
Skeps Reviews Widget Security & Risk Analysis
wordpress.org/plugins/skeps-review-widgetAuthenticate with your Google account to display the Google My Business star rating widget on your WordPress website. No Google API's knowledge n …
Is Skeps Reviews Widget Safe to Use in 2026?
Generally Safe
Score 85/100Skeps Reviews Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The skeps-review-widget plugin v1.0.0 exhibits a concerning security posture due to a significant number of unprotected entry points. While it demonstrates good practices in SQL query handling with 100% prepared statements and has a clean vulnerability history with no recorded CVEs, the high number of AJAX handlers (5) lacking authentication checks presents a substantial risk. This means an unauthenticated attacker could potentially interact with these AJAX endpoints, leading to unintended actions or information disclosure.
The taint analysis reveals two flows with unsanitized paths, which, although not classified as critical or high severity, warrant attention. These could indicate potential vulnerabilities if further exploitation is possible. The low percentage of properly escaped output (17%) also suggests a risk of cross-site scripting (XSS) vulnerabilities, especially when combined with the unprotected AJAX endpoints. The plugin does implement nonce checks for its entry points, which is a positive measure, but their effectiveness is diminished when the endpoints themselves lack proper authentication.
In conclusion, the plugin's strengths lie in its SQL handling and lack of past vulnerabilities. However, the critical weaknesses of unprotected AJAX endpoints and potential unsanitized paths, coupled with insufficient output escaping, create a notable security risk. Addressing the unauthenticated AJAX handlers and improving output sanitization are crucial steps to enhance the plugin's security.
Key Concerns
- AJAX handlers without auth checks
- Unsanitized paths in taint analysis
- Low percentage of properly escaped output
- Large attack surface without auth
Skeps Reviews Widget Security Vulnerabilities
Skeps Reviews Widget Code Analysis
Output Escaping
Data Flow Analysis
Skeps Reviews Widget Attack Surface
AJAX Handlers 5
Shortcodes 1
WordPress Hooks 8
Scheduled Events 1
Maintenance & Trust
Skeps Reviews Widget Maintenance & Trust
Maintenance Signals
Community Trust
Skeps Reviews Widget Alternatives
Widgets for Google Reviews
wp-reviews-plugin-for-google
Embed Google reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Google reviews.
Rich Showcase for Google Reviews
widget-google-reviews
Display up to 10 Google reviews in less than a minute. Continue collecting new reviews. No limits on connected places, widgets, shortcodes and blocks.
Reviews and Rating – Google Reviews
g-business-reviews-rating
Completely restriction-free Google reviews and rating as Shortcode/Widget. Extensive display options; delicious themes; includes Structured Data.
Lara's Google Analytics (GA4)
lara-google-analytics
Full width Google Analytics dashboard widget for Wordpress admin interface, which also inserts latest Google Analytics (GA4) tracking code to your pag …
Customer Reviews Collector for WooCommerce
customer-reviews-collector-for-woocommerce
Collect reviews on Google, Facebook, Yelp, Trustindex and other platforms automatically, with the help of our system.
Skeps Reviews Widget Developer Profile
2 plugins · 10 total installs
How We Detect Skeps Reviews Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/skeps-review-widget/dist/assets/css/sgr-admin.min.css/wp-content/plugins/skeps-review-widget/dist/assets/css/sgr-public.min.css/wp-content/plugins/skeps-review-widget/dist/assets/js/sgr-admin.js/wp-content/plugins/skeps-review-widget/dist/assets/js/sgr-admin.jsskeps-review-widget/dist/assets/css/sgr-admin.min.css?ver=skeps-review-widget/dist/assets/css/sgr-public.min.css?ver=skeps-review-widget/dist/assets/js/sgr-admin.js?ver=HTML / DOM Fingerprints
sgr-widgetdata-nonce="sgr_nonce"sgr_ajax[sgr-widget][sgr-widget type=