TWB Woocommerce Reviews Security & Risk Analysis

wordpress.org/plugins/twb-woocommerce-reviews

Display Woocommerce reviews anywhere using shortcode. Specify reviews using product ID. Now supports Masonry layout.

600 active installs v1.7.8 PHP + WP 4.6+ Updated Feb 25, 2025
e-commerceproduct-reviewreviewstestimonialswoocommerce-review
91
A · Safe
CVEs total2
Unpatched0
Last CVEMar 27, 2025
Safety Verdict

Is TWB Woocommerce Reviews Safe to Use in 2026?

Generally Safe

Score 91/100

TWB Woocommerce Reviews has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Mar 27, 2025Updated 1yr ago
Risk Assessment

The twb-woocommerce-reviews plugin v1.7.8 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by utilizing prepared statements for all SQL queries and performing nonce checks. There are no identified critical or high-severity taint flows, and the static analysis reveals a limited attack surface with no direct unprotected entry points like unprotected AJAX handlers or REST API routes. File operations and external HTTP requests are also absent, reducing common attack vectors.

However, several areas raise concerns. The significant percentage of improperly escaped output (30%) indicates a potential for Cross-Site Scripting (XSS) vulnerabilities, especially given that XSS is listed as a common vulnerability type in its history. While the plugin has no currently unpatched CVEs, its history of two medium-severity CVEs, including CSRF and XSS, suggests past weaknesses that could resurface if not diligently addressed. The absence of capability checks on the identified shortcode also means that any actions performed by this shortcode might not be properly authorized, potentially leading to privilege escalation or unauthorized operations if the shortcode's functionality is sensitive.

In conclusion, while the plugin has made strides in secure coding practices like prepared statements and nonce checks, the prevalent unescaped output and past vulnerability history warrant careful consideration. The lack of capability checks on its sole entry point is a notable weakness. Further investigation into the specific unescaped output instances and the functionality of the shortcode is recommended to fully mitigate potential risks.

Key Concerns

  • Significant unescaped output
  • Past medium severity CVEs (2 total)
  • Missing capability checks on shortcode
Vulnerabilities
2

TWB Woocommerce Reviews Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2025-30801medium · 4.3Cross-Site Request Forgery (CSRF)

TWB Woocommerce Reviews <= 1.7.7 - Cross-Site Request Forgery

Mar 27, 2025 Patched in 1.7.8 (7d)
CVE-2023-47653medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

TWB Woocommerce Reviews <= 1.7.5 - Authenticated (Administrator+) Stored Cross-Site Scripting

Nov 7, 2023 Patched in 1.7.6 (347d)
Code Analysis
Analyzed Mar 16, 2026

TWB Woocommerce Reviews Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
40
95 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

70% escaped135 total outputs
Attack Surface

TWB Woocommerce Reviews Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[twb_wc_reviews] twb-output.php:5
WordPress Hooks 7
actionadmin_menuadmin\options.php:3
actionadmin_initadmin\options.php:4
actionadmin_noticestwb-wc-reviews.php:37
actionadmin_enqueue_scriptstwb-wc-reviews.php:48
actionwp_enqueue_scriptstwb-wc-reviews.php:59
actionwp_headtwb_wc_reviews_functions.php:8
actionwp_footertwb_wc_reviews_functions.php:56
Maintenance & Trust

TWB Woocommerce Reviews Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedFeb 25, 2025
PHP min version
Downloads15K

Community Trust

Rating96/100
Number of ratings26
Active installs600
Developer Profile

TWB Woocommerce Reviews Developer Profile

Abu Bakar

3 plugins · 700 total installs

73
trust score
Avg Security Score
92/100
Avg Patch Time
118 days
View full developer profile
Detection Fingerprints

How We Detect TWB Woocommerce Reviews

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/twb-woocommerce-reviews/admin/js/admin_js.js/wp-content/plugins/twb-woocommerce-reviews/inc/css/twb_wc_reviews_main.css/wp-content/plugins/twb-woocommerce-reviews/inc/css/slick.css/wp-content/plugins/twb-woocommerce-reviews/inc/js/slick.min.js
Script Paths
/wp-content/plugins/twb-woocommerce-reviews/admin/js/admin_js.js/wp-content/plugins/twb-woocommerce-reviews/inc/js/slick.min.js
Version Parameters
twb-woocommerce-reviews/inc/css/slick.css?ver=twb-woocommerce-reviews/inc/js/slick.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
twb_wc_reviewstwb_wc_reviews_cttwb_wc_reviews_ratings_wraptwb_wcr_authortwb_wcr_datetwb_wc_reviews_slide_wraptwb_wc_reviews_wrappertwb_wc_reviews_slide
Data Attributes
twb_wcr_layouttwb_wcr_txtcolortwb_wcr_bgcolortwb_wcr_ms_external_libtwb_wcr_ms_guttertwb_wcr_slider_effect+1 more
JS Globals
twb_wc_reviews_option
FAQ

Frequently Asked Questions about TWB Woocommerce Reviews