
Wp Post Rating Security & Risk Analysis
wordpress.org/plugins/wp-post-ratingWP-POST-RATING is powerful rating plugin with ajax security requests.
Is Wp Post Rating Safe to Use in 2026?
Generally Safe
Score 85/100Wp Post Rating has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-post-rating" plugin version 1.2.2 exhibits a mixed security posture. On the positive side, it demonstrates good practices by using prepared statements for all SQL queries, has no known historical vulnerabilities, and makes no external HTTP requests. The absence of bundled libraries also simplifies security management. However, significant concerns arise from the static analysis. Two AJAX handlers are present without any authentication checks, creating a substantial attack surface that could be exploited by unauthenticated users. Furthermore, a concerning 75% of output operations are not properly escaped, leaving the plugin vulnerable to cross-site scripting (XSS) attacks through these unescaped outputs. The taint analysis also indicates three flows with unsanitized paths, although these did not reach a critical or high severity, they still represent potential weaknesses that warrant attention. The plugin's lack of capability checks further exacerbates the risk posed by the unprotected AJAX endpoints and unescaped outputs.
Key Concerns
- Unprotected AJAX handlers
- High percentage of unescaped output
- Flows with unsanitized paths
- No capability checks
Wp Post Rating Security Vulnerabilities
Wp Post Rating Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Wp Post Rating Attack Surface
AJAX Handlers 2
Shortcodes 3
WordPress Hooks 12
Maintenance & Trust
Wp Post Rating Maintenance & Trust
Maintenance Signals
Community Trust
Wp Post Rating Alternatives
WP-PostRatings
wp-postratings
Adds an AJAX rating system for your WordPress site's content.
Post Ratings
post-ratings
Simple, developer-friendly, straightforward post rating plugin. Relies on post meta to store avg. rating / vote count.
Pixelpost Importer
pixelpost-importer
Import your PixelPost database in WordPress (categories, posts, comments, and ratings).
wp-postratings-my
wp-postratings-my
Shows users their WP-PostRatings and allows filters.
MSD Google Review
msd-google-reviews
The quality and quantity of reviews on Google is one of the most important ranking factors for local SEO. And, when a person scans the search results …
Wp Post Rating Developer Profile
1 plugin · 10 total installs
How We Detect Wp Post Rating
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-post-rating/css/main.css/wp-content/plugins/wp-post-rating/js/main.bundle.js/wp-content/plugins/wp-post-rating/js/admin.bundle.js/wp-content/plugins/wp-post-rating/css/admin.css/wp-content/plugins/wp-post-rating/js/main.bundle.js/wp-content/plugins/wp-post-rating/js/admin.bundle.jswp-post-rating/main.css?ver=wp-post-rating/main.bundle.js?ver=HTML / DOM Fingerprints
wp-post-ratingWPR[wp_rating][wp_rating_total][wp_rating_avg]