171
actionwp_enqueue_scriptsincludes\class-simple-woo-reviews.php:172
filterbody_classpublic\partials\simple-woo-reviews-shortcodes-manager.php:81
actionwp_enqueue_scriptspublic\partials\simple-woo-reviews-shortcodes-manager.php:90
actionwoocommerce_register_formpublic\partials\simple-woo-reviews-wc-account-manager.php:87
actionwoocommerce_register_form_tagpublic\partials\simple-woo-reviews-wc-account-manager.php:88
actionwoocommerce_register_postpublic\partials\simple-woo-reviews-wc-account-manager.php:89
actionwoocommerce_created_customerpublic\partials\simple-woo-reviews-wc-account-manager.php:90
actionshow_user_profilepublic\partials\simple-woo-reviews-wc-account-manager.php:93
actionedit_user_profilepublic\partials\simple-woo-reviews-wc-account-manager.php:94
actionuser_new_formpublic\partials\simple-woo-reviews-wc-account-manager.php:95
actionuser_registerpublic\partials\simple-woo-reviews-wc-account-manager.php:96
actionprofile_updatepublic\partials\simple-woo-reviews-wc-account-manager.php:97
actionwoocommerce_edit_account_formpublic\partials\simple-woo-reviews-wc-account-manager.php:100
actionwoocommerce_save_account_details_errorspublic\partials\simple-woo-reviews-wc-account-manager.php:101
actionwoocommerce_save_account_detailspublic\partials\simple-woo-reviews-wc-account-manager.php:102
actionwoocommerce_edit_account_form_tagpublic\partials\simple-woo-reviews-wc-account-manager.php:103
actioninitpublic\partials\simple-woo-reviews-wc-account-manager.php:104
actionwoocommerce_review_beforepublic\partials\simple-woo-reviews-wc-account-manager.php:105
filterwoocommerce_my_account_my_orders_actionspublic\partials\simple-woo-reviews-wc-account-manager.php:106
filterwoocommerce_product_review_comment_form_argspublic\partials\simple-woo-reviews-wc-review-form-manager.php:87
actionpre_comment_on_postpublic\partials\simple-woo-reviews-wc-review-form-manager.php:88
actionwp_insert_commentpublic\partials\simple-woo-reviews-wc-review-form-manager.php:89
actionwoocommerce_review_after_comment_textpublic\partials\simple-woo-reviews-wc-review-form-manager.php:90
actionadmin_noticessimple-woo-reviews.php:102
Maintenance & Trust

Simple Woo Reviews Lite Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 28, 2026
PHP min version7.0
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Simple Woo Reviews Lite Developer Profile

themesjungle

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Simple Woo Reviews Lite

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/simple-woo-reviews-lite/admin/css/simple-woo-reviews-admin.css/wp-content/plugins/simple-woo-reviews-lite/assets/css/jquery.fancybox.min.css/wp-content/plugins/simple-woo-reviews-lite/assets/css/jquery.raty.css/wp-content/plugins/simple-woo-reviews-lite/admin/js/simple-woo-reviews-admin.js/wp-content/plugins/simple-woo-reviews-lite/assets/js/jquery.fancybox.min.js/wp-content/plugins/simple-woo-reviews-lite/assets/js/jquery.raty.js
Script Paths
/wp-content/plugins/simple-woo-reviews-lite/admin/js/simple-woo-reviews-admin.js
Version Parameters
simple-woo-reviews-lite/admin/css/simple-woo-reviews-admin.css?ver=simple-woo-reviews-lite/assets/css/jquery.fancybox.min.css?ver=simple-woo-reviews-lite/assets/css/jquery.raty.css?ver=simple-woo-reviews-lite/admin/js/simple-woo-reviews-admin.js?ver=simple-woo-reviews-lite/assets/js/jquery.fancybox.min.js?ver=simple-woo-reviews-lite/assets/js/jquery.raty.js?ver=

HTML / DOM Fingerprints

CSS Classes
swr-reviews-containerswr-review-titleswr-ratingswr-authorswr-dateswr-comment
HTML Comments
<!-- Default plugin settings --><!-- Custom review title --><!-- Custom rating value --><!-- Custom review author -->+2 more
Data Attributes
data-swr-product-iddata-swr-review-iddata-swr-ratingdata-swr-authordata-swr-datedata-swr-comment
JS Globals
swr_ajax_url
REST Endpoints
/wp-json/simple-woo-reviews/v1/reviews
Shortcode Output
[simple_woo_reviews][simple_woo_reviews product_id=X][simple_woo_reviews count=Y][simple_woo_reviews display_rating=true]
FAQ

Frequently Asked Questions about Simple Woo Reviews Lite