
Builder for WooCommerce product reviews shortcodes – ReviewShort Security & Risk Analysis
wordpress.org/plugins/woo-product-reviews-shortcodeShow WooCommerce customer feedback anywhere with WooCommerce reviews shortcodes, beautifully and ...
Is Builder for WooCommerce product reviews shortcodes – ReviewShort Safe to Use in 2026?
Generally Safe
Score 91/100Builder for WooCommerce product reviews shortcodes – ReviewShort has a strong security track record. Known vulnerabilities have been patched promptly.
The 'woo-product-reviews-shortcode' plugin exhibits a mixed security posture. While it demonstrates good practices in terms of prepared SQL statements and a substantial number of nonce and capability checks, concerns arise from the limited output escaping and the presence of unsanitized path taint flows. Despite having zero currently unpatched CVEs, the plugin's history of two medium severity vulnerabilities, specifically Missing Authorization and CSRF, in the past is a significant indicator of potential weaknesses. The most recent vulnerability being in May 2024 suggests that these types of issues may resurface if not addressed comprehensively.
While the attack surface is relatively small and all identified entry points appear to have some form of authorization check, the 14% proper output escaping rate is a notable weakness. This could potentially lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not properly sanitized before being displayed. The two taint flows with unsanitized paths are also a concern, as they suggest a risk of directory traversal or insecure file operations, even though they are not currently classified as critical or high severity. Overall, the plugin has strengths in its handling of database queries and access control mechanisms, but requires attention to output sanitization and potential path manipulation vulnerabilities to improve its security.
Key Concerns
- Low percentage of properly escaped output
- Taint flows with unsanitized paths
- Past medium severity vulnerabilities (Missing Auth, CSRF)
Builder for WooCommerce product reviews shortcodes – ReviewShort Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Builder for WooCommerce reviews shortcodes – ReviewShort <= 1.01.5 - Missing Authorization
Builder for WooCommerce reviews shortcodes – ReviewShort <= 1.01.3 - Cross-Site Request Forgery
Builder for WooCommerce product reviews shortcodes – ReviewShort Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Builder for WooCommerce product reviews shortcodes – ReviewShort Attack Surface
AJAX Handlers 4
Shortcodes 1
WordPress Hooks 21
Maintenance & Trust
Builder for WooCommerce product reviews shortcodes – ReviewShort Maintenance & Trust
Maintenance Signals
Community Trust
Builder for WooCommerce product reviews shortcodes – ReviewShort Alternatives
Reviews for WooCommerce
reviews-for-woocommerce
This plugin provides different template to show WooCommerce reviews of any product.
Customer Reviews Collector for WooCommerce
customer-reviews-collector-for-woocommerce
Collect reviews on Google, Facebook, Yelp, Trustindex and other platforms automatically, with the help of our system.
Yuko Customer Reviews for WooCommerce
yuko-integration
Complete WooCommerce product review plugin and customer review system to collect verified reviews, boost SEO, and drive sales with social proof.
Customer Reviews for WooCommerce
customer-reviews-woocommerce
Customer Reviews for WooCommerce plugin helps you get more sales with social proof. Set up automated review reminders and increase conversion rate.
Photo Reviews for WooCommerce
woo-photo-reviews
Let customers attach photos to reviews, enhanced with filterable grids and overall ratings. Auto-send review reminders and coupon emails
Builder for WooCommerce product reviews shortcodes – ReviewShort Developer Profile
4 plugins · 3K total installs
How We Detect Builder for WooCommerce product reviews shortcodes – ReviewShort
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/woo-product-reviews-shortcode/admin/assets/css/tipr.css/wp-content/plugins/woo-product-reviews-shortcode/admin/assets/css/style.css/wp-content/plugins/woo-product-reviews-shortcode/admin/assets/js/tipr.min.js/wp-content/plugins/woo-product-reviews-shortcode/admin/assets/js/script.jsadmin/assets/js/tipr.min.jsadmin/assets/js/script.jswoo-product-reviews-shortcode/admin/assets/css/tipr.css?ver=woo-product-reviews-shortcode/admin/assets/css/style.css?ver=woo-product-reviews-shortcode/admin/assets/js/tipr.min.js?ver=woo-product-reviews-shortcode/admin/assets/js/script.js?ver=HTML / DOM Fingerprints
wprshrtcd-builderwprshrtcd-helpdata-nonce="wprshrtcd_ajax_nonce"wprshrtcd_ajax_objectrevrt_fs