
Combine Reviews for WooCommerce Security & Risk Analysis
wordpress.org/plugins/woo-combined-reviewsThe simple plugin that combine reviews of all products on your WooCommerce website.
Is Combine Reviews for WooCommerce Safe to Use in 2026?
Generally Safe
Score 85/100Combine Reviews for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "woo-combined-reviews" v1.0.0 plugin exhibits a generally good security posture, with no known vulnerabilities in its history and a clean taint analysis. The static analysis also reveals no dangerous functions, file operations, or external HTTP requests. This indicates that the development team has followed some good security practices. However, there are areas for improvement. The plugin performs one SQL query that does not use prepared statements, which poses a risk of SQL injection if the input to this query is not properly sanitized before reaching the database. Additionally, while the plugin has one nonce check and one capability check, the overall attack surface appears minimal (0 entry points), suggesting this might be less of an immediate concern but still a practice that could be strengthened. The percentage of properly escaped output is also not 100%, which could lead to cross-site scripting (XSS) vulnerabilities if untrusted data is displayed without adequate sanitization.
In conclusion, while the plugin is free of known historical vulnerabilities and has passed a static analysis with no critical or high-severity issues, the presence of raw SQL queries and imperfect output escaping present tangible, albeit potentially manageable, risks. The lack of a larger attack surface is a positive sign. Continued vigilance and adherence to secure coding practices, particularly around database interactions and output rendering, are recommended to maintain a strong security posture.
Key Concerns
- Raw SQL query without prepared statements
- Imperfect output escaping
Combine Reviews for WooCommerce Security Vulnerabilities
Combine Reviews for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Combine Reviews for WooCommerce Attack Surface
WordPress Hooks 6
Maintenance & Trust
Combine Reviews for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Combine Reviews for WooCommerce Alternatives
Photo Reviews for WooCommerce
woo-photo-reviews
Let customers attach photos to reviews, enhanced with filterable grids and overall ratings. Auto-send review reminders and coupon emails
ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema
reviewx
Drive woocommerce business growth with social proof: gather product reviews with multicriteria ratings, auto-reminder emails, discounts, and more.
Faview – Virtual Reviews for WooCommerce
woo-virtual-reviews
Faview - Virtual Reviews for WooCommerce generates and displays canned reviews to boost your customer engagement.
Customer Reviews Collector for WooCommerce
customer-reviews-collector-for-woocommerce
Collect reviews on Google, Facebook, Yelp, Trustindex and other platforms automatically, with the help of our system.
Ryviu – Product Reviews for WooCommerce
ryviu
Install Ryviu quickly and easily into your WordPress site. Boost eco-friendly eCommerce with trusted reviews and increased sales growth.
Combine Reviews for WooCommerce Developer Profile
5 plugins · 1K total installs
How We Detect Combine Reviews for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woo-combined-reviews/assets/css/admin.csswoo-combined-reviews/assets/css/admin.css?ver=