
Widgets for Alibaba Reviews Security & Risk Analysis
wordpress.org/plugins/widgets-for-alibaba-reviewsEmbed Alibaba reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Alibaba reviews.
Is Widgets for Alibaba Reviews Safe to Use in 2026?
Generally Safe
Score 100/100Widgets for Alibaba Reviews has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "widgets-for-alibaba-reviews" plugin version 13.2.7 exhibits a mixed security posture. While it demonstrates strong adherence to secure coding practices by properly escaping all output, utilizing prepared statements for the vast majority of its SQL queries, and including a substantial number of nonce and capability checks, there are significant areas of concern. The presence of a dangerous `unserialize` function, even if not explicitly shown to be exploitable in taint analysis, introduces a potential risk if user-controlled input is ever passed to it without proper sanitization.
More critically, the plugin has an exposed attack surface with three identified entry points, all of which lack authentication or permission checks. This includes one AJAX handler and two REST API routes. The taint analysis, while showing no critical or high severity flows, did identify one flow with an unsanitized path, which combined with the unprotected entry points, represents a notable risk. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive indicator of past security diligence. However, this does not negate the risks identified in the current version's code analysis.
Key Concerns
- Unprotected AJAX handler
- Unprotected REST API routes
- Use of unserialize function
- Flow with unsanitized path
Widgets for Alibaba Reviews Security Vulnerabilities
Widgets for Alibaba Reviews Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Widgets for Alibaba Reviews Attack Surface
AJAX Handlers 1
REST API Routes 2
WordPress Hooks 36
Maintenance & Trust
Widgets for Alibaba Reviews Maintenance & Trust
Maintenance Signals
Community Trust
Widgets for Alibaba Reviews Alternatives
WP Testimonials
testimonial-widgets
Display your Testimonials on your website fast and easily. 21 widget types, 25 widget styles available. (Free Plugin)
Widgets for Thumbtack Reviews
widgets-for-thumbtack-reviews
Embed Thumbtack reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Thumbtack reviews.
Widgets for Ebay Reviews
widgets-for-ebay-reviews
Embed Ebay reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Ebay reviews.
Widgets for Capterra Reviews
review-widgets-for-capterra
Embed Capterra reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Capterra reviews.
Widgets for SourceForge Reviews
widgets-for-sourceforge-reviews
Embed SourceForge reviews fast and easily into your WordPress site. Increase SEO, trust and sales using SourceForge reviews.
Widgets for Alibaba Reviews Developer Profile
32 plugins · 976K total installs
How We Detect Widgets for Alibaba Reviews
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/widgets-for-alibaba-reviews/assets/css/widgets-for-alibaba-reviews.css/wp-content/plugins/widgets-for-alibaba-reviews/assets/js/widgets-for-alibaba-reviews.jshttps://cdn.trustindex.io/loader.jswidgets-for-alibaba-reviews/assets/css/widgets-for-alibaba-reviews.css?ver=widgets-for-alibaba-reviews/assets/js/widgets-for-alibaba-reviews.js?ver=HTML / DOM Fingerprints
trustindex-notification-rowdata-ccm-injectedtrustindex_pm_alibabaTrustindexPlugin_alibaba/wp-json/trustindex/v1/settings