
Untappd Ratings for WooCommerce Security & Risk Analysis
wordpress.org/plugins/untappd-ratings-for-woocommerceEverything you need to show Untappd ratings on WooCommerce stores.
Is Untappd Ratings for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Untappd Ratings for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "untappd-ratings-for-woocommerce" plugin v1.0.9 exhibits a strong security posture based on the provided static analysis. The plugin effectively utilizes prepared statements for all SQL queries, has a high rate of properly escaped output, and implements nonce and capability checks on its entry points. The absence of dangerous functions, file operations, and known vulnerabilities in its history are positive indicators. The plugin also appears to be actively maintained and secure, with no recorded past vulnerabilities.
While the overall security is good, there are minor areas that could be improved. The presence of external HTTP requests, although not inherently insecure, represents a potential attack vector if the external service is compromised or if the data sent or received is not handled securely. The attack surface, though protected, is composed of several AJAX handlers which, if any future updates introduce vulnerabilities, could be entry points. The taint analysis showing zero flows is reassuring, suggesting no immediate data sanitization issues were detected.
In conclusion, this plugin appears to be well-secured with robust coding practices. The strengths lie in its handling of sensitive operations like database queries and output, along with a clean vulnerability history. The minor weaknesses relate to external dependencies and the breadth of the protected attack surface, which are common in many WordPress plugins. Overall, the risk is assessed as low.
Key Concerns
- External HTTP requests detected
- Multiple AJAX entry points
Untappd Ratings for WooCommerce Security Vulnerabilities
Untappd Ratings for WooCommerce Release Timeline
Untappd Ratings for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Untappd Ratings for WooCommerce Attack Surface
AJAX Handlers 5
Shortcodes 1
WordPress Hooks 24
Maintenance & Trust
Untappd Ratings for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Untappd Ratings for WooCommerce Alternatives
WPSSO Ratings and Reviews
wpsso-ratings-and-reviews
Adds Ratings and Reviews Features to the WordPress Comments System.
Breview – Order reviews for WooCommerce
breview
Collect reviews from order page after completion and display them on product pages on your WooCommerce store.
Custom Reviews Woocommerce
custom-reviews-and-ratings-for-woocommerce
You can add custom reviews and ratings to your woocommerce products from wp admin dashboard.
Kiyoh Reviews
kiyoh-reviews
Integrate Kiyoh reviews with your WooCommerce store. Automatically send review invitations and display product reviews.
Reco For Woocommerce
reco-for-woocommerce
Sync WooCommerce orders with external product review service Reco.se and display high-quality rating widgets across your shop.
Untappd Ratings for WooCommerce Developer Profile
2 plugins · 210 total installs
How We Detect Untappd Ratings for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/untappd-ratings-for-woocommerce/assets/css/urwc-map.css/wp-content/plugins/untappd-ratings-for-woocommerce/assets/js/urwc-map.js/wp-content/plugins/untappd-ratings-for-woocommerce/addons/brewery-activity-feed/js/urwc-brewery-activity-feed-map.js/wp-content/plugins/untappd-ratings-for-woocommerce/assets/js/urwc-map.jsuntappd-ratings-for-woocommerce/assets/css/urwc-map.css?ver=untappd-ratings-for-woocommerce/addons/brewery-activity-feed/js/urwc-brewery-activity-feed-map.js?ver=untappd-ratings-for-woocommerce/assets/js/urwc-map.js?ver=HTML / DOM Fingerprints
urwc-mapurwc-map-containerurwc-map-loading-overlayurwc-map-loading-contentdata-api_keydata-brewery_iddata-lat_lngdata-max_checkinsdata-classdata-container_class+11 moreurwc_map_data/wp-json/urwc/v1/checkins[urwc_untappd_map