
WP Google Review Slider Security & Risk Analysis
wordpress.org/plugins/wp-google-places-review-sliderDisplay Google reviews on your site and even show user images! No address, no problem! Also works with Service Area Businesses and Products! Lightwei …
Is WP Google Review Slider Safe to Use in 2026?
Generally Safe
Score 92/100WP Google Review Slider has a strong security track record. Known vulnerabilities have been patched promptly.
The 'wp-google-places-review-slider' plugin, version 17.7, presents a mixed security posture. While the static analysis shows no critical or high severity taint flows and a reasonable percentage of SQL queries using prepared statements and output escaping, there are significant concerns. The most alarming aspect is the substantial attack surface of 14 unprotected AJAX handlers, indicating a high likelihood of unauthorized access to plugin functionalities. The vulnerability history, with 6 known CVEs including one high and five medium severity issues, highlights a pattern of past security weaknesses. Common vulnerability types like Missing Authorization, CSRF, XSS, and SQL Injection further reinforce these concerns, suggesting that input validation and authorization checks have been historically insufficient.
Despite the absence of current unpatched vulnerabilities and some positive coding practices like a good percentage of prepared statements, the sheer number of unprotected entry points and the historical pattern of vulnerabilities are major red flags. The plugin's past struggles with fundamental security concepts like authorization and input sanitization, combined with a broad, unprotected AJAX interface, make it a considerable risk. While the specific code signals for this version are not inherently dire (no dangerous functions, no unsanitized paths), the historical context and the exposed attack surface heavily outweigh these positive aspects. Users should exercise extreme caution.
Key Concerns
- 14 unprotected AJAX handlers
- 6 known CVEs (1 high, 5 medium)
- Vulnerability history includes Missing Auth, CSRF, XSS, SQLi
- Bundled Freemius v1.0 (potentially outdated)
WP Google Review Slider Security Vulnerabilities
CVEs by Year
Severity Breakdown
6 total CVEs
Google Review Slider <= 17.4 - Missing Authorization
WP Google Review Slider <= 16.0 - Cross-Site Request Forgery to SQL Injection
WP Google Review Slider <= 15.5 - Authenticated (Admin+) Stored Cross-Site Scripting
WP Google Review Slider <= 13.5 - Authenticated (Administrator+) Stored Cross-Site Scripting
WP Google Review Slider <= 11.7 - Authenticated (Subscriber+) SQL Injection
WP Google Review Slider <= 11.5 - Authenticated (Administrator+) Stored Cross-Site Scripting
WP Google Review Slider Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Google Review Slider Attack Surface
AJAX Handlers 14
Shortcodes 1
WordPress Hooks 17
Scheduled Events 2
Maintenance & Trust
WP Google Review Slider Maintenance & Trust
Maintenance Signals
Community Trust
WP Google Review Slider Alternatives
Widgets for Google Business Reviews and Ratings
widgets-for-google-reviews-and-ratings
🛠️ Display Google Business Reviews on your WordPress website to build credibility, boost customer trust, and improve SEO with Google Rich Snippets
Widgets for Google Reviews
wp-reviews-plugin-for-google
Embed Google reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Google reviews.
Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More
reviews-feed
No API key required. Display Yelp and Google reviews for any business in a clean, customizable feed on your site.
Rich Showcase for Google Reviews
widget-google-reviews
Display up to 10 Google reviews in less than a minute. Continue collecting new reviews. No limits on connected places, widgets, shortcodes and blocks.
WP TripAdvisor Review Slider
wp-tripadvisor-review-slider
Create a TripAdvisor review slider! Now with User Images! Easily display your TripAdvisor reviews in your Posts, Pages, and Widget areas!
WP Google Review Slider Developer Profile
11 plugins · 48K total installs
How We Detect WP Google Review Slider
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-google-places-review-slider/assets/css/frontend.css/wp-content/plugins/wp-google-places-review-slider/assets/css/owl.carousel.min.css/wp-content/plugins/wp-google-places-review-slider/assets/css/style.css/wp-content/plugins/wp-google-places-review-slider/assets/js/frontend.js/wp-content/plugins/wp-google-places-review-slider/assets/js/owl.carousel.min.js/wp-content/plugins/wp-google-places-review-slider/assets/js/scripts.jshttps://wpreviewslider.com/wp-content/plugins/wp-google-places-review-slider/assets/js/frontend.jshttps://wpreviewslider.com/wp-content/plugins/wp-google-places-review-slider/assets/js/owl.carousel.min.jshttps://wpreviewslider.com/wp-content/plugins/wp-google-places-review-slider/assets/js/scripts.jswp-google-places-review-slider/assets/css/frontend.css?ver=wp-google-places-review-slider/assets/css/owl.carousel.min.css?ver=wp-google-places-review-slider/assets/css/style.css?ver=wp-google-places-review-slider/assets/js/frontend.js?ver=wp-google-places-review-slider/assets/js/owl.carousel.min.js?ver=wp-google-places-review-slider/assets/js/scripts.js?ver=HTML / DOM Fingerprints
wpr-review-sliderdata-iddata-location-iddata-place-iddata-api-keydata-langdata-lat+5 morewpslider_options[wp_google_reviews]