Site Reviews Security & Risk Analysis

wordpress.org/plugins/site-reviews

Site Reviews is a complete review management solution that integrates with WooCommerce and SureCart and works similarly to reviews on Amazon, Tripadvi …

70K active installs v8.0.6 PHP 8.1.2+ WP 6.7+ Updated Mar 15, 2026
business-reviewsproduct-reviewsratingsreviewstestimonials
96
A · Safe
CVEs total13
Unpatched0
Last CVEFeb 26, 2025
Safety Verdict

Is Site Reviews Safe to Use in 2026?

Generally Safe

Score 96/100

Site Reviews has a strong security track record. Known vulnerabilities have been patched promptly.

13 known CVEsLast CVE: Feb 26, 2025Updated 19d ago
Risk Assessment

The Site Reviews v8.0.6 plugin exhibits a mixed security posture. While it demonstrates a good number of security practices such as numerous capability checks and nonces, and a majority of SQL queries utilizing prepared statements, several areas raise concerns. The presence of the `unserialize` function is a significant risk factor, as it can lead to deserialization vulnerabilities if not handled with extreme caution and proper input validation. The taint analysis identified one flow with an unsanitized path, which, although not rated critical or high, still represents a potential entry point for attackers. The plugin's vulnerability history, with 13 known CVEs including one high severity and twelve medium, indicates a pattern of past security weaknesses. Common vulnerability types like Authentication Bypass, Missing Authorization, and Cross-site Scripting suggest recurring issues with input handling and access control. The fact that the last vulnerability was recent (February 2025) and there are currently no unpatched CVEs is a positive sign, but the overall historical trend warrants vigilance. The plugin's strengths lie in its numerous built-in security checks and efforts to use prepared statements. However, the risks associated with `unserialize`, the identified unsanitized path, and the plugin's history of diverse and prevalent vulnerabilities mean it should be used with awareness and kept updated diligently.

Key Concerns

  • Presence of unserialize function
  • Flow with unsanitized path
  • High number of known CVEs (13 total)
  • 1 high severity known CVE
  • 12 medium severity known CVEs
  • 51% of outputs properly escaped
Vulnerabilities
13

Site Reviews Security Vulnerabilities

CVEs by Year

1 CVE in 2018
2018
2 CVEs in 2021
2021
6 CVEs in 2023
2023
3 CVEs in 2024
2024
1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

High
1
Medium
12

13 total CVEs

CVE-2025-1232medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Site Reviews <= 7.2.4 - Unauthenticated Stored Cross-Site Scripting

Feb 26, 2025 Patched in 7.2.5 (27d)
CVE-2024-3050medium · 5.3Authentication Bypass by Spoofing

Site Reviews <= 6.11.8 - IP Address Spoofing to Blocking Bypass

May 8, 2024 Patched in 7.0.0 (30d)
CVE-2024-29095medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Site Reviews <= 6.11.6 - Authenticated (Author+) Stored Cross-Site Scripting

Mar 15, 2024 Patched in 6.11.7 (6d)
CVE-2024-2293medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Site Reviews <= 6.11.4 - Authenticated(Subscriber+) Stored Cross-Site Scripting via display name

Mar 11, 2024 Patched in 6.11.7 (3d)
CVE-2023-49832medium · 5.4Missing Authorization

Site Reviews <= 6.10.2 - Missing Authorization

Aug 29, 2023 Patched in 6.10.3 (147d)
CVE-2023-1525medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Site Reviews <= 6.7.0 - Authenticated (Administrator+) Stored Cross-Site Scripting

Apr 5, 2023 Patched in 6.7.1 (293d)
CVE-2023-27629medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Site Reviews <= 6.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via block attribute

Mar 13, 2023 Patched in 6.6.0 (316d)
CVE-2023-27625medium · 5.4Missing Authorization

Site Reviews <= 6.5.1 - Missing Authorization

Mar 13, 2023 Patched in 6.6.0 (316d)
CVE-2023-27612medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Site Reviews <= 6.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode

Mar 13, 2023 Patched in 6.6.0 (316d)
CVE-2022-46801medium · 6.5Improper Neutralization of Formula Elements in a CSV File

