Combine Reviews for WooCommerce Security & Risk Analysis

wordpress.org/plugins/woo-combined-reviews

The simple plugin that combine reviews of all products on your WooCommerce website.

0 active installs v1.0.0 PHP 5.6+ WP 4.3+ Updated Mar 10, 2021
reviewswoocommercewoocommerce-reviews
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Combine Reviews for WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Combine Reviews for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "woo-combined-reviews" v1.0.0 plugin exhibits a generally good security posture, with no known vulnerabilities in its history and a clean taint analysis. The static analysis also reveals no dangerous functions, file operations, or external HTTP requests. This indicates that the development team has followed some good security practices. However, there are areas for improvement. The plugin performs one SQL query that does not use prepared statements, which poses a risk of SQL injection if the input to this query is not properly sanitized before reaching the database. Additionally, while the plugin has one nonce check and one capability check, the overall attack surface appears minimal (0 entry points), suggesting this might be less of an immediate concern but still a practice that could be strengthened. The percentage of properly escaped output is also not 100%, which could lead to cross-site scripting (XSS) vulnerabilities if untrusted data is displayed without adequate sanitization.

In conclusion, while the plugin is free of known historical vulnerabilities and has passed a static analysis with no critical or high-severity issues, the presence of raw SQL queries and imperfect output escaping present tangible, albeit potentially manageable, risks. The lack of a larger attack surface is a positive sign. Continued vigilance and adherence to secure coding practices, particularly around database interactions and output rendering, are recommended to maintain a strong security posture.

Key Concerns

  • Raw SQL query without prepared statements
  • Imperfect output escaping
Vulnerabilities
None known

Combine Reviews for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Combine Reviews for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
4
8 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

67% escaped12 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<wcr_admin> (admin\wcr_admin.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Combine Reviews for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionadmin_menuclass-woo-combined-reviews.php:16
actionadmin_enqueue_scriptsclass-woo-combined-reviews.php:17
actionplugins_loadedclass-woo-combined-reviews.php:19
actionplugins_loadedclass-woo-combined-reviews.php:20
filterwoocommerce_product_tabsclass-woo-combined-reviews.php:80
actionadmin_noticeswoo-combined-reviews.php:59
Maintenance & Trust

Combine Reviews for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedMar 10, 2021
PHP min version5.6
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

Combine Reviews for WooCommerce Developer Profile

ahmadshyk

5 plugins · 1K total installs

83
trust score
Avg Security Score
84/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Combine Reviews for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woo-combined-reviews/assets/css/admin.css
Version Parameters
woo-combined-reviews/assets/css/admin.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Combine Reviews for WooCommerce