
WP Plugin Reviews Security & Risk Analysis
wordpress.org/plugins/wp-plugin-reviewsDisplays the latest reviews of a WordPress Plugin in the sidebar.
Is WP Plugin Reviews Safe to Use in 2026?
Generally Safe
Score 85/100WP Plugin Reviews has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'wp-plugin-reviews' plugin v0.4 exhibits a generally good security posture with no recorded vulnerabilities or critical taint flows. The plugin demonstrates strong adherence to secure coding practices by exclusively using prepared statements for SQL queries and avoiding file operations or external HTTP requests, which are common vectors for attacks. The absence of a significant attack surface, with zero AJAX handlers, REST API routes, shortcodes, or cron events, further reduces its exposure to potential exploits. However, the presence of the `create_function` function is a notable concern. While it's not directly linked to a discovered vulnerability in this version, `create_function` is deprecated and can be a source of security issues if not handled with extreme care, particularly in how its inputs are managed. Additionally, a very low percentage (22%) of output is properly escaped, indicating a potential risk for cross-site scripting (XSS) vulnerabilities if user-controlled data is outputted without adequate sanitization. The lack of any recorded vulnerability history is a positive indicator, suggesting the developers are either diligent or the plugin has not been a target. However, it's crucial to remember that a clean history doesn't guarantee future security, especially with the identified code quality concerns.
Key Concerns
- Use of deprecated and potentially unsafe create_function
- Low percentage of properly escaped output
- No nonce checks implemented
- No capability checks implemented
WP Plugin Reviews Security Vulnerabilities
WP Plugin Reviews Code Analysis
Dangerous Functions Found
Output Escaping
WP Plugin Reviews Attack Surface
WordPress Hooks 3
Maintenance & Trust
WP Plugin Reviews Maintenance & Trust
Maintenance Signals
Community Trust
WP Plugin Reviews Alternatives
Widgets for Google Reviews
wp-reviews-plugin-for-google
Embed Google reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Google reviews.
Rich Showcase for Google Reviews
widget-google-reviews
Display up to 10 Google reviews in less than a minute. Continue collecting new reviews. No limits on connected places, widgets, shortcodes and blocks.
Trustpilot Reviews
trustpilot-reviews
Generate reviews, add TrustBox for your Woocommerce site with Trustpilot reviews plugin
WP Testimonials
testimonial-widgets
Display your Testimonials on your website fast and easily. 21 widget types, 25 widget styles available. (Free Plugin)
Widgets for Booking.com Reviews
review-widgets-for-booking-com
Embed Booking.com reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Booking.com reviews.
WP Plugin Reviews Developer Profile
16 plugins · 21K total installs
How We Detect WP Plugin Reviews
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
plugin-reviewsplugin-reviewplugin-review-textplugin-review-authorWP_Plugin_Review_Widgetid="wp-plugin-reviews"id="wp-plugin-reviews-title"id="wp-plugin-reviews-plugin"id="wp-plugin-reviews-count"<div class = "plugin-reviews"><div class = "plugin-review"><blockquote class = "plugin-review-text"><span class = "plugin-review-author" style = "float:right">