ST Product Review Generator Security & Risk Analysis

wordpress.org/plugins/st-product-review-generator

Transform the way you manage product feedback with ST Product Review Generator by StrivioThemes — the ultimate solution for bringing your customer&#03 …

20 active installs v0.0.5 PHP 7.4+ WP 5.6+ Updated Jan 19, 2026
commentsgeneratorreviewssample-datawoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ST Product Review Generator Safe to Use in 2026?

Generally Safe

Score 100/100

ST Product Review Generator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "st-product-review-generator" plugin v0.0.5 presents a generally positive security posture based on the provided static analysis. The absence of any known CVEs and the plugin's history of no recorded vulnerabilities suggest a strong track record. The code exhibits good practices in several areas, including a high percentage of properly escaped output (97%), robust nonce checks (4), and capability checks (3). The attack surface is minimal with only one AJAX handler, and importantly, this handler is not reported as unprotected. There are no critical or high severity taint flows identified, and no SQL queries are executed without prepared statements, which are significant strengths. The plugin also avoids dangerous functions and file operations, further contributing to its secure design. However, a minor concern lies in the presence of raw SQL queries, even if they are not currently exploitable due to other security measures. The external HTTP request, while only one, warrants attention as it represents a potential third-party dependency risk. The bundled Select2 library could also be a point of concern if it's an older version, though this is not explicitly stated. Overall, this plugin appears well-secured, but vigilance regarding its SQL practices and any bundled libraries is recommended.

Key Concerns

  • Raw SQL queries without prepared statements
  • External HTTP requests present
Vulnerabilities
None known

ST Product Review Generator Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

ST Product Review Generator Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
0 prepared
Unescaped Output
2
64 escaped
Nonce Checks
4
Capability Checks
3
File Operations
0
External Requests
1
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

0% prepared2 total queries

Output Escaping

97% escaped66 total outputs
Data Flows
All sanitized

Data Flow Analysis

3 flows
stprg_handle_license_form_submission (includes\stprg-license-manager.php:58)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

ST Product Review Generator Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_stprg_get_products_by_categoryst-product-review-generator.php:29
WordPress Hooks 5
actionadmin_menust-product-review-generator.php:25
actionadmin_post_st_generate_reviewsst-product-review-generator.php:26
actionadmin_noticesst-product-review-generator.php:27
actionadmin_enqueue_scriptsst-product-review-generator.php:28
actionadmin_headst-product-review-generator.php:30
Maintenance & Trust

ST Product Review Generator Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJan 19, 2026
PHP min version7.4
Downloads274

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

ST Product Review Generator Developer Profile

Kristyna Bennett

30 plugins · 2K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ST Product Review Generator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/st-product-review-generator/assets/select2/select2.min.css/wp-content/plugins/st-product-review-generator/assets/css/stprg-admin.css/wp-content/plugins/st-product-review-generator/assets/select2/select2.min.js/wp-content/plugins/st-product-review-generator/assets/js/stprg-admin.js
Script Paths
https://fonts.googleapis.com/css2?family=Montserrat:wght@400;500;600;700&display=swap
Version Parameters
st-product-review-generator/assets/select2/select2.min.css?ver=st-product-review-generator/assets/css/stprg-admin.css?ver=st-product-review-generator/assets/select2/select2.min.js?ver=st-product-review-generator/assets/js/stprg-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
stprg-main-wrapper
HTML Comments
<!-- ST Product Review Generator Admin Page --><!-- Review Generation Form --><!-- Product Selection --><!-- Category Filter -->+6 more
Data Attributes
data-action="stprg_get_products_by_category"data-nonce="
JS Globals
stprgAdminData
FAQ

Frequently Asked Questions about ST Product Review Generator