Widgets for Thumbtack Reviews Security & Risk Analysis
wordpress.org/plugins/widgets-for-thumbtack-reviewsEmbed Thumbtack reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Thumbtack reviews.
Is Widgets for Thumbtack Reviews Safe to Use in 2026?
Generally Safe
Score 100/100Widgets for Thumbtack Reviews has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "widgets-for-thumbtack-reviews" v13.2.7 exhibits a mixed security posture. On the positive side, the code demonstrates strong adherence to secure coding practices with 100% of outputs being properly escaped and a very high percentage of SQL queries using prepared statements. The absence of any recorded vulnerabilities in its history is also a positive indicator, suggesting a generally well-maintained codebase. However, there are significant concerns regarding the attack surface. All identified entry points, including AJAX handlers and REST API routes, lack authentication checks or permission callbacks, creating a direct path for potential exploitation.
Specifically, the analysis reveals one AJAX handler and two REST API routes that are completely unprotected. This means any unauthenticated user could potentially interact with these endpoints. While the taint analysis did not reveal any critical or high severity flows, the presence of one flow with unsanitized paths warrants attention, even if its severity is not yet classified. The use of the `unserialize` function, although potentially necessary, is inherently risky and requires careful input validation, especially when combined with unprotected entry points. The plugin's overall security is compromised by these unprotected entry points, which represent a significant risk despite other good coding practices.
In conclusion, while the plugin has a clean vulnerability history and generally good internal coding practices for SQL and output handling, the exposed attack surface is its Achilles' heel. The lack of authentication on all identified entry points presents a clear and immediate risk. Addressing these unprotected entry points should be the highest priority to improve the plugin's security posture.
Key Concerns
- Unprotected AJAX handlers
- Unprotected REST API routes
- Flow with unsanitized paths
- Dangerous function unserialize
Widgets for Thumbtack Reviews Security Vulnerabilities
Widgets for Thumbtack Reviews Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Widgets for Thumbtack Reviews Attack Surface
AJAX Handlers 1
REST API Routes 2
WordPress Hooks 36
Maintenance & Trust
Widgets for Thumbtack Reviews Maintenance & Trust
Maintenance Signals
Community Trust
Widgets for Thumbtack Reviews Alternatives
WP Testimonials
testimonial-widgets
Display your Testimonials on your website fast and easily. 21 widget types, 25 widget styles available. (Free Plugin)
Widgets for Ebay Reviews
widgets-for-ebay-reviews
Embed Ebay reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Ebay reviews.
Widgets for Capterra Reviews
review-widgets-for-capterra
Embed Capterra reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Capterra reviews.
Widgets for Alibaba Reviews
widgets-for-alibaba-reviews
Embed Alibaba reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Alibaba reviews.
Widgets for SourceForge Reviews
widgets-for-sourceforge-reviews
Embed SourceForge reviews fast and easily into your WordPress site. Increase SEO, trust and sales using SourceForge reviews.
Widgets for Thumbtack Reviews Developer Profile
32 plugins · 976K total installs
How We Detect Widgets for Thumbtack Reviews
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/widgets-for-thumbtack-reviews/include/elementor-widgets.phphttps://cdn.trustindex.io/loader.jswidgets-for-thumbtack-reviews/style.css?ver=widgets-for-thumbtack-reviews/script.js?ver=HTML / DOM Fingerprints
trustindex-notification-rowti-close-notificationti-hide-notificationdata-ccm-injectedti_woocommerce_noticeTrustindexPlugin_thumbtack/wp-json/trustindex-api/v1/widgets/get