
TWB Woocommerce Reviews Security & Risk Analysis
wordpress.org/plugins/twb-woocommerce-reviewsDisplay Woocommerce reviews anywhere using shortcode. Specify reviews using product ID. Now supports Masonry layout.
Is TWB Woocommerce Reviews Safe to Use in 2026?
Generally Safe
Score 91/100TWB Woocommerce Reviews has a strong security track record. Known vulnerabilities have been patched promptly.
The twb-woocommerce-reviews plugin v1.7.8 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by utilizing prepared statements for all SQL queries and performing nonce checks. There are no identified critical or high-severity taint flows, and the static analysis reveals a limited attack surface with no direct unprotected entry points like unprotected AJAX handlers or REST API routes. File operations and external HTTP requests are also absent, reducing common attack vectors.
However, several areas raise concerns. The significant percentage of improperly escaped output (30%) indicates a potential for Cross-Site Scripting (XSS) vulnerabilities, especially given that XSS is listed as a common vulnerability type in its history. While the plugin has no currently unpatched CVEs, its history of two medium-severity CVEs, including CSRF and XSS, suggests past weaknesses that could resurface if not diligently addressed. The absence of capability checks on the identified shortcode also means that any actions performed by this shortcode might not be properly authorized, potentially leading to privilege escalation or unauthorized operations if the shortcode's functionality is sensitive.
In conclusion, while the plugin has made strides in secure coding practices like prepared statements and nonce checks, the prevalent unescaped output and past vulnerability history warrant careful consideration. The lack of capability checks on its sole entry point is a notable weakness. Further investigation into the specific unescaped output instances and the functionality of the shortcode is recommended to fully mitigate potential risks.
Key Concerns
- Significant unescaped output
- Past medium severity CVEs (2 total)
- Missing capability checks on shortcode
TWB Woocommerce Reviews Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
TWB Woocommerce Reviews <= 1.7.7 - Cross-Site Request Forgery
TWB Woocommerce Reviews <= 1.7.5 - Authenticated (Administrator+) Stored Cross-Site Scripting
TWB Woocommerce Reviews Code Analysis
Output Escaping
TWB Woocommerce Reviews Attack Surface
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
TWB Woocommerce Reviews Maintenance & Trust
Maintenance Signals
Community Trust
TWB Woocommerce Reviews Alternatives
Wiremo – Product Reviews for WooCommerce
woo-reviews-by-wiremo
Show customers, that you care with Wiremo’s review request email feature. Automatically display great reviews on your website to boost sales.
Site Reviews
site-reviews
Site Reviews is a complete review management solution that integrates with WooCommerce and SureCart and works similarly to reviews on Amazon, Tripadvi …
Photo Reviews for WooCommerce
woo-photo-reviews
Let customers attach photos to reviews, enhanced with filterable grids and overall ratings. Auto-send review reminders and coupon emails
ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema
reviewx
Drive woocommerce business growth with social proof: gather product reviews with multicriteria ratings, auto-reminder emails, discounts, and more.
Yotpo: Product & Photo Reviews for WooCommerce
yotpo-social-reviews-for-woocommerce
Collect product reviews, photo reviews, site reviews & ratings
TWB Woocommerce Reviews Developer Profile
3 plugins · 700 total installs
How We Detect TWB Woocommerce Reviews
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/twb-woocommerce-reviews/admin/js/admin_js.js/wp-content/plugins/twb-woocommerce-reviews/inc/css/twb_wc_reviews_main.css/wp-content/plugins/twb-woocommerce-reviews/inc/css/slick.css/wp-content/plugins/twb-woocommerce-reviews/inc/js/slick.min.js/wp-content/plugins/twb-woocommerce-reviews/admin/js/admin_js.js/wp-content/plugins/twb-woocommerce-reviews/inc/js/slick.min.jstwb-woocommerce-reviews/inc/css/slick.css?ver=twb-woocommerce-reviews/inc/js/slick.min.js?ver=HTML / DOM Fingerprints
twb_wc_reviewstwb_wc_reviews_cttwb_wc_reviews_ratings_wraptwb_wcr_authortwb_wcr_datetwb_wc_reviews_slide_wraptwb_wc_reviews_wrappertwb_wc_reviews_slidetwb_wcr_layouttwb_wcr_txtcolortwb_wcr_bgcolortwb_wcr_ms_external_libtwb_wcr_ms_guttertwb_wcr_slider_effect+1 moretwb_wc_reviews_option