
WidgetPack Review System Security & Risk Analysis
wordpress.org/plugins/widgetpack-review-systemThe WidgetPack Review System replaces default WordPress comments with social review service to get more reviews mean more traffic and more sales.
Is WidgetPack Review System Safe to Use in 2026?
Generally Safe
Score 85/100WidgetPack Review System has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "widgetpack-review-system" v1.2 plugin exhibits a generally positive security posture, with no recorded vulnerabilities or CVEs, indicating a history of secure development. The code analysis reveals a strong adherence to secure coding practices, particularly in its use of prepared statements for all SQL queries and the presence of nonce and capability checks. This suggests a conscious effort by the developers to protect against common database injection and unauthorized access vulnerabilities.
However, certain aspects warrant attention. The presence of dangerous functions like 'ini_set' and 'set_time_limit' could be a concern if not handled with extreme care, as they can be misused for privilege escalation or denial-of-service attacks. Furthermore, the taint analysis identified two flows with unsanitized paths, which, while not classified as critical or high severity in this assessment, represent potential vectors for path traversal or file inclusion vulnerabilities. The low percentage of properly escaped output (17%) is a significant weakness, leaving the plugin susceptible to cross-site scripting (XSS) attacks through user-generated content displayed on the frontend.
In conclusion, while the plugin benefits from a clean vulnerability history and good practices in database and authentication handling, the low output escaping rate and the presence of unsanitized paths are notable weaknesses. Developers should prioritize addressing the output escaping issues to mitigate XSS risks and thoroughly review the identified taint flows to ensure no exploitable path traversal vulnerabilities exist. The use of dangerous functions should also be carefully scrutinized to confirm they are not exposed to user input in an unsafe manner.
Key Concerns
- Low output escaping rate (17%)
- Taint analysis shows unsanitized paths (2 flows)
- Presence of dangerous functions (ini_set, set_time_limit)
WidgetPack Review System Security Vulnerabilities
WidgetPack Review System Release Timeline
WidgetPack Review System Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
WidgetPack Review System Attack Surface
WordPress Hooks 12
Scheduled Events 2
Maintenance & Trust
WidgetPack Review System Maintenance & Trust
Maintenance Signals
Community Trust
WidgetPack Review System Alternatives
Stars Rating
stars-rating
A complete review plugin — star ratings, photo uploads, likes & dislikes, and Google rich snippets, all from one place.
REVIEWS.io for WooCommerce
reviewscouk-for-woocommerce
REVIEWS.io, helps eCommerce merchants to collect & display verified product and company reviews. A Google Licensed partner.
Integration for BazaarVoice
integration-for-baazarvoice
An plugin that will integrate with the Bazaarvoice rating system.
weeComments – Shop & Products Reviews
weecomments
Genera confianza en tu tienda online y aumenta las ventas con weecomments. http://weecomments.com Muestra un widget de opiniones de la tienda online, …
Show Product Reviews and Ratings
show-product-review-and-ratings
With this plugin you will rank much higher on Google!
WidgetPack Review System Developer Profile
6 plugins · 114K total installs
How We Detect WidgetPack Review System
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/widgetpack-review-system/static/js/admin.js/wp-content/plugins/widgetpack-review-system/static/js/count.jshttps://embed.widgetpack.com/widget.jswidgetpack-review-system/static/js/admin.js?ver=widgetpack-review-system/static/js/count.js?ver=HTML / DOM Fingerprints
wprev-postiddata-wpac-chanadminVarscountVarswpac_initWIDGETPACK_LOADED