
Rich Showcase for Google Reviews Security & Risk Analysis
wordpress.org/plugins/widget-google-reviewsDisplay up to 10 Google reviews in less than a minute. Continue collecting new reviews. No limits on connected places, widgets, shortcodes and blocks.
Is Rich Showcase for Google Reviews Safe to Use in 2026?
Generally Safe
Score 90/100Rich Showcase for Google Reviews has a strong security track record. Known vulnerabilities have been patched promptly.
The "widget-google-reviews" plugin version 6.9.4.4 exhibits a mixed security posture with some concerning findings despite several good practices. While the absence of dangerous functions and the presence of nonce and capability checks are positive, the plugin has several areas of risk. A significant concern is the number of AJAX handlers (3 out of 8) that lack authentication checks, presenting a potential attack vector. The taint analysis also reveals 4 high-severity flows with unsanitized paths, indicating potential vulnerabilities that could be exploited. The plugin's vulnerability history is also a notable point of concern, with 5 known CVEs in the past, including 3 high-severity ones, suggesting a recurring pattern of exploitable weaknesses, particularly related to Cross-site Scripting, SQL Injection, CSRF, and missing authorization.
Despite these risks, the plugin does demonstrate some positive security measures. The majority of SQL queries (55%) use prepared statements, and a good portion of output (61%) is properly escaped. The low number of file operations and external HTTP requests also limits the potential for certain types of attacks. However, the combination of unprotected entry points, high-severity taint flows, and a history of significant vulnerabilities means that caution is warranted. The presence of unpatched CVEs in the past, even if none are currently listed, suggests a need for vigilance and timely updates.
Key Concerns
- AJAX handlers without authentication checks
- High severity taint flows
- Vulnerability history (high severity)
- Vulnerability history (medium severity)
- SQL queries not using prepared statements
- Output escaping not properly handled
Rich Showcase for Google Reviews Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
Rich Shortcodes for Google Reviews <= 6.8 - Unauthenticated Stored Cross-Site Scripting via Google Review
Plugin for Google Reviews <= 3.1 - Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode
Plugin for Google Reviews <= 2.2.3 - Authenticated (Subscriber+) SQL Injection
Plugin for Google Reviews <= 2.2.2 - Cross-Site Request Forgery
Plugin for Google Reviews <= 2.2.2 - Missing Authorization
Rich Showcase for Google Reviews Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Rich Showcase for Google Reviews Attack Surface
AJAX Handlers 8
Shortcodes 1
WordPress Hooks 45
Scheduled Events 1
Maintenance & Trust
Rich Showcase for Google Reviews Maintenance & Trust
Maintenance Signals
Community Trust
Rich Showcase for Google Reviews Alternatives
Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More
reviews-feed
No API key required. Display Yelp and Google reviews for any business in a clean, customizable feed on your site.
Free Customer Service Tools by OpenWidget
free-customer-service-tools-by-openwidget
Enhance engagement and trust with AI-based tools, Google Reviews, bug reporting, live chat, FAQs, and more! No coding skills required.
Free Google Reviews widget by OpenWidget
free-google-reviews-widget-by-openwidget
⭐️ Embed Google reviews into your WordPress site. Improve trust, sales & SEO of your Wordpress site with Google reviews.
Smart Showcase for Google Reviews
smart-showcase-for-google-reviews
Smart Showcase for Google Reviews is a WordPress plugin that lets businesses display Google customer reviews on their websites easily.
Revix Reviews – All-in-One Business Review Manager
revix-reviews
Revix Reviews helps you collect, import, and display reviews—including Trustpilot and Google—with more platforms coming soon.
Rich Showcase for Google Reviews Developer Profile
5 plugins · 114K total installs
How We Detect Rich Showcase for Google Reviews
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/widget-google-reviews/css/admin-main.css/wp-content/plugins/widget-google-reviews/css/public-main.css/wp-content/plugins/widget-google-reviews/css/public-badge.css/wp-content/plugins/widget-google-reviews/js/admin-main.js/wp-content/plugins/widget-google-reviews/js/admin-builder.js/wp-content/plugins/widget-google-reviews/js/admin-apexcharts.js/wp-content/plugins/widget-google-reviews/js/public-main.jshttps://cdn.reviewsplugin.com/assets/js/time.jshttps://cdn.reviewsplugin.com/assets/js/utils.jshttps://cdn.reviewsplugin.com/assets/js/column.jshttps://cdn.reviewsplugin.com/assets/js/common.jshttps://cdn.reviewsplugin.com/assets/js/lightbox.jshttps://cdn.reviewsplugin.com/assets/js/toast.js+7 morewidget-google-reviews/css/admin-main.css?ver=widget-google-reviews/css/public-main.css?ver=widget-google-reviews/css/public-badge.css?ver=widget-google-reviews/js/admin-main.js?ver=widget-google-reviews/js/admin-builder.js?ver=widget-google-reviews/js/admin-apexcharts.js?ver=widget-google-reviews/js/public-main.js?ver=HTML / DOM Fingerprints
grw-reviewsgrw-badgegrw-containerdata-grw-iddata-grw-reviews-iddata-grw-typedata-grw-location-idgrw_builder_params[grw-reviews-gallery[grw-reviews-slider[grw-reviews-badge