WP Google Review Slider Security & Risk Analysis

wordpress.org/plugins/wp-google-places-review-slider

Display Google reviews on your site and even show user images! No address, no problem! Also works with Service Area Businesses and Products! Lightwei …

30K active installs v17.7 PHP + WP 3.0.1+ Updated Dec 3, 2025
googlegoogle-places-reviewsreviewsslidertestimonials
92
A · Safe
CVEs total6
Unpatched0
Last CVENov 14, 2025
Safety Verdict

Is WP Google Review Slider Safe to Use in 2026?

Generally Safe

Score 92/100

WP Google Review Slider has a strong security track record. Known vulnerabilities have been patched promptly.

6 known CVEsLast CVE: Nov 14, 2025Updated 4mo ago
Risk Assessment

The 'wp-google-places-review-slider' plugin, version 17.7, presents a mixed security posture. While the static analysis shows no critical or high severity taint flows and a reasonable percentage of SQL queries using prepared statements and output escaping, there are significant concerns. The most alarming aspect is the substantial attack surface of 14 unprotected AJAX handlers, indicating a high likelihood of unauthorized access to plugin functionalities. The vulnerability history, with 6 known CVEs including one high and five medium severity issues, highlights a pattern of past security weaknesses. Common vulnerability types like Missing Authorization, CSRF, XSS, and SQL Injection further reinforce these concerns, suggesting that input validation and authorization checks have been historically insufficient.

Despite the absence of current unpatched vulnerabilities and some positive coding practices like a good percentage of prepared statements, the sheer number of unprotected entry points and the historical pattern of vulnerabilities are major red flags. The plugin's past struggles with fundamental security concepts like authorization and input sanitization, combined with a broad, unprotected AJAX interface, make it a considerable risk. While the specific code signals for this version are not inherently dire (no dangerous functions, no unsanitized paths), the historical context and the exposed attack surface heavily outweigh these positive aspects. Users should exercise extreme caution.

Key Concerns

  • 14 unprotected AJAX handlers
  • 6 known CVEs (1 high, 5 medium)
  • Vulnerability history includes Missing Auth, CSRF, XSS, SQLi
  • Bundled Freemius v1.0 (potentially outdated)
Vulnerabilities
6

WP Google Review Slider Security Vulnerabilities

CVEs by Year

1 CVE in 2022
2022
1 CVE in 2023
2023
1 CVE in 2024
2024
3 CVEs in 2025
2025
Patched Has unpatched

Severity Breakdown

High
1
Medium
5

6 total CVEs

CVE-2025-66063medium · 4.3Missing Authorization

Google Review Slider <= 17.4 - Missing Authorization

Nov 14, 2025 Patched in 17.6 (12d)
CVE-2025-30783medium · 4.3Cross-Site Request Forgery (CSRF)

WP Google Review Slider <= 16.0 - Cross-Site Request Forgery to SQL Injection

Mar 27, 2025 Patched in 16.1 (7d)
CVE-2024-11109medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WP Google Review Slider <= 15.5 - Authenticated (Admin+) Stored Cross-Site Scripting

Mar 3, 2025 Patched in 15.6 (86d)
CVE-2024-2310medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WP Google Review Slider <= 13.5 - Authenticated (Administrator+) Stored Cross-Site Scripting

Apr 5, 2024 Patched in 13.6 (18d)
CVE-2023-0259high · 8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

WP Google Review Slider <= 11.7 - Authenticated (Subscriber+) SQL Injection

Jan 23, 2023 Patched in 11.8 (365d)
CVE-2022-4242medium · 5.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WP Google Review Slider <= 11.5 - Authenticated (Administrator+) Stored Cross-Site Scripting

Dec 2, 2022 Patched in 11.6 (417d)
Code Analysis
Analyzed Mar 16, 2026

WP Google Review Slider Code Analysis

Dangerous Functions
0
Raw SQL Queries
24
27 prepared
Unescaped Output
150
286 escaped
Nonce Checks
23
Capability Checks
24
File Operations
7
External Requests
15
Bundled Libraries
1

Bundled Libraries

Freemius1.0

SQL Query Safety

53% prepared51 total queries

Output Escaping

66% escaped436 total outputs
Data Flows
All sanitized

Data Flow Analysis

9 flows
wpfbr_ajax_crawl_placeid (admin\class-wp-google-reviews-admin.php:1014)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
14 unprotected

