
Website Rating Security & Risk Analysis
wordpress.org/plugins/website-ratingEasy way to rate the overall website and display the rating values with colorful graph.
Is Website Rating Safe to Use in 2026?
Generally Safe
Score 85/100Website Rating has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'website-rating' plugin version 1.3 exhibits a seemingly strong security posture based on the provided static analysis. There are no detected dangerous functions, file operations, external HTTP requests, or SQL injection vulnerabilities due to prepared statements. The absence of known CVEs and a clean vulnerability history further contribute to this positive outlook. However, a significant concern arises from the low percentage of properly escaped output (26%). This indicates that a substantial portion of user-facing content might be susceptible to Cross-Site Scripting (XSS) attacks, especially if the plugin processes and displays user-generated content or data from external sources without adequate sanitization.
The plugin's attack surface is reported as zero entry points, which is generally positive, but this needs to be viewed in conjunction with the output escaping issue. If there are indeed no AJAX handlers, REST API routes, shortcodes, or cron events, it would explain the lack of formal capability and nonce checks. Nevertheless, the lack of explicit capability checks on potential, even if currently undetected, entry points is a weakness that could become a risk if functionality changes or is added in the future. The current vulnerability history suggests diligent maintenance or a lack of past exploitation, but it's crucial to remember that a clean history doesn't guarantee future security.
In conclusion, while the plugin has excellent foundational security practices regarding SQL, dangerous functions, and its attack surface, the pervasive lack of output escaping is a critical weakness that introduces a significant XSS risk. The absence of capability checks, while currently seemingly benign due to the limited attack surface, is a potential area for future exploitation if not addressed proactively. It is recommended to prioritize addressing the output escaping issues to mitigate XSS vulnerabilities.
Key Concerns
- Low percentage of properly escaped output
- No capability checks on entry points
Website Rating Security Vulnerabilities
Website Rating Release Timeline
Website Rating Code Analysis
Output Escaping
Website Rating Attack Surface
WordPress Hooks 6
Maintenance & Trust
Website Rating Maintenance & Trust
Maintenance Signals
Community Trust
Website Rating Alternatives
Ridplace Rating Stars
ridplace-ratingstars
Add rating stars on your website and in google search results
Crowdsignal Dashboard – Polls, Surveys & more
polldaddy
Manage your Crowdsignal polls, surveys, quizzes, and ratings directly from the WordPress dashboard.
Strong Testimonials
strong-testimonials
An easy-to-use testimonial plugin to collect and show customer feedback in WordPress
kk Star Ratings – Rate Post & Collect User Feedbacks
kk-star-ratings
kk Star Ratings allows blog visitors to involve and interact more effectively with your website by rating posts.
WP Ultimate Review
wp-ultimate-review
WP Ultimate Review is the perfect plugin to collect & display customers' feedback effortlessly on products, services, & content in WordPress.
Website Rating Developer Profile
21 plugins · 4K total installs
How We Detect Website Rating
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
web-rateratttingratingname="buffercode_website_rating_cutom_title"name="buffercode_website_rating_options"name="buffercode_website_rating_submit"setCookie