
Stars Rating Security & Risk Analysis
wordpress.org/plugins/stars-ratingA plugin to turn comments into reviews by adding rating feature.
Is Stars Rating Safe to Use in 2026?
Generally Safe
Score 99/100Stars Rating has a strong security track record. Known vulnerabilities have been patched promptly.
The "stars-rating" plugin v4.0.7 exhibits a generally good security posture, with no identified critical or high severity vulnerabilities in the static analysis, including no dangerous functions, file operations, or external HTTP requests. The presence of nonce checks and capability checks, along with the consistent use of prepared statements for SQL queries, indicates a commitment to secure coding practices. However, a significant concern is the moderate percentage of output escaping (68%), suggesting that some data might be rendered without proper sanitization, potentially opening avenues for cross-site scripting (XSS) vulnerabilities. While the taint analysis shows no flows with unsanitized paths, this doesn't completely negate the risk from unescaped output. The plugin's vulnerability history reveals one high severity CVE related to Uncontrolled Resource Consumption, last patched in late 2021. The fact that this vulnerability is no longer unpatched is positive, but the historical presence of a high-severity issue warrants vigilance. Overall, the plugin demonstrates strengths in core security implementations but has a notable weakness in output escaping and a past high-severity vulnerability that requires attention.
Key Concerns
- Moderate output escaping (68%)
- One high severity CVE in history (Uncontrolled Resource Consumption)
Stars Rating Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Stars Rating <= 3.5.0 - Denial of Service
Stars Rating Code Analysis
Output Escaping
Stars Rating Attack Surface
Shortcodes 1
WordPress Hooks 15
Maintenance & Trust
Stars Rating Maintenance & Trust
Maintenance Signals
Community Trust
Stars Rating Alternatives
REVIEWS.io for WooCommerce
reviewscouk-for-woocommerce
REVIEWS.io, helps eCommerce merchants to collect & display verified product and company reviews. A Google Licensed partner.
Five-Star Ratings Shortcode
five-star-ratings-shortcode
Simple lightweight shortcode to add 5-star ratings anywhere.
Better WooCommerce Stars Shortcode
better-woocommerce-stars-shortcode
Creates a shortcode that displays the rating, in stars, of any WooCommerce product.
Integration for BazaarVoice
integration-for-baazarvoice
An plugin that will integrate with the Bazaarvoice rating system.
weeComments – Shop & Products Reviews
weecomments
Genera confianza en tu tienda online y aumenta las ventas con weecomments. http://weecomments.com Muestra un widget de opiniones de la tienda online, …
Stars Rating Developer Profile
3 plugins · 2K total installs
How We Detect Stars Rating
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/stars-rating/includes/css/font-awesome.min.css/wp-content/plugins/stars-rating/admin/css/stars-rating-admin.css/wp-content/plugins/stars-rating/public/css/fontawesome-stars.css/wp-content/plugins/stars-rating/public/css/stars-rating-public.css/wp-content/plugins/stars-rating/public/js/jquery.barrating.min.js/wp-content/plugins/stars-rating/public/js/script.js/wp-content/plugins/stars-rating/public/js/jquery.barrating.min.js/wp-content/plugins/stars-rating/public/js/script.jsstars-rating/admin/css/stars-rating-admin.css?ver=stars-rating/public/css/stars-rating-public.css?ver=stars-rating/public/js/script.js?ver=HTML / DOM Fingerprints
rating-starsstars-style-regularstars-style-modernstars-style-starstars-style-squarestars-style-filledfarateddata-rating-valueStars_Rating_Public[stars_rating_avg]