
Ultimate Reviews Security & Risk Analysis
wordpress.org/plugins/ultimate-reviewsBest review plugin. Let visitors submit reviews and display them via shortcode or widget. Replace WooCommerce reviews and ratings. Require login, etc.
Is Ultimate Reviews Safe to Use in 2026?
Generally Safe
Score 89/100Ultimate Reviews has a strong security track record. Known vulnerabilities have been patched promptly.
The 'ultimate-reviews' plugin v3.2.17 presents a mixed security profile. On the positive side, the static analysis indicates good coding practices with all AJAX handlers and REST API routes appearing to have authentication checks. SQL queries are exclusively using prepared statements, and a high percentage of output is properly escaped, which are strong indicators of security awareness. The presence of numerous nonce and capability checks further reinforces this positive aspect.
However, several concerns warrant attention. The taint analysis revealed two flows with unsanitized paths, which could potentially lead to issues if not handled carefully, though the critical and high severity counts are zero. More significantly, the plugin has a history of 5 known CVEs, including one critical and four medium. While no CVEs are currently unpatched, the nature of past vulnerabilities (Authorization Bypass, Cross-Site Scripting, Deserialization) suggests a pattern of complex security flaws that require vigilant patching. The last vulnerability being in 2026 is also unusual and could indicate outdated historical data or a future unpatched issue if it's not a typo.
Overall, the current version of the plugin demonstrates improved security practices in its code compared to its past, evident by the absence of immediately exploitable issues in the static analysis. Nevertheless, the historical vulnerability data, particularly the critical past vulnerability and the types of issues encountered, suggest that users should remain cautious and prioritize timely updates for any future releases to mitigate risks associated with previously exploited weaknesses.
Key Concerns
- Historical critical CVE present
- Historical medium CVEs present (4)
- Taint flows with unsanitized paths (2)
- Past vulnerability types are severe (Auth Bypass, XSS, Deserialization)
Ultimate Reviews Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
Ultimate Reviews <= 3.2.16 - Unauthenticated Insecure Direct Object Reference
Ultimate Reviews <= 3.2.14 - Reflected Cross-Site Scripting
Ultimate Reviews <= 3.2.8 - Unauthenticated stored Cross-Site Scripting via reviews
Ultimate Reviews <= 3.0.15 - Authenticated Stored Cross-Site Scripting
Ultimate Reviews < 2.1.33 - PHP Object Injection
Ultimate Reviews Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Ultimate Reviews Attack Surface
AJAX Handlers 20
Shortcodes 5
WordPress Hooks 73
Maintenance & Trust
Ultimate Reviews Maintenance & Trust
Maintenance Signals
Community Trust
Ultimate Reviews Alternatives
Builder for WooCommerce product reviews shortcodes – ReviewShort
woo-product-reviews-shortcode
Show WooCommerce customer feedback anywhere with WooCommerce reviews shortcodes, beautifully and ...
Site Reviews
site-reviews
Site Reviews is a complete review management solution that integrates with WooCommerce and SureCart and works similarly to reviews on Amazon, Tripadvi …
Photo Reviews for WooCommerce
woo-photo-reviews
Let customers attach photos to reviews, enhanced with filterable grids and overall ratings. Auto-send review reminders and coupon emails
ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema
reviewx
Drive woocommerce business growth with social proof: gather product reviews with multicriteria ratings, auto-reminder emails, discounts, and more.
Yotpo: Product & Photo Reviews for WooCommerce
yotpo-social-reviews-for-woocommerce
Collect product reviews, photo reviews, site reviews & ratings
Ultimate Reviews Developer Profile
21 plugins · 66K total installs
How We Detect Ultimate Reviews
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ultimate-reviews/assets/css/ewd-urp-admin.css/wp-content/plugins/ultimate-reviews/assets/css/ewd-urp-helper-install-notice.css/wp-content/plugins/ultimate-reviews/assets/js/ewd-urp-admin.js/wp-content/plugins/ultimate-reviews/assets/js/ewd-urp-helper-install-notice.js/wp-content/plugins/ultimate-reviews/assets/js/ewd-urp-front-end.js/wp-content/plugins/ultimate-reviews/assets/js/ewd-urp-helper-install-notice.js/wp-content/plugins/ultimate-reviews/assets/js/ewd-urp-admin.js/wp-content/plugins/ultimate-reviews/assets/js/ewd-urp-front-end.jsewd-urp-helper-install-noticeewd-urp-helper-install-notice.css?ver=ewd-urp-admin.css?ver=ewd-urp-admin.js?ver=ewd-urp-front-end.js?ver=HTML / DOM Fingerprints
ewd-urp-review-form-wrapperewd-urp-review-display-wrapperewd-urp-review-containerewd-urp-no-reviews-messageewd-urp-review-headerewd-urp-review-titleewd-urp-review-author-dateewd-urp-review-rating+2 more<!-- Check if the user is logged in --><!-- Display the review form --><!-- Display the reviews --><!-- If reviews are empty -->+7 moredata-product-iddata-review-iddata-ratingdata-form-nonceewd_urp_php_js_dataewd_urp_helper_notice/wp-json/ewd-urp/v1/submit_review/wp-json/ewd-urp/v1/get_reviews[ultimate-reviews][review-form][recent-reviews][product-reviews]