
Widgets for SourceForge Reviews Security & Risk Analysis
wordpress.org/plugins/widgets-for-sourceforge-reviewsEmbed SourceForge reviews fast and easily into your WordPress site. Increase SEO, trust and sales using SourceForge reviews.
Is Widgets for SourceForge Reviews Safe to Use in 2026?
Generally Safe
Score 100/100Widgets for SourceForge Reviews has a strong security track record. Known vulnerabilities have been patched promptly.
The "widgets-for-sourceforge-reviews" plugin, version 13.2.7, exhibits a mixed security posture. While it demonstrates strong adherence to output escaping and a high percentage of prepared SQL statements, significant security concerns arise from its unprotected entry points. The presence of AJAX handlers and REST API routes without proper authentication or permission checks creates a substantial attack surface, making it vulnerable to unauthorized access and potential manipulation.
The code analysis reveals a single instance of `unserialize`, a function known to be risky if used with untrusted input. While taint analysis did not reveal critical or high severity unsanitized paths, the existence of a flow with an unsanitized path is a notable risk. The plugin's vulnerability history, although currently clear of unpatched CVEs, includes a past medium-severity vulnerability related to unrestricted file uploads, suggesting a prior pattern of security weaknesses that requires ongoing vigilance.
In conclusion, the plugin benefits from good output sanitization and SQL query practices. However, the critical weakness lies in its exposed entry points without adequate security controls. This, coupled with the past vulnerability history, necessitates careful consideration of the risks associated with deploying this plugin. Future development should prioritize securing all entry points and thoroughly auditing the use of potentially dangerous functions like `unserialize`.
Key Concerns
- Unprotected AJAX handlers
- Unprotected REST API routes
- Dangerous function (unserialize)
- Flow with unsanitized paths
- Past medium vulnerability (unrestricted upload)
Widgets for SourceForge Reviews Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Multiple Plugins by Trustindex.io <= (Various Versions)- Authenticated (Editor+) Arbitrary File Upload
Widgets for SourceForge Reviews Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Widgets for SourceForge Reviews Attack Surface
AJAX Handlers 1
REST API Routes 2
WordPress Hooks 36
Maintenance & Trust
Widgets for SourceForge Reviews Maintenance & Trust
Maintenance Signals
Community Trust
Widgets for SourceForge Reviews Alternatives
WP Testimonials
testimonial-widgets
Display your Testimonials on your website fast and easily. 21 widget types, 25 widget styles available. (Free Plugin)
Widgets for Thumbtack Reviews
widgets-for-thumbtack-reviews
Embed Thumbtack reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Thumbtack reviews.
Widgets for Ebay Reviews
widgets-for-ebay-reviews
Embed Ebay reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Ebay reviews.
Widgets for Capterra Reviews
review-widgets-for-capterra
Embed Capterra reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Capterra reviews.
Widgets for Alibaba Reviews
widgets-for-alibaba-reviews
Embed Alibaba reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Alibaba reviews.
Widgets for SourceForge Reviews Developer Profile
32 plugins · 976K total installs
How We Detect Widgets for SourceForge Reviews
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/widgets-for-sourceforge-reviews/assets/css/trustindex-common.css/wp-content/plugins/widgets-for-sourceforge-reviews/assets/js/trustindex-common.js/wp-content/plugins/widgets-for-sourceforge-reviews/assets/js/trustindex-public.js/wp-content/plugins/widgets-for-sourceforge-reviews/assets/css/trustindex-public.css/wp-content/plugins/widgets-for-sourceforge-reviews/assets/js/trustindex-admin.js/wp-content/plugins/widgets-for-sourceforge-reviews/assets/css/trustindex-admin.csshttps://cdn.trustindex.io/loader.js/wp-content/plugins/widgets-for-sourceforge-reviews/assets/css/trustindex-common.css?ver=/wp-content/plugins/widgets-for-sourceforge-reviews/assets/js/trustindex-common.js?ver=/wp-content/plugins/widgets-for-sourceforge-reviews/assets/js/trustindex-public.js?ver=/wp-content/plugins/widgets-for-sourceforge-reviews/assets/css/trustindex-public.css?ver=/wp-content/plugins/widgets-for-sourceforge-reviews/assets/js/trustindex-admin.js?ver=/wp-content/plugins/widgets-for-sourceforge-reviews/assets/css/trustindex-admin.css?ver=HTML / DOM Fingerprints
ti-notification-rowtrustindex-notification-rowti-site-datadata-ccm-injected="1"TrustindexPlugin_sourceForge/wp-json/widgets-for-sourceforge-reviews/v1/settings/wp-json/widgets-for-sourceforge-reviews/v1/reviews[widget_reviews][widget_review_form]