Site Reviews <= 6.2.0 - Unauthenticated CSV Injection

Jan 27, 2023 Patched in 6.4.0 (361d)
CVE-2021-24973high · 7.2Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Site Reviews <= 5.17.2 - Unauthenticated Stored Cross-Site Scripting

Dec 6, 2021 Patched in 5.17.3 (778d)
CVE-2021-24603medium · 5.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Site Reviews <= 5.13.0 - Admin+ Stored Cross-Site Scripting

Aug 9, 2021 Patched in 5.13.1 (897d)
CVE-2018-0603medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Site Reviews <= 2.15.2 - Cross-Site Scripting

May 28, 2018 Patched in 2.15.3 (2066d)
Code Analysis
Analyzed Mar 16, 2026

Site Reviews Code Analysis

Dangerous Functions
1
Raw SQL Queries
34
124 prepared
Unescaped Output
603
625 escaped
Nonce Checks
20
Capability Checks
21
File Operations
43
External Requests
5
Bundled Libraries
2

Dangerous Functions Found

unserialize$schedule = unserialize( $data->schedule ); // phpcs:ignore WordPress.PHP.DiscouragedPHPFunctions.sevendors\woocommerce\action-scheduler\classes\data-stores\ActionScheduler_DBStore.php:397

Bundled Libraries

TinyMCESelect2

SQL Query Safety

78% prepared158 total queries

Output Escaping

51% escaped1228 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
display_table (vendors\woocommerce\action-scheduler\classes\abstracts\ActionScheduler_Abstract_ListTable.php:736)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Site Reviews Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[profile-rating] plugin\Integrations\ProfilePress\Controllers\DirectoryController.php:169
WordPress Hooks 181
actionwp_headcompatibility.php:18
filterwoocommerce_reviews_titlecompatibility.php:32
actionadmin_enqueue_scriptscompatibility.php:54
filterwoocommerce_product_get_rating_htmlcompatibility.php:88
actionavia_action_before_framework_initcompatibility.php:100
filtersite-reviews/defaults/style-classes/defaultscompatibility.php:101
actionavf_duplicate_post_addedcompatibility.php:109
actionedit_form_topcompatibility.php:126
filtersite-reviews/paginate_linkscompatibility.php:152
filtersite-reviews/paginate_linkcompatibility.php:157
filterclassic_editor_enabled_editors_for_post_typecompatibility.php:172
actionmembers_register_capscompatibility.php:185
actionplugins_loadedcompatibility.php:215
filtersf_edit_query_argscompatibility.php:232
filtersgo_js_minify_excludecompatibility.php:253
actionenqueue_block_editor_assetscompatibility.php:278
actionwp_enqueue_scriptscompatibility.php:279
filtersite-reviews/config/styles/ninja_formscompatibility.php:280
filtersite-reviews/build/template/reviews-formcompatibility.php:293
filterwpforms_frontend_missing_assets_error_js_disablecompatibility.php:295
filterwpforms_global_assetscompatibility.php:296
filtertcb_post_typescompatibility.php:308
actionload-post.phpcompatibility.php:335
actionload-post-new.phpcompatibility.php:336
actionplugins_loadeddeprecated.php:8
filtersite-reviews/review-form/fields/orderdeprecated.php:12
actionplugins_loadeddeprecated.php:24
filtersite-reviews/review-form/fields/alldeprecated.php:28
actionplugins_loadeddeprecated.php:40
filtersite-reviews/rest-api/reviews/schema/propertiesdeprecated.php:44
filtersite-reviews/rest-api/summary/schema/propertiesdeprecated.php:51
actionsite-reviews/review/updateddeprecated.php:58
filtersite-reviews/slack/notificationdeprecated.php:65
actionplugins_loadeddeprecated.php:77
filtersite-reviews/build/template/reviewdeprecated.php:87
filtersite-reviews/build/template/reviewdeprecated.php:96
filtersite-reviews/config/forms/review-formdeprecated.php:99
