
wp-postratings-my Security & Risk Analysis
wordpress.org/plugins/wp-postratings-myShows users their WP-PostRatings and allows filters.
Is wp-postratings-my Safe to Use in 2026?
Generally Safe
Score 100/100wp-postratings-my has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-postratings-my" plugin version 3.6.1 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, properly escaped output, and SQL queries that exclusively use prepared statements are all positive indicators. Furthermore, the lack of known vulnerabilities in its history suggests a history of security awareness by the developers.
However, there are notable areas for concern. The most significant is the complete absence of nonce checks and capability checks. While the static analysis reported no unprotected entry points, the lack of these fundamental WordPress security mechanisms on the single identified shortcode is a critical oversight. This could potentially allow for unauthorized actions if a vulnerability elsewhere were to be exploited, or if the shortcode itself has unforeseen interaction points.
In conclusion, while the plugin avoids common pitfalls like raw SQL or unescaped output, the missing nonce and capability checks represent a significant weakness in its security architecture. This oversight leaves it vulnerable to certain types of attacks that could be mitigated with these standard WordPress security practices. The developer should prioritize implementing these checks.
Key Concerns
- No nonce checks implemented
- No capability checks implemented
wp-postratings-my Security Vulnerabilities
wp-postratings-my Code Analysis
SQL Query Safety
Output Escaping
wp-postratings-my Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
wp-postratings-my Maintenance & Trust
Maintenance Signals
Community Trust
wp-postratings-my Alternatives
WP-PostRatings
wp-postratings
Adds an AJAX rating system for your WordPress site's content.
Pixelpost Importer
pixelpost-importer
Import your PixelPost database in WordPress (categories, posts, comments, and ratings).
Post Ratings
post-ratings
Simple, developer-friendly, straightforward post rating plugin. Relies on post meta to store avg. rating / vote count.
Wp Post Rating
wp-post-rating
WP-POST-RATING is powerful rating plugin with ajax security requests.
Strong Testimonials
strong-testimonials
An easy-to-use testimonial plugin to collect and show customer feedback in WordPress
wp-postratings-my Developer Profile
2 plugins · 20 total installs
How We Detect wp-postratings-my
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-postratings-my/wp-postratings-my.phpHTML / DOM Fingerprints
<h3>Your Ratings</h3>Filter Ratings: <br /><i>Current Filters [<a href="?" title="clear filters">x</a>]:</i> <br /><br />