
Widgets for Zillow Reviews Security & Risk Analysis
wordpress.org/plugins/widgets-for-zillow-reviewsEmbed Zillow reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Zillow reviews.
Is Widgets for Zillow Reviews Safe to Use in 2026?
Generally Safe
Score 100/100Widgets for Zillow Reviews has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "widgets-for-zillow-reviews" plugin exhibits a mixed security posture. On the positive side, it demonstrates excellent practices in output escaping and SQL query handling, with 100% of outputs properly escaped and 98% of SQL queries using prepared statements. The plugin also has a clean vulnerability history with no recorded CVEs, suggesting a potentially robust development process in the past.
However, significant concerns arise from the attack surface analysis. The plugin exposes three distinct entry points (one AJAX handler and two REST API routes) without any authentication or permission checks. This lack of authorization is a critical security weakness that could allow unauthenticated users to interact with sensitive functionalities. Furthermore, the presence of the `unserialize` function, while not directly flagged as a critical taint flow in this analysis, is a known risk if not handled with extreme care, especially when dealing with external input.
While the plugin has no current or historical CVEs, the absence of authentication checks on multiple entry points presents a tangible and immediate risk. The developer should prioritize implementing proper nonce checks and capability checks on all AJAX handlers and permission callbacks on REST API routes to mitigate this significant exposure. The `unserialize` function should also be scrutinized for potential vulnerabilities if it's ever exposed to user-controlled data.
Key Concerns
- Unprotected AJAX handler
- Unprotected REST API routes
- Presence of unserialize function
Widgets for Zillow Reviews Security Vulnerabilities
Widgets for Zillow Reviews Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Widgets for Zillow Reviews Attack Surface
AJAX Handlers 1
REST API Routes 2
WordPress Hooks 36
Maintenance & Trust
Widgets for Zillow Reviews Maintenance & Trust
Maintenance Signals
Community Trust
Widgets for Zillow Reviews Alternatives
WP Testimonials
testimonial-widgets
Display your Testimonials on your website fast and easily. 21 widget types, 25 widget styles available. (Free Plugin)
Widgets for Amazon Reviews
review-widgets-for-amazon
Embed Amazon reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Amazon reviews.
Widgets for Thumbtack Reviews
widgets-for-thumbtack-reviews
Embed Thumbtack reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Thumbtack reviews.
Widgets for Ebay Reviews
widgets-for-ebay-reviews
Embed Ebay reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Ebay reviews.
Widgets for Capterra Reviews
review-widgets-for-capterra
Embed Capterra reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Capterra reviews.
Widgets for Zillow Reviews Developer Profile
32 plugins · 976K total installs
How We Detect Widgets for Zillow Reviews
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/widgets-for-zillow-reviews/css/widgets-for-zillow-reviews.css/wp-content/plugins/widgets-for-zillow-reviews/js/widgets-for-zillow-reviews.js/wp-content/plugins/widgets-for-zillow-reviews/include/admin/css/trustindex-admin.css/wp-content/plugins/widgets-for-zillow-reviews/include/admin/js/trustindex-admin.jshttps://cdn.trustindex.io/loader.jswidgets-for-zillow-reviews/css/widgets-for-zillow-reviews.css?ver=widgets-for-zillow-reviews/js/widgets-for-zillow-reviews.js?ver=widgets-for-zillow-reviews/include/admin/css/trustindex-admin.css?ver=widgets-for-zillow-reviews/include/admin/js/trustindex-admin.js?ver=HTML / DOM Fingerprints
trustindex-notification-rowti-close-notificationti-hide-notificationdata-ccm-injected="1"trustindex_pm_zillowTrustindexPlugin_zillowti_woocommerce_notice/wp-json/widgets-for-zillow-reviews/v1/settings/wp-json/widgets-for-zillow-reviews/v1/feed/wp-json/widgets-for-zillow-reviews/v1/reviews/wp-json/widgets-for-zillow-reviews/v1/save_reviews