filtersite-reviews/rendered/template/reviewsdeprecated.php:106
filtersite-reviews/review-form/fields/orderdeprecated.php:114
filtersite-reviews/defaults/review-table-filtersdeprecated.php:121
actionsite-reviews/review/respondeddeprecated.php:128
actiondeprecated_hook_rundeprecated.php:170
actiondeprecated_function_rundeprecated.php:193
actionadmin_footerdeprecated.php:202
actionwp_footerdeprecated.php:203
actionplugins_loadedhelpers.php:30
filtersite-reviews/config/forms/metabox-fieldsmigration.php:19
filtersite-reviews/defaults/ratingmigration.php:20
filtersite-reviews/defaults/reviewsmigration.php:21
actionplugins_loadedplugin\Addons\Hooks.php:29
actioninitplugin\Application.php:133
filterwxr_export_skip_postmetaplugin\Commands\ExportRatings.php:19
filtergettext_defaultplugin\Database\Cache.php:93
actioninitplugin\Hooks\AbstractHooks.php:101
actionplugins_loadedplugin\Hooks\AbstractHooks.php:104
actionafter_setup_themeplugin\Hooks\TranslationHooks.php:12
actionplugins_loadedplugin\Hooks.php:53
actionfusion_builder_before_initplugin\Integrations\Avada\Elements\FusionElement.php:47
actionwp_enqueue_scriptsplugin\Integrations\Bricks\BricksElement.php:33
filteret_required_module_assetsplugin\Integrations\Divi\Controller.php:100
filtersite-reviews/paginate_linkplugin\Integrations\Divi\Controller.php:188
actioninitplugin\Integrations\Divi\Modules\DiviModule.php:31
actionux_builder_setupplugin\Integrations\Flatsome\Shortcodes\FlatsomeShortcode.php:63
actionmultilingualpress.add_service_providersplugin\Integrations\MultilingualPress\Hooks.php:29
filtermultilingualpress.all_post_typesplugin\Integrations\MultilingualPress\Hooks.php:35
filtermultilingualpress.all_taxonomiesplugin\Integrations\MultilingualPress\Hooks.php:42
actionnetwork_admin_noticesplugin\Integrations\MultilingualPress\Hooks.php:85
filtermultilingualpress.supported_post_typesplugin\Integrations\MultilingualPress\ServiceProvider.php:141
filtermultilingualpress.supported_taxonomiesplugin\Integrations\MultilingualPress\ServiceProvider.php:148
actionsite-reviews/review/createdplugin\Integrations\MyCred\MyCredHook.php:67
actionsite-reviews/review/transitionedplugin\Integrations\MyCred\MyCredHook.php:68
filtersite-reviews/reviews/fallbackplugin\Integrations\ProfilePress\Controllers\AccountController.php:90
filtersite-reviews/review/value/authorplugin\Integrations\ProfilePress\Controllers\ProfileController.php:220
filtersite-reviews/reviews/fallbackplugin\Integrations\ProfilePress\Controllers\ProfileController.php:221
filtersite-reviews/summary/value/percentagesplugin\Integrations\ProfilePress\Controllers\ProfileController.php:230
filtersite-reviews/summary/value/ratingplugin\Integrations\ProfilePress\Controllers\ProfileController.php:231
filtersite-reviews/summary/value/textplugin\Integrations\ProfilePress\Controllers\ProfileController.php:232
filtersite-reviews/schema/allplugin\Integrations\SureCart\Controllers\ProductController.php:178
filtersite-reviews/reviews/fallbackplugin\Integrations\UltimateMember\Controllers\AccountController.php:88
filtersite-reviews/review/value/authorplugin\Integrations\UltimateMember\Controllers\ProfileController.php:184
filtersite-reviews/reviews/fallbackplugin\Integrations\UltimateMember\Controllers\ProfileController.php:185
filtersite-reviews/summary/value/percentagesplugin\Integrations\UltimateMember\Controllers\ProfileController.php:194
filtersite-reviews/summary/value/ratingplugin\Integrations\UltimateMember\Controllers\ProfileController.php:195
filtersite-reviews/summary/value/textplugin\Integrations\UltimateMember\Controllers\ProfileController.php:196
