
weeComments – Shop & Products Reviews Security & Risk Analysis
wordpress.org/plugins/weecommentsGenera confianza en tu tienda online y aumenta las ventas con weecomments. http://weecomments.com Muestra un widget de opiniones de la tienda online, …
Is weeComments – Shop & Products Reviews Safe to Use in 2026?
Generally Safe
Score 85/100weeComments – Shop & Products Reviews has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The weecomments plugin v3.1.4 exhibits a mixed security posture. On the positive side, it demonstrates good practices in its database interactions, with 100% of its SQL queries utilizing prepared statements, and it has no known unpatched vulnerabilities. The attack surface appears limited, with no AJAX handlers or REST API routes exposed without proper authentication or permission checks. However, significant concerns arise from the static analysis. The plugin fails to implement any nonce checks or capability checks, which are fundamental for securing WordPress actions. Furthermore, a concerning 0% of its output is properly escaped, creating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The use of the `create_function` dangerous function is also a red flag, as it can lead to code injection vulnerabilities if not handled with extreme care and sanitization. The absence of any recorded vulnerabilities in its history might suggest a lack of rigorous security auditing or that potential issues have gone unnoticed or unreported. While the plugin's database queries and lack of known CVEs are strengths, the critical findings of missing nonce/capability checks and widespread unescaped output, coupled with the use of a dangerous function, present a substantial security risk that requires immediate attention.
Key Concerns
- Missing Nonce Checks
- Missing Capability Checks
- Unescaped Output (31 total)
- Use of Dangerous Function (create_function)
weeComments – Shop & Products Reviews Security Vulnerabilities
weeComments – Shop & Products Reviews Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
weeComments – Shop & Products Reviews Attack Surface
Shortcodes 3
WordPress Hooks 10
Maintenance & Trust
weeComments – Shop & Products Reviews Maintenance & Trust
Maintenance Signals
Community Trust
weeComments – Shop & Products Reviews Alternatives
Revi.io – Customer & Products Reviews
revi-io-customer-and-product-reviews
Automatically collect and display verified product and store reviews to build trust, and stand out on Google Shopping and Search
Site Reviews
site-reviews
Site Reviews is a complete review management solution that integrates with WooCommerce and SureCart and works similarly to reviews on Amazon, Tripadvi …
Gutena Star Ratings
gutena-star-ratings
Gutena Star Ratings is a great block that lets you add star rating to client testimonials and reviews. Not only the star rating will tell customers ho …
WPSSO Ratings and Reviews
wpsso-ratings-and-reviews
Adds Ratings and Reviews Features to the WordPress Comments System.
Author Product Review
author-product-review
This plugin allow author to add Schema.org markup options for product reviews.
weeComments – Shop & Products Reviews Developer Profile
1 plugin · 10 total installs
How We Detect weeComments – Shop & Products Reviews
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/weecomments/css/back.css/wp-content/plugins/weecomments/css/style.csshttps://weecomments.com/js/widget-product-wordpress.jsHTML / DOM Fingerprints
weecommentsid="wee_prod"lol/wp-json/weecomments/