
WP Customer Reviews Security & Risk Analysis
wordpress.org/plugins/wp-customer-reviewsAllows your visitors to leave business / product reviews. Testimonials are in Microdata / Microformat and may display star ratings in search results.
Is WP Customer Reviews Safe to Use in 2026?
Generally Safe
Score 89/100WP Customer Reviews has a strong security track record. Known vulnerabilities have been patched promptly.
The wp-customer-reviews plugin v3.7.7 presents a mixed security posture. While the static analysis indicates a relatively small attack surface with no immediately obvious unprotected entry points and a decent percentage of SQL queries using prepared statements, several concerning signals exist. The presence of the `unserialize` function is a significant red flag, as it can lead to critical vulnerabilities if not handled with extreme caution and proper input validation. Furthermore, the low percentage of properly escaped output (34%) suggests a high likelihood of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into user-facing content. The plugin's vulnerability history, with 8 known CVEs, including 2 high severity and 6 medium severity, reinforces these concerns. The common vulnerability types like Open Redirect, Missing Authorization, XSS, and CSRF indicate recurring security weaknesses that have been exploited in the past. Although there are currently no unpatched CVEs, the history suggests a pattern of insecure coding practices that could lead to new vulnerabilities in the future. In conclusion, while the plugin has addressed past vulnerabilities, the presence of dangerous functions like `unserialize` and a significant portion of improperly escaped output, combined with a history of multiple high and medium severity CVEs, warrants caution.
Key Concerns
- Dangerous function unserialize present
- Low percentage of properly escaped output (34%)
- Total known CVEs: 8 (2 high, 6 medium)
- Common vulnerability types: Open Redirect, Missing Authorization, XSS, CSRF
WP Customer Reviews Security Vulnerabilities
CVEs by Year
Severity Breakdown
8 total CVEs
WP Customer Reviews <= 3.7.5 - Reflected Cross-Site Scripting via 'wpcr3_fname' Parameter
WP Customer Reviews <= 3.7.0 - Authenticated (Contributor+) Malicious Redirect via HTTP-EQUIV Injection
WP Customer Reviews <= 3.6.6 - Authenticated (Subscriber+) Sensitive Information Exposure
WP Customer Reviews <= 3.6.6 - Authenticated (Administrator+) Stored Cross-Site Scripting
WP Customer Reviews <= 3.5.5 - Authenticated Stored Cross-Site Scripting
WP Customer Reviews <= 3.4.2 - Multiple Stored Cross-Site Scripting
Customer Reviews < 3.0.9 - Cross-Site Scripting
WP Customer Reviews <= 3.0.8 - Cross-Site Request Forgery
WP Customer Reviews Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Customer Reviews Attack Surface
Shortcodes 3
WordPress Hooks 15
Maintenance & Trust
WP Customer Reviews Maintenance & Trust
Maintenance Signals
Community Trust
WP Customer Reviews Alternatives
Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More
reviews-feed
No API key required. Display Yelp and Google reviews for any business in a clean, customizable feed on your site.
Rich Showcase for Google Reviews
widget-google-reviews
Display up to 10 Google reviews in less than a minute. Continue collecting new reviews. No limits on connected places, widgets, shortcodes and blocks.
Site Reviews
site-reviews
Site Reviews is a complete review management solution that integrates with WooCommerce and SureCart and works similarly to reviews on Amazon, Tripadvi …
WP Google Review Slider
wp-google-places-review-slider
Display Google reviews on your site and even show user images! No address, no problem! Also works with Service Area Businesses and Products! Lightwei …
WP Testimonials
testimonial-widgets
Display your Testimonials on your website fast and easily. 21 widget types, 25 widget styles available. (Free Plugin)
WP Customer Reviews Developer Profile
1 plugin · 20K total installs
How We Detect WP Customer Reviews
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-customer-reviews/css/wp-customer-reviews-3.css/wp-content/plugins/wp-customer-reviews/css/wp-customer-reviews-3-frontend.css/wp-content/plugins/wp-customer-reviews/js/wp-customer-reviews-3-frontend.js/wp-content/plugins/wp-customer-reviews/js/wp-customer-reviews-3-frontend.jswp-customer-reviews/css/wp-customer-reviews-3.css?ver=wp-customer-reviews/css/wp-customer-reviews-3-frontend.css?ver=wp-customer-reviews/js/wp-customer-reviews-3-frontend.js?ver=HTML / DOM Fingerprints
wpcr3-frontend-containerwpcr3-frontend-reviews-holderwpcr3-frontend-review-itemwpcr3-frontend-review-formwpcr3-frontend-rating-starsdata-wpcr3-elementdata-wpcr3-rating-valuedata-wpcr3-idwpcr3_ajaxurlwpcr3_frontend_params[wpcr_insert]