actionlws_woorewards_abstracts_event_installedplugin\Integrations\WooRewards\Hooks.php:15
actionphpmailer_initplugin\Modules\Email.php:39
actionwp_mail_failedplugin\Modules\Email.php:78
actionwp_mail_failedplugin\Modules\Email.php:95
filterquery/sql/clause/operatorplugin\Modules\Validator\ReviewLimitsValidator.php:97
actionadmin_noticesplugin\Notices\AbstractNotice.php:35
filterupgrader_pre_installplugin\Overrides\PluginUpgrader.php:12
filterupgrader_clear_destinationplugin\Overrides\PluginUpgrader.php:13
actionaction_scheduler/created_tableplugin\Overrides\ScheduledActionsTable.php:613
filterlogin_urlplugin\Shortcodes\SiteReviewsFormShortcode.php:91
filterregister_urlplugin\Shortcodes\SiteReviewsFormShortcode.php:119
actionplugins_loadedvendors\woocommerce\action-scheduler\action-scheduler.php:36
actionplugins_loadedvendors\woocommerce\action-scheduler\action-scheduler.php:39
actioninitvendors\woocommerce\action-scheduler\classes\abstracts\ActionScheduler.php:196
actioninitvendors\woocommerce\action-scheduler\classes\abstracts\ActionScheduler.php:197
actioninitvendors\woocommerce\action-scheduler\classes\abstracts\ActionScheduler.php:198
actioninitvendors\woocommerce\action-scheduler\classes\abstracts\ActionScheduler.php:199
actioninitvendors\woocommerce\action-scheduler\classes\abstracts\ActionScheduler.php:200
actioninitvendors\woocommerce\action-scheduler\classes\abstracts\ActionScheduler.php:202
actionaction_scheduler/migration_completevendors\woocommerce\action-scheduler\classes\abstracts\ActionScheduler.php:261
actionaction_scheduler_canceled_actionvendors\woocommerce\action-scheduler\classes\abstracts\ActionScheduler_Logger.php:67
actionaction_scheduler_begin_executevendors\woocommerce\action-scheduler\classes\abstracts\ActionScheduler_Logger.php:68
actionaction_scheduler_after_executevendors\woocommerce\action-scheduler\classes\abstracts\ActionScheduler_Logger.php:69
actionaction_scheduler_failed_executionvendors\woocommerce\action-scheduler\classes\abstracts\ActionScheduler_Logger.php:70
actionaction_scheduler_failed_actionvendors\woocommerce\action-scheduler\classes\abstracts\ActionScheduler_Logger.php:71
actionaction_scheduler_unexpected_shutdownvendors\woocommerce\action-scheduler\classes\abstracts\ActionScheduler_Logger.php:72
actionaction_scheduler_reset_actionvendors\woocommerce\action-scheduler\classes\abstracts\ActionScheduler_Logger.php:73
actionaction_scheduler_execution_ignoredvendors\woocommerce\action-scheduler\classes\abstracts\ActionScheduler_Logger.php:74
actionaction_scheduler_failed_fetch_actionvendors\woocommerce\action-scheduler\classes\abstracts\ActionScheduler_Logger.php:75
actionaction_scheduler_failed_to_schedule_next_instancevendors\woocommerce\action-scheduler\classes\abstracts\ActionScheduler_Logger.php:76
actionaction_scheduler_bulk_cancel_actionsvendors\woocommerce\action-scheduler\classes\abstracts\ActionScheduler_Logger.php:77
actionaction_scheduler_stored_actionvendors\woocommerce\action-scheduler\classes\abstracts\ActionScheduler_Logger.php:84
actionwoocommerce_admin_status_content_action-schedulervendors\woocommerce\action-scheduler\classes\ActionScheduler_AdminView.php:56
actionwoocommerce_system_status_reportvendors\woocommerce\action-scheduler\classes\ActionScheduler_AdminView.php:57
filterwoocommerce_admin_status_tabsvendors\woocommerce\action-scheduler\classes\ActionScheduler_AdminView.php:58
actionadmin_menuvendors\woocommerce\action-scheduler\classes\ActionScheduler_AdminView.php:61
