
Admin Reviews Security & Risk Analysis
wordpress.org/plugins/wp-admin-reviewsThis plugin allow admin to add reviews on posts and products from admin panel for users.
Is Admin Reviews Safe to Use in 2026?
Generally Safe
Score 85/100Admin Reviews has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-admin-reviews v1.0 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for all its SQL queries and has no known historical vulnerabilities, suggesting a history of secure development. However, the analysis reveals significant security concerns primarily related to its attack surface. With two AJAX handlers identified, and crucially, both lacking authentication checks, there's a substantial risk of unauthorized actions being performed. Furthermore, only one out of twelve output points are properly escaped, indicating a high probability of Cross-Site Scripting (XSS) vulnerabilities. The absence of taint analysis flows with unsanitized paths is a good sign, but it doesn't mitigate the immediate risks from unprotected AJAX endpoints and poor output escaping.
Despite the lack of historical CVEs, the current static analysis results highlight critical areas for immediate attention. The unprotected AJAX handlers are the most pressing concern, potentially allowing any unauthenticated user to trigger sensitive actions within the plugin. The widespread lack of output escaping is another major weakness that could be exploited to inject malicious scripts into the site. While the plugin has good SQL practices and no known vulnerabilities, these strengths are overshadowed by the evident attack vectors present in the code. Addressing the unprotected entry points and improving output escaping should be the top priorities for improving the security of this plugin.
Key Concerns
- Unprotected AJAX handlers
- Poor output escaping (33% proper)
Admin Reviews Security Vulnerabilities
Admin Reviews Release Timeline
Admin Reviews Code Analysis
SQL Query Safety
Output Escaping
Admin Reviews Attack Surface
AJAX Handlers 2
WordPress Hooks 3
Maintenance & Trust
Admin Reviews Maintenance & Trust
Maintenance Signals
Community Trust
Admin Reviews Alternatives
Widgets for Google Reviews
wp-reviews-plugin-for-google
Embed Google reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Google reviews.
Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More
reviews-feed
No API key required. Display Yelp and Google reviews for any business in a clean, customizable feed on your site.
Rich Showcase for Google Reviews
widget-google-reviews
Display up to 10 Google reviews in less than a minute. Continue collecting new reviews. No limits on connected places, widgets, shortcodes and blocks.
Customer Reviews for WooCommerce
customer-reviews-woocommerce
Customer Reviews for WooCommerce plugin helps you get more sales with social proof. Set up automated review reminders and increase conversion rate.
Site Reviews
site-reviews
Site Reviews is a complete review management solution that integrates with WooCommerce and SureCart and works similarly to reviews on Amazon, Tripadvi …
Admin Reviews Developer Profile
5 plugins · 420 total installs
How We Detect Admin Reviews
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-admin-reviews/css/arw-style.css/wp-content/plugins/wp-admin-reviews/js/arw_script.js/wp-content/plugins/wp-admin-reviews/js/arw_script.jswp-admin-reviews/css/arw-style.css?ver=1wp-admin-reviews/js/arw_script.js?ver=HTML / DOM Fingerprints
select2-containerselect2-container--defaultselect2-container--openselect2-dropdownselect2-dropdown--belowselect2-resultsselect2-results__optionssearch_post+2 morepostidrole='option'class='select2-results__option search_post'class='select2-results__option user_detail'emailuser_url+1 moreajax_params/wp-json/wp/v2/users