WP Google Review Slider Attack Surface

Entry Points15
Unprotected14

AJAX Handlers 14

authwp_ajax_wpfbr_google_reviewsincludes\class-wp-google-reviews.php:391
authwp_ajax_wpfbr_testing_apiincludes\class-wp-google-reviews.php:394
authwp_ajax_wpfbr_crawl_placeidincludes\class-wp-google-reviews.php:397
authwp_ajax_wpfbr_crawl_placeid_goincludes\class-wp-google-reviews.php:400
authwp_ajax_wprp_get_previewincludes\class-wp-google-reviews.php:417
authwp_ajax_wprp_save_templateincludes\class-wp-google-reviews.php:419
authwp_ajax_wpfbr_dfs_daily_remainingincludes\class-wp-google-reviews.php:422
authwp_ajax_wpfbr_dfs_test_searchincludes\class-wp-google-reviews.php:425
authwp_ajax_wpfbr_dfs_download_reviewsincludes\class-wp-google-reviews.php:428
authwp_ajax_wpfbr_dfs_poll_resultsincludes\class-wp-google-reviews.php:431
authwp_ajax_wpfbr_dfs_save_place_idincludes\class-wp-google-reviews.php:434
authwp_ajax_wpfbr_dfs_save_task_idincludes\class-wp-google-reviews.php:435
authwp_ajax_wpfbr_dfs_update_task_statusincludes\class-wp-google-reviews.php:436
authwp_ajax_wpfbr_dfs_check_existing_taskincludes\class-wp-google-reviews.php:437

Shortcodes 1

[wprevpro_usetemplate] public\class-wp-google-reviews-public.php:142
WordPress Hooks 17
actionplugins_loadedincludes\class-wp-google-reviews.php:365
actionadmin_enqueue_scriptsincludes\class-wp-google-reviews.php:380
actionadmin_enqueue_scriptsincludes\class-wp-google-reviews.php:382
actionadmin_initincludes\class-wp-google-reviews.php:385
actionadmin_menuincludes\class-wp-google-reviews.php:388
actionadmin_noticesincludes\class-wp-google-reviews.php:407
actionwp_dashboard_setupincludes\class-wp-google-reviews.php:410
actionadmin_menuincludes\class-wp-google-reviews.php:413
actionadmin_headincludes\class-wp-google-reviews.php:414
actionwpgoogle_daily_eventincludes\class-wp-google-reviews.php:440
actionwp_enqueue_scriptsincludes\class-wp-google-reviews.php:458
actionwp_enqueue_scriptsincludes\class-wp-google-reviews.php:459
actionwpfbr_cron_google_reviewincludes\class-wp-google-reviews.php:461
actioninitpublic\class-wp-google-reviews-template_action.php:3
actionwprev_pro_plugin_actionpublic\class-wp-google-reviews-template_action.php:24
actionwidgets_initpublic\class-wp-google-reviews-widget.php:95
actionafter_uninstallwp-google-reviews.php:116

Scheduled Events 2

wpfbr_cron_google_review
wpgoogle_daily_event
Maintenance & Trust

WP Google Review Slider Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 3, 2025
PHP min version
Downloads1.6M

Community Trust

Rating98/100
Number of ratings359
Active installs30K
Developer Profile

WP Google Review Slider Developer Profile

jgwhite33

11 plugins · 48K total installs

74
trust score
Avg Security Score
93/100
Avg Patch Time
201 days
View full developer profile
Detection Fingerprints

How We Detect WP Google Review Slider

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-google-places-review-slider/assets/css/frontend.css/wp-content/plugins/wp-google-places-review-slider/assets/css/owl.carousel.min.css/wp-content/plugins/wp-google-places-review-slider/assets/css/style.css/wp-content/plugins/wp-google-places-review-slider/assets/js/frontend.js/wp-content/plugins/wp-google-places-review-slider/assets/js/owl.carousel.min.js/wp-content/plugins/wp-google-places-review-slider/assets/js/scripts.js
Script Paths
https://wpreviewslider.com/wp-content/plugins/wp-google-places-review-slider/assets/js/frontend.jshttps://wpreviewslider.com/wp-content/plugins/wp-google-places-review-slider/assets/js/owl.carousel.min.jshttps://wpreviewslider.com/wp-content/plugins/wp-google-places-review-slider/assets/js/scripts.js
Version Parameters
wp-google-places-review-slider/assets/css/frontend.css?ver=wp-google-places-review-slider/assets/css/owl.carousel.min.css?ver=wp-google-places-review-slider/assets/css/style.css?ver=wp-google-places-review-slider/assets/js/frontend.js?ver=wp-google-places-review-slider/assets/js/owl.carousel.min.js?ver=wp-google-places-review-slider/assets/js/scripts.js?ver=

HTML / DOM Fingerprints

CSS Classes
wpr-review-slider
Data Attributes
data-iddata-location-iddata-place-iddata-api-keydata-langdata-lat+5 more
JS Globals
wpslider_options
Shortcode Output
[wp_google_reviews]
FAQ

Frequently Asked Questions about WP Google Review Slider