actionadmin_noticesvendors\woocommerce\action-scheduler\classes\ActionScheduler_AdminView.php:62
actioncurrent_screenvendors\woocommerce\action-scheduler\classes\ActionScheduler_AdminView.php:63
filteraction_scheduler_store_classvendors\woocommerce\action-scheduler\classes\ActionScheduler_DataController.php:190
filteraction_scheduler_logger_classvendors\woocommerce\action-scheduler\classes\ActionScheduler_DataController.php:191
actiondeactivate_pluginvendors\woocommerce\action-scheduler\classes\ActionScheduler_DataController.php:192
actionaction_scheduler/progress_tickvendors\woocommerce\action-scheduler\classes\ActionScheduler_DataController.php:197
actionshutdownvendors\woocommerce\action-scheduler\classes\ActionScheduler_FatalErrorMonitor.php:45
actionaction_scheduler_before_executevendors\woocommerce\action-scheduler\classes\ActionScheduler_FatalErrorMonitor.php:46
actionaction_scheduler_after_executevendors\woocommerce\action-scheduler\classes\ActionScheduler_FatalErrorMonitor.php:47
actionaction_scheduler_execution_ignoredvendors\woocommerce\action-scheduler\classes\ActionScheduler_FatalErrorMonitor.php:48
actionaction_scheduler_failed_executionvendors\woocommerce\action-scheduler\classes\ActionScheduler_FatalErrorMonitor.php:49
actionaction_scheduler/created_tablevendors\woocommerce\action-scheduler\classes\ActionScheduler_ListTable.php:554
filtercron_schedulesvendors\woocommerce\action-scheduler\classes\ActionScheduler_QueueRunner.php:72
actionshutdownvendors\woocommerce\action-scheduler\classes\ActionScheduler_QueueRunner.php:95
actionaction_scheduler_initvendors\woocommerce\action-scheduler\classes\ActionScheduler_RecurringActionScheduler.php:28
actionpre_get_commentsvendors\woocommerce\action-scheduler\classes\ActionScheduler_WPCommentCleaner.php:44
actionwp_count_commentsvendors\woocommerce\action-scheduler\classes\ActionScheduler_WPCommentCleaner.php:45
actioncomment_feed_wherevendors\woocommerce\action-scheduler\classes\ActionScheduler_WPCommentCleaner.php:46
actionload-tools_page_action-schedulervendors\woocommerce\action-scheduler\classes\ActionScheduler_WPCommentCleaner.php:49
actionload-woocommerce_page_wc-statusvendors\woocommerce\action-scheduler\classes\ActionScheduler_WPCommentCleaner.php:50
actionadmin_noticesvendors\woocommerce\action-scheduler\classes\ActionScheduler_WPCommentCleaner.php:109
actionaction_scheduler_deleted_actionvendors\woocommerce\action-scheduler\classes\data-stores\ActionScheduler_DBLogger.php:112
actionaction_scheduler/created_tablevendors\woocommerce\action-scheduler\classes\data-stores\ActionScheduler_HybridStore.php:75
filtercomments_clausesvendors\woocommerce\action-scheduler\classes\data-stores\ActionScheduler_wpCommentLogger.php:129
actionaction_scheduler_before_process_queuevendors\woocommerce\action-scheduler\classes\data-stores\ActionScheduler_wpCommentLogger.php:254
actionaction_scheduler_after_process_queuevendors\woocommerce\action-scheduler\classes\data-stores\ActionScheduler_wpCommentLogger.php:255
actionpre_get_commentsvendors\woocommerce\action-scheduler\classes\data-stores\ActionScheduler_wpCommentLogger.php:259
actionwp_count_commentsvendors\woocommerce\action-scheduler\classes\data-stores\ActionScheduler_wpCommentLogger.php:260
actioncomment_feed_wherevendors\woocommerce\action-scheduler\classes\data-stores\ActionScheduler_wpCommentLogger.php:261
actionwp_insert_commentvendors\woocommerce\action-scheduler\classes\data-stores\ActionScheduler_wpCommentLogger.php:264
actionwp_set_comment_statusvendors\woocommerce\action-scheduler\classes\data-stores\ActionScheduler_wpCommentLogger.php:265
