
Star Rating Feedback Security & Risk Analysis
wordpress.org/plugins/star-rating-feedbackThis plugin allows you to add a Star Rating feedback form. Currently it is localised for use in the UK
Is Star Rating Feedback Safe to Use in 2026?
Generally Safe
Score 85/100Star Rating Feedback has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "star-rating-feedback" plugin version 0.2 presents a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and has no known past vulnerabilities or unpatched CVEs. The attack surface is also relatively small, with only one shortcode as an entry point and no AJAX handlers or REST API routes exposed without authentication.
However, significant concerns arise from the code analysis. The plugin exhibits a complete lack of output escaping for all identified output points, creating a high risk of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the taint analysis reveals two flows with unsanitized paths, classified as high severity, which strongly suggests potential for data injection or manipulation. The absence of nonce and capability checks on the single entry point (shortcode) is also a critical oversight, leaving it vulnerable to unauthorized or unintended execution.
Given the lack of historical vulnerabilities, it might suggest that past versions or similar functionalities were not exploited. However, the current code analysis reveals substantial weaknesses in output sanitization and data handling. The high number of unsanitized taint flows and the complete lack of output escaping are serious concerns that outweigh the positive aspects of SQL preparation and lack of historical issues. The plugin, as analyzed, is not secure without remediation for these critical code-level flaws.
Key Concerns
- High severity unsanitized taint flows
- 100% of outputs unescaped
- No nonce checks on entry points
- No capability checks on entry points
Star Rating Feedback Security Vulnerabilities
Star Rating Feedback Release Timeline
Star Rating Feedback Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Star Rating Feedback Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
Star Rating Feedback Maintenance & Trust
Maintenance Signals
Community Trust
Star Rating Feedback Alternatives
Contact Form & SMTP Plugin for WordPress by PirateForms
pirate-forms
A simple and effective WordPress contact form & SMTP plugin. Compatible with best themes out there, is both a secure and responsive contact form p …
Contact Form Clean and Simple
clean-and-simple-contact-form-by-meg-nicholas
A clean and simple contact form with flexible CSS framework support.
Lite Contact Form
lite-contact-form
Lightweight and simple contact form with no additional user-unfriendly options. Can be additionally protected against spam by using Akismet and Google …
Surveys by Feedback Cat
surveys-by-feedback-cat
Surveys by Feedback Cat Helps You Grow Your Business Or Blog By Making It Easy To Gather Feedback Using Onpage User Surveys.
Voice Feedback – Collect Anonymous Voice Messages & Real User Insights Instantly
voice-feedback
Let users record and send voice feedback on your WordPress site. A simple voice recorder plugin with playback, re-record, and admin voice library.
Star Rating Feedback Developer Profile
1 plugin · 10 total installs
How We Detect Star Rating Feedback
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/star-rating-feedback/stylesheets/font-awesome.min.css/wp-content/plugins/star-rating-feedback/stylesheets/jquery.datepick.css/wp-content/plugins/star-rating-feedback/stylesheets/style.css/wp-content/plugins/star-rating-feedback/javascripts/jquery.validate.js/wp-content/plugins/star-rating-feedback/javascripts/jquery.raty.min.js/wp-content/plugins/star-rating-feedback/javascripts/jquery.datepick.js/wp-content/plugins/star-rating-feedback/javascripts/jquery.datepick-en-GB.js/wp-content/plugins/star-rating-feedback/javascripts/feedback.js/wp-content/plugins/star-rating-feedback/stylesheets/style.css?ver=/wp-content/plugins/star-rating-feedback/javascripts/feedback.js?ver=HTML / DOM Fingerprints
star-ratingfauxLabelfeedback-headerdata-typedata-icondata-colordata-color-ondata-colorsdata-size+4 moreMyScriptParams<div class="star-rating" data-type=<label class="feedback-header" for="comments">