
Reviews Widgets for Google & 45+ platforms by Repuso Security & Risk Analysis
wordpress.org/plugins/social-testimonials-and-reviews-widgetCollect social proof reviews, showcase on your website. Boost your website sales and conversion rate.
Is Reviews Widgets for Google & 45+ platforms by Repuso Safe to Use in 2026?
Generally Safe
Score 92/100Reviews Widgets for Google & 45+ platforms by Repuso has a strong security track record. Known vulnerabilities have been patched promptly.
The 'social-testimonials-and-reviews-widget' plugin version 5.32 exhibits a mixed security posture. The static analysis reveals good practices in several areas, with all identified AJAX handlers and REST API routes having appropriate authorization checks. The absence of raw SQL queries, file operations, and a low number of external HTTP requests are positive indicators. However, the plugin has a history of significant vulnerabilities, with 5 known CVEs, including one high and four medium severity issues, primarily related to missing authorization, Cross-Site Scripting (XSS), and Cross-Site Request Forgery (CSRF). While there are currently no unpatched vulnerabilities, this history suggests a pattern of recurring security weaknesses that attackers may exploit if new flaws are introduced or old ones reappear.
The code analysis flags one flow with an unsanitized path, indicating a potential risk, although it's not classified as critical or high severity. The output escaping rate of 83% also leaves room for improvement, with 17% of outputs potentially being unescaped, which could lead to XSS vulnerabilities if user-supplied data is involved. The presence of 7 AJAX handlers, while all protected, still represents a notable attack surface. The external HTTP request, though only one, warrants attention as it could be a vector for further exploitation if not properly secured.
In conclusion, while the plugin implements some strong security measures, particularly around SQL and authorization on its primary entry points, its past vulnerability history and the presence of unsanitized paths and unescaped outputs are significant concerns. Users should remain vigilant, and ongoing security audits are recommended to ensure these historical patterns do not repeat.
Key Concerns
- Flows with unsanitized paths found
- Output escaping is not 100%
- History of 1 high severity CVE
- History of 4 medium severity CVEs
- 7 AJAX handlers, attack surface
Reviews Widgets for Google & 45+ platforms by Repuso Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
Social proof testimonials and reviews by Repuso <= 5.29 - Missing Authorization
Social proof testimonials and reviews by Repuso <= 5.21 - Missing Authorization
Social proof testimonials and reviews by Repuso <= 5.20 - Authenticated (Contributor+) Stored Cross-Site Scripting
Social proof testimonials and reviews by Repuso <= 4.97 - Missing Authorization
Social proof testimonials and reviews by Repuso <= 5.01 - Cross-Site Request Forgery
Reviews Widgets for Google & 45+ platforms by Repuso Code Analysis
Output Escaping
Data Flow Analysis
Reviews Widgets for Google & 45+ platforms by Repuso Attack Surface
AJAX Handlers 7
WordPress Hooks 7
Maintenance & Trust
Reviews Widgets for Google & 45+ platforms by Repuso Maintenance & Trust
Maintenance Signals
Community Trust
Reviews Widgets for Google & 45+ platforms by Repuso Alternatives
Proofratings
proofratings
Display social proof ratings on your website. Boost your website sales and conversion rate.
Reviewkit – Trustpilot Reviews Widget & Embed
gutensuite-reviewkit
Easily embed and showcase Trustpilot reviews on your WordPress site to build trust and boost conversions.
Trustify Blocks – Testimonials, Reviews & Trust Widgets for Gutenberg
trustify-blocks
Build trust and credibility with your website visitors using customizable testimonials and review blocks.
Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More
reviews-feed
No API key required. Display Yelp and Google reviews for any business in a clean, customizable feed on your site.
Rich Showcase for Google Reviews
widget-google-reviews
Display up to 10 Google reviews in less than a minute. Continue collecting new reviews. No limits on connected places, widgets, shortcodes and blocks.
Reviews Widgets for Google & 45+ platforms by Repuso Developer Profile
1 plugin · 1K total installs
How We Detect Reviews Widgets for Google & 45+ platforms by Repuso
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/social-testimonials-and-reviews-widget/css/rw-admin.css/wp-content/plugins/social-testimonials-and-reviews-widget/js/rw-admin.jsHTML / DOM Fingerprints
data-repuso-idajax_var[repuso_widget][Repuso_widget][REPUso_widget]