filterwp_insert_post_datavendors\woocommerce\action-scheduler\classes\data-stores\ActionScheduler_wpPostStore.php:81
filterpre_wp_unique_post_slugvendors\woocommerce\action-scheduler\classes\data-stores\ActionScheduler_wpPostStore.php:82
filterpre_wp_unique_post_slugvendors\woocommerce\action-scheduler\classes\data-stores\ActionScheduler_wpPostStore.php:518
filterwp_insert_post_datavendors\woocommerce\action-scheduler\classes\data-stores\ActionScheduler_wpPostStore.php:1006
filterpre_wp_unique_post_slugvendors\woocommerce\action-scheduler\classes\data-stores\ActionScheduler_wpPostStore.php:1007
filteraction_scheduler_migration_dependencies_metvendors\woocommerce\action-scheduler\classes\data-stores\ActionScheduler_wpPostStore.php:1094
actionadmin_noticesvendors\woocommerce\action-scheduler\classes\migration\Controller.php:176
filteraction_scheduler_store_classvendors\woocommerce\action-scheduler\classes\migration\Controller.php:190
filteraction_scheduler_logger_classvendors\woocommerce\action-scheduler\classes\migration\Controller.php:191
actioninitvendors\woocommerce\action-scheduler\classes\migration\Controller.php:192
actionwp_loadedvendors\woocommerce\action-scheduler\classes\migration\Controller.php:193
actionload-tools_page_action-schedulervendors\woocommerce\action-scheduler\classes\migration\Controller.php:196
actionload-woocommerce_page_wc-statusvendors\woocommerce\action-scheduler\classes\migration\Controller.php:197
actionaction_scheduler_before_schema_updatevendors\woocommerce\action-scheduler\classes\schema\ActionScheduler_LoggerSchema.php:35
actionaction_scheduler_before_schema_updatevendors\woocommerce\action-scheduler\classes\schema\ActionScheduler_StoreSchema.php:40
actionaction_scheduler_deleted_actionvendors\woocommerce\action-scheduler\classes\WP_CLI\Action\Delete_Command.php:40
actionaction_scheduler_execution_ignoredvendors\woocommerce\action-scheduler\classes\WP_CLI\Action\Run_Command.php:42
actionaction_scheduler_after_executevendors\woocommerce\action-scheduler\classes\WP_CLI\Action\Run_Command.php:43
actionaction_scheduler_failed_executionvendors\woocommerce\action-scheduler\classes\WP_CLI\Action\Run_Command.php:44
actionaction_scheduler_failed_validationvendors\woocommerce\action-scheduler\classes\WP_CLI\Action\Run_Command.php:45
actionaction_scheduler_before_executevendors\woocommerce\action-scheduler\classes\WP_CLI\ActionScheduler_WPCLI_QueueRunner.php:87
actionaction_scheduler_after_executevendors\woocommerce\action-scheduler\classes\WP_CLI\ActionScheduler_WPCLI_QueueRunner.php:88
actionaction_scheduler_failed_executionvendors\woocommerce\action-scheduler\classes\WP_CLI\ActionScheduler_WPCLI_QueueRunner.php:89
actionaction_scheduler/migrate_action_dry_runvendors\woocommerce\action-scheduler\classes\WP_CLI\Migration_Command.php:137
actionaction_scheduler/no_action_to_migratevendors\woocommerce\action-scheduler\classes\WP_CLI\Migration_Command.php:144
actionaction_scheduler/migrate_action_failedvendors\woocommerce\action-scheduler\classes\WP_CLI\Migration_Command.php:151
actionaction_scheduler/migrate_action_incompletevendors\woocommerce\action-scheduler\classes\WP_CLI\Migration_Command.php:158
actionaction_scheduler/migrated_actionvendors\woocommerce\action-scheduler\classes\WP_CLI\Migration_Command.php:167
actionaction_scheduler/migration_batch_startingvendors\woocommerce\action-scheduler\classes\WP_CLI\Migration_Command.php:176
actionaction_scheduler/migration_batch_completevendors\woocommerce\action-scheduler\classes\WP_CLI\Migration_Command.php:183
Maintenance & Trust

