Trustami Badge for Customer Reviews and Google Stars Security & Risk Analysis

wordpress.org/plugins/trustami-badge-for-customer-reviews-and-google-stars

Trustami plugin for WooCommerce. Trustami - One badge for all your customer reviews. Trustami collects, analyzes and presents a users' distribute …

100 active installs v1.0.12 PHP 5.6+ WP 5.6+ Updated Dec 11, 2025
customer-reviewsgoogle-starsreview-overviewreviewswidget
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Trustami Badge for Customer Reviews and Google Stars Safe to Use in 2026?

Generally Safe

Score 100/100

Trustami Badge for Customer Reviews and Google Stars has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The security posture of the trustami-badge-for-customer-reviews-and-google-stars plugin, version 1.0.12, appears to be a mixed bag. On the positive side, there are no recorded vulnerabilities (CVEs) associated with this plugin, nor are there any apparent critical or high severity taint flows, dangerous functions, or SQL injection risks due to the use of prepared statements. The limited attack surface, with zero AJAX handlers, REST API routes, shortcodes, or cron events, also contributes to a lower initial risk profile. However, a significant concern arises from the complete lack of output escaping. With 26 total outputs, none of which are properly escaped, the plugin is highly vulnerable to Cross-Site Scripting (XSS) attacks. This is a critical flaw that could allow attackers to inject malicious scripts into pages rendered by the plugin, potentially leading to session hijacking, credential theft, or defacement. The absence of nonce and capability checks further exacerbates this risk by not providing essential authorization and integrity controls.

Key Concerns

  • All outputs are unescaped
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Trustami Badge for Customer Reviews and Google Stars Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Trustami Badge for Customer Reviews and Google Stars Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
26
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped26 total outputs
Attack Surface

Trustami Badge for Customer Reviews and Google Stars Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 18
filterwoocommerce_settings_tabs_arrayincludes\class-trustami-settings-tab.php:15
actionwoocommerce_settings_tabs_trustami_settings_tabincludes\class-trustami-settings-tab.php:16
actionwoocommerce_update_options_trustami_settings_tabincludes\class-trustami-settings-tab.php:17
actionplugins_loadedincludes\class-trustami.php:153
actionadmin_enqueue_scriptsincludes\class-trustami.php:168
actionadmin_enqueue_scriptsincludes\class-trustami.php:169
actionwp_footerincludes\class-trustami.php:186
actionwidgets_initincludes\widgets\class-trustami-widget-badge.php:92
actionwidgets_initincludes\widgets\class-trustami-widget-box.php:92
actionwidgets_initincludes\widgets\class-trustami-widget-button.php:93
actionwidgets_initincludes\widgets\class-trustami-widget-comments.php:92
actionwidgets_initincludes\widgets\class-trustami-widget-container.php:92
actionwidgets_initincludes\widgets\class-trustami-widget-duo.php:93
actionwidgets_initincludes\widgets\class-trustami-widget-shopauskunft.php:93
actionwidgets_initincludes\widgets\class-trustami-widget-social.php:93
actionwidgets_initincludes\widgets\class-trustami-widget-stars.php:93
actionwidgets_initincludes\widgets\class-trustami-widget-sticker.php:93
actionwidgets_initincludes\widgets\class-trustami-widget-text.php:92
Maintenance & Trust

Trustami Badge for Customer Reviews and Google Stars Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 11, 2025
PHP min version5.6
Downloads4K

Community Trust

Rating100/100
Number of ratings1
Active installs100
Developer Profile

Trustami Badge for Customer Reviews and Google Stars Developer Profile

Trustami

1 plugin · 100 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Trustami Badge for Customer Reviews and Google Stars

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/trustami-badge-for-customer-reviews-and-google-stars/css/trustami-admin.css/wp-content/plugins/trustami-badge-for-customer-reviews-and-google-stars/js/trustami-admin.js
Script Paths
/wp-content/plugins/trustami-badge-for-customer-reviews-and-google-stars/js/trustami-admin.js
Version Parameters
trustami-admin.css?ver=trustami-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
trustami-badge-settings
Data Attributes
data-trustami-settings
JS Globals
trustami_ajax_object
Shortcode Output
[trustami-badge]
FAQ

Frequently Asked Questions about Trustami Badge for Customer Reviews and Google Stars