
WP Review Slider Security & Risk Analysis
wordpress.org/plugins/wp-facebook-reviewsUse the official Facebook API to show off your review and recommendations in a slider or grid! A simple and easy way to display your Twitter and Faceb …
Is WP Review Slider Safe to Use in 2026?
Generally Safe
Score 90/100WP Review Slider has a strong security track record. Known vulnerabilities have been patched promptly.
The "wp-facebook-reviews" plugin v14.0 presents a moderate security risk primarily due to a significant number of unprotected AJAX endpoints. While the static analysis shows no critical or high severity taint flows and a decent percentage of SQL queries using prepared statements, the high count of unprotected entry points (6 out of 7) is a major concern. This indicates that attackers could potentially trigger functionality within the plugin without proper authentication, opening the door to various exploits.
The plugin's vulnerability history, with 4 known CVEs including high and medium severity issues like Cross-Site Scripting and SQL Injection, further reinforces the need for caution. Although there are currently no unpatched vulnerabilities, the recurring nature of these vulnerability types suggests potential weaknesses in input sanitization and output escaping within the plugin's codebase that have been exploited in the past.
Overall, the plugin demonstrates some good practices such as the use of nonces and capability checks, and a lack of dangerous functions. However, the substantial attack surface without adequate authorization controls, combined with its past vulnerability record, necessitates vigilance. Users should ensure they are on the latest patch levels and be aware of the potential for new vulnerabilities to emerge if these fundamental security gaps are not addressed.
Key Concerns
- High number of unprotected AJAX handlers
- Previous high severity vulnerabilities (XSS, SQLi)
- Bundled outdated library (Freemius v1.0)
- SQL queries not using prepared statements
- Output escaping not always properly applied
WP Review Slider Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
WP Review Slider <= 13.9 - Authenticated (Subscriber+) Stored Cross-Site Scripting
WP Review Slider <= 12.7 - Authenticated (Administrator+) Stored Cross-Site Scripting
WP Review Slider <= 12.8 - Authenticated (Administrator+) Stored Cross-Site Scripting
WP Review Slider <= 12.1 - Authenticated (Subscriber+) SQL Injection
WP Review Slider < 11.0 - SQL Injection
WP Review Slider Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Review Slider Attack Surface
AJAX Handlers 6
Shortcodes 1
WordPress Hooks 15
Maintenance & Trust
WP Review Slider Maintenance & Trust
Maintenance Signals
Community Trust
WP Review Slider Alternatives
WP Google Review Slider
wp-google-places-review-slider
Display Google reviews on your site and even show user images! No address, no problem! Also works with Service Area Businesses and Products! Lightwei …
WP TripAdvisor Review Slider
wp-tripadvisor-review-slider
Create a TripAdvisor review slider! Now with User Images! Easily display your TripAdvisor reviews in your Posts, Pages, and Widget areas!
EmbedSocial – Social Media Feeds, Reviews and Galleries
embedalbum-pro
EmbedSocial allows you to collect and embed social media content on any website automatically.
Solid Testimonials – Testimonial Slider, Video Testimonials & Customer Reviews
gs-testimonial
Showcase and automate customer reviews with ease - sliders, grids, filters, and more to boost trust and sales.
Testimonial Customer Feedback
testimonial-maker
Display client testimonials with customizable layouts, slider effects, and responsive design. Simple setup with shortcode support.
WP Review Slider Developer Profile
11 plugins · 48K total installs
How We Detect WP Review Slider
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-facebook-reviews/admin/css/wp-fb-reviews-admin.css/wp-content/plugins/wp-facebook-reviews/admin/js/wp-fb-reviews-admin.js/wp-content/plugins/wp-facebook-reviews/public/css/wp-fb-reviews-public.css/wp-content/plugins/wp-facebook-reviews/public/js/wp-fb-reviews-public.jsHTML / DOM Fingerprints
wp-fb-reviews-widgetwp-fb-reviews-sliderwpfbreviews-facebook<!-- wp-fb-reviews starts here --><!-- wp-fb-reviews ends here -->data-fb-app-iddata-page-iddata-page-access-tokendata-posts-limitdata-show-avatardata-show-author+5 moreWP_FB_Reviews_Public/wp-json/wp-fb-reviews/v1/get-reviews[wp_fb_reviews]