Site Reviews Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 15, 2026
PHP min version8.1.2
Downloads3.1M

Community Trust

Rating98/100
Number of ratings366
Active installs70K
Developer Profile

Site Reviews Developer Profile

Gemini Labs

3 plugins · 71K total installs

75
trust score
Avg Security Score
94/100
Avg Patch Time
427 days
View full developer profile
Detection Fingerprints

How We Detect Site Reviews

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/site-reviews/assets/css/admin/color-picker.min.css/wp-content/plugins/site-reviews/assets/css/admin/default.min.css/wp-content/plugins/site-reviews/assets/css/admin/field-editor.min.css/wp-content/plugins/site-reviews/assets/css/admin/forms.min.css/wp-content/plugins/site-reviews/assets/css/admin/legacy.min.css/wp-content/plugins/site-reviews/assets/css/admin/locations.min.css/wp-content/plugins/site-reviews/assets/css/admin/migrate.min.css/wp-content/plugins/site-reviews/assets/css/admin/styles.min.css+17 more
Script Paths
/wp-content/plugins/site-reviews/assets/js/admin/color-picker.min.js/wp-content/plugins/site-reviews/assets/js/admin/field-editor.min.js/wp-content/plugins/site-reviews/assets/js/admin/forms.min.js/wp-content/plugins/site-reviews/assets/js/admin/locations.min.js/wp-content/plugins/site-reviews/assets/js/admin/migrate.min.js/wp-content/plugins/site-reviews/assets/js/admin/styles.min.js+5 more
Version Parameters
site-reviews/assets/css/admin/color-picker.min.css?ver=site-reviews/assets/css/admin/default.min.css?ver=site-reviews/assets/css/admin/field-editor.min.css?ver=site-reviews/assets/css/admin/forms.min.css?ver=site-reviews/assets/css/admin/legacy.min.css?ver=site-reviews/assets/css/admin/locations.min.css?ver=site-reviews/assets/css/admin/migrate.min.css?ver=site-reviews/assets/css/admin/styles.min.css?ver=site-reviews/assets/css/admin/users.min.css?ver=site-reviews/assets/css/frontend/default.min.css?ver=site-reviews/assets/css/frontend/display.min.css?ver=site-reviews/assets/css/frontend/icons.min.css?ver=site-reviews/assets/css/frontend/shortcodes.min.css?ver=site-reviews/assets/css/frontend/themes.min.css?ver=site-reviews/assets/js/admin/color-picker.min.js?ver=site-reviews/assets/js/admin/field-editor.min.js?ver=site-reviews/assets/js/admin/forms.min.js?ver=site-reviews/assets/js/admin/locations.min.js?ver=site-reviews/assets/js/admin/migrate.min.js?ver=site-reviews/assets/js/admin/styles.min.js?ver=site-reviews/assets/js/admin/users.min.js?ver=site-reviews/assets/js/frontend/display.min.js?ver=site-reviews/assets/js/frontend/forms.min.js?ver=site-reviews/assets/js/frontend/shortcodes.min.js?ver=site-reviews/assets/js/frontend/themes.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
glsr-starsglsr-starglsr-post-type-reviewsglsr-reviews-collectionglsr-reviews-titleglsr-reviews-wrapperglsr-reviewglsr-user-display-name+479 more
HTML Comments
<!-- This fixes the "Product Reviews Style" setting in the Salient theme when the option is set to "Submission Form Off Canvas". --><!-- @see https://themenectar.com/salient/ --><!-- This fixes the Site Reviews settings when the User Activity Log plugin is enabled. --><!-- @see https://wordpress.org/support/topic/this-breaks-the-wordpress-color-picker/ -->+8 more
Data Attributes
data-integration="site-reviews"data-post-type="site-reviews"data-plugin-name="Site Reviews"
JS Globals
glsrSiteReviews
REST Endpoints
/wp-json/site-reviews/v1/reviews/wp-json/site-reviews/v1/settings
Shortcode Output
[site_reviews][site_reviews_summary][site_reviews_form][site_reviews_list]
FAQ

Frequently Asked Questions about Site Reviews