
WP Rate And Review Security & Risk Analysis
wordpress.org/plugins/wp-rate-and-reviewWP Rate And Review enhