Reviews Widgets for Google & 45+ platforms by Repuso Security & Risk Analysis

wordpress.org/plugins/social-testimonials-and-reviews-widget

Collect social proof reviews, showcase on your website. Boost your website sales and conversion rate.

1K active installs v5.32 PHP + WP 3.0.1+ Updated Jan 27, 2026
badgereviewsreviews-badgetestimonial-feedtestimonials
92
A · Safe
CVEs total5
Unpatched0
Last CVEOct 16, 2025
Download
Safety Verdict

Is Reviews Widgets for Google & 45+ platforms by Repuso Safe to Use in 2026?

Generally Safe

Score 92/100

Reviews Widgets for Google & 45+ platforms by Repuso has a strong security track record. Known vulnerabilities have been patched promptly.

5 known CVEsLast CVE: Oct 16, 2025Updated 2mo ago
Risk Assessment

The 'social-testimonials-and-reviews-widget' plugin version 5.32 exhibits a mixed security posture. The static analysis reveals good practices in several areas, with all identified AJAX handlers and REST API routes having appropriate authorization checks. The absence of raw SQL queries, file operations, and a low number of external HTTP requests are positive indicators. However, the plugin has a history of significant vulnerabilities, with 5 known CVEs, including one high and four medium severity issues, primarily related to missing authorization, Cross-Site Scripting (XSS), and Cross-Site Request Forgery (CSRF). While there are currently no unpatched vulnerabilities, this history suggests a pattern of recurring security weaknesses that attackers may exploit if new flaws are introduced or old ones reappear.

The code analysis flags one flow with an unsanitized path, indicating a potential risk, although it's not classified as critical or high severity. The output escaping rate of 83% also leaves room for improvement, with 17% of outputs potentially being unescaped, which could lead to XSS vulnerabilities if user-supplied data is involved. The presence of 7 AJAX handlers, while all protected, still represents a notable attack surface. The external HTTP request, though only one, warrants attention as it could be a vector for further exploitation if not properly secured.

In conclusion, while the plugin implements some strong security measures, particularly around SQL and authorization on its primary entry points, its past vulnerability history and the presence of unsanitized paths and unescaped outputs are significant concerns. Users should remain vigilant, and ongoing security audits are recommended to ensure these historical patterns do not repeat.

Key Concerns

  • Flows with unsanitized paths found
  • Output escaping is not 100%
  • History of 1 high severity CVE
  • History of 4 medium severity CVEs
  • 7 AJAX handlers, attack surface
Vulnerabilities
5

Reviews Widgets for Google & 45+ platforms by Repuso Security Vulnerabilities

CVEs by Year

2 CVEs in 2023
2023
3 CVEs in 2025
2025
Patched Has unpatched

Severity Breakdown

High
1
Medium
4

5 total CVEs

CVE-2025-62071medium · 4.3Missing Authorization

Social proof testimonials and reviews by Repuso <= 5.29 - Missing Authorization

Oct 16, 2025 Patched in 5.30 (8d)
CVE-2025-31886medium · 4.3Missing Authorization

Social proof testimonials and reviews by Repuso <= 5.21 - Missing Authorization

Apr 1, 2025 Patched in 5.22 (8d)
CVE-2024-13351high · 7.2Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Social proof testimonials and reviews by Repuso <= 5.20 - Authenticated (Contributor+) Stored Cross-Site Scripting

Jan 14, 2025 Patched in 5.21 (1d)
CVE-2023-46196medium · 4.3Missing Authorization

Social proof testimonials and reviews by Repuso <= 4.97 - Missing Authorization

Oct 18, 2023 Patched in 5.00 (97d)
CVE-2023-45048medium · 5.4Cross-Site Request Forgery (CSRF)

Social proof testimonials and reviews by Repuso <= 5.01 - Cross-Site Request Forgery

Oct 3, 2023 Patched in 5.02 (112d)
Code Analysis
Analyzed Mar 16, 2026

Reviews Widgets for Google & 45+ platforms by Repuso Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
16
80 escaped
Nonce Checks
8
Capability Checks
11
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

83% escaped96 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

4 flows1 with unsanitized paths
<social-testimonials-and-reviews-widget> (social-testimonials-and-reviews-widget.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Reviews Widgets for Google & 45+ platforms by Repuso Attack Surface

Entry Points7
Unprotected0

AJAX Handlers 7

authwp_ajax_rw_get_login_urlsocial-testimonials-and-reviews-widget.php:584
authwp_ajax_rw_store_loginsocial-testimonials-and-reviews-widget.php:585
authwp_ajax_rw_store_subaccountsocial-testimonials-and-reviews-widget.php:586
authwp_ajax_rw_store_infosocial-testimonials-and-reviews-widget.php:587
authwp_ajax_rw_logoutsocial-testimonials-and-reviews-widget.php:588
authwp_ajax_rw_store_notice_dismisssocial-testimonials-and-reviews-widget.php:589
authwp_ajax_hooksocial-testimonials-and-reviews-widget.php:594
WordPress Hooks 7
actioninitsocial-testimonials-and-reviews-widget.php:577
actionwp_footersocial-testimonials-and-reviews-widget.php:578
actionadmin_enqueue_scriptssocial-testimonials-and-reviews-widget.php:582
actionadmin_menusocial-testimonials-and-reviews-widget.php:583
actionadmin_enqueue_scriptssocial-testimonials-and-reviews-widget.php:590
actionplugins_loadedsocial-testimonials-and-reviews-widget.php:592
actionadmin_noticessocial-testimonials-and-reviews-widget.php:593
Maintenance & Trust

Reviews Widgets for Google & 45+ platforms by Repuso Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 27, 2026
PHP min version
Downloads71K

Community Trust

Rating96/100
Number of ratings24
Active installs1K
Developer Profile

Reviews Widgets for Google & 45+ platforms by Repuso Developer Profile

Repuso

1 plugin · 1K total installs

82
trust score
Avg Security Score
92/100
Avg Patch Time
45 days
View full developer profile
Detection Fingerprints

How We Detect Reviews Widgets for Google & 45+ platforms by Repuso

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/social-testimonials-and-reviews-widget/css/rw-admin.css/wp-content/plugins/social-testimonials-and-reviews-widget/js/rw-admin.js

HTML / DOM Fingerprints

Data Attributes
data-repuso-id
JS Globals
ajax_var
Shortcode Output
[repuso_widget][Repuso_widget][REPUso_widget]
FAQ

Frequently Asked Questions about Reviews Widgets for Google & 45+ platforms by Repuso