Builder for WooCommerce product reviews shortcodes – ReviewShort Security & Risk Analysis

wordpress.org/plugins/woo-product-reviews-shortcode

Show WooCommerce customer feedback anywhere with WooCommerce reviews shortcodes, beautifully and ...

100 active installs v1.01.8 PHP 7.0+ WP 5.0+ Updated Feb 23, 2025
customer-reviewsgoogle-ratingreview-pluginwoocommerce-product-reviewswoocommerce-reviews
91
A · Safe
CVEs total2
Unpatched0
Last CVEMay 16, 2024
Download
Safety Verdict

Is Builder for WooCommerce product reviews shortcodes – ReviewShort Safe to Use in 2026?

Generally Safe

Score 91/100

Builder for WooCommerce product reviews shortcodes – ReviewShort has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: May 16, 2024Updated 1yr ago
Risk Assessment

The 'woo-product-reviews-shortcode' plugin exhibits a mixed security posture. While it demonstrates good practices in terms of prepared SQL statements and a substantial number of nonce and capability checks, concerns arise from the limited output escaping and the presence of unsanitized path taint flows. Despite having zero currently unpatched CVEs, the plugin's history of two medium severity vulnerabilities, specifically Missing Authorization and CSRF, in the past is a significant indicator of potential weaknesses. The most recent vulnerability being in May 2024 suggests that these types of issues may resurface if not addressed comprehensively.

While the attack surface is relatively small and all identified entry points appear to have some form of authorization check, the 14% proper output escaping rate is a notable weakness. This could potentially lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not properly sanitized before being displayed. The two taint flows with unsanitized paths are also a concern, as they suggest a risk of directory traversal or insecure file operations, even though they are not currently classified as critical or high severity. Overall, the plugin has strengths in its handling of database queries and access control mechanisms, but requires attention to output sanitization and potential path manipulation vulnerabilities to improve its security.

Key Concerns

  • Low percentage of properly escaped output
  • Taint flows with unsanitized paths
  • Past medium severity vulnerabilities (Missing Auth, CSRF)
Vulnerabilities
2

Builder for WooCommerce product reviews shortcodes – ReviewShort Security Vulnerabilities

CVEs by Year

2 CVEs in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2024-34763medium · 5.3Missing Authorization

Builder for WooCommerce reviews shortcodes – ReviewShort <= 1.01.5 - Missing Authorization

May 16, 2024 Patched in 1.01.6 (5d)
CVE-2024-29093medium · 4.3Cross-Site Request Forgery (CSRF)

Builder for WooCommerce reviews shortcodes – ReviewShort <= 1.01.3 - Cross-Site Request Forgery

Mar 15, 2024 Patched in 1.01.4 (6d)
Code Analysis
Analyzed Mar 16, 2026

Builder for WooCommerce product reviews shortcodes – ReviewShort Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
217
34 escaped
Nonce Checks
7
Capability Checks
5
File Operations
4
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

SQL Query Safety

100% prepared2 total queries

Output Escaping

14% escaped251 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
wprshrtcd_template_redirect (admin\functions.php:231)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Builder for WooCommerce product reviews shortcodes – ReviewShort Attack Surface

Entry Points5
Unprotected0

AJAX Handlers 4

authwp_ajax_wprshrtcd_save_settingsadmin\functions.php:533
authwp_ajax_wprshrtcd_duplicate_settingsadmin\functions.php:594
authwp_ajax_wprshrtcd_copy_templateadmin\functions.php:645
authwp_ajax_wprshrtcd_delete_templateadmin\functions.php:712

Shortcodes 1

[wprshrtcd_woo_product_reviews] includes\shortcodes.php:203
WordPress Hooks 21
actionadmin_enqueue_scriptsadmin\functions.php:2
actionadmin_menuadmin\functions.php:22
actionadmin_menuadmin\functions.php:23
actioninitadmin\functions.php:107
actioninitadmin\functions.php:220
actiontemplate_redirectadmin\functions.php:229
actioninitincludes\cpt.php:56
actionwp_enqueue_scriptsincludes\functions.php:168
actionwprshrtcd_before_commentsincludes\woo-hooks.php:2
actionwprshrtcd_before_commentsincludes\woo-hooks.php:3
actionwprshrtcd_commentsincludes\woo-hooks.php:5
actionwprshrtcd_before_comment_contentincludes\woo-hooks.php:7
actionwprshrtcd_comment_contentincludes\woo-hooks.php:9
actionwprshrtcd_comment_contentincludes\woo-hooks.php:10
actionwprshrtcd_comment_contentincludes\woo-hooks.php:11
actionwprshrtcd_comment_contentincludes\woo-hooks.php:12
actionadmin_noticeswoo-product-reviews-shortcode.php:39
actionbefore_woocommerce_initwoo-product-reviews-shortcode.php:44
actionplugins_loadedwoo-product-reviews-shortcode.php:103
actionplugins_loadedwoo-product-reviews-shortcode.php:115
filterplugin_localewoo-product-reviews-shortcode.php:118
Maintenance & Trust

Builder for WooCommerce product reviews shortcodes – ReviewShort Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedFeb 23, 2025
PHP min version7.0
Downloads11K

Community Trust

Rating52/100
Number of ratings5
Active installs100
Developer Profile

Builder for WooCommerce product reviews shortcodes – ReviewShort Developer Profile

Saleswonder Team: Tobias

4 plugins · 3K total installs

78
trust score
Avg Security Score
86/100
Avg Patch Time
48 days
View full developer profile
Detection Fingerprints

How We Detect Builder for WooCommerce product reviews shortcodes – ReviewShort

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woo-product-reviews-shortcode/admin/assets/css/tipr.css/wp-content/plugins/woo-product-reviews-shortcode/admin/assets/css/style.css/wp-content/plugins/woo-product-reviews-shortcode/admin/assets/js/tipr.min.js/wp-content/plugins/woo-product-reviews-shortcode/admin/assets/js/script.js
Script Paths
admin/assets/js/tipr.min.jsadmin/assets/js/script.js
Version Parameters
woo-product-reviews-shortcode/admin/assets/css/tipr.css?ver=woo-product-reviews-shortcode/admin/assets/css/style.css?ver=woo-product-reviews-shortcode/admin/assets/js/tipr.min.js?ver=woo-product-reviews-shortcode/admin/assets/js/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
wprshrtcd-builderwprshrtcd-help
Data Attributes
data-nonce="wprshrtcd_ajax_nonce"
JS Globals
wprshrtcd_ajax_objectrevrt_fs
FAQ

Frequently Asked Questions about Builder for WooCommerce product reviews shortcodes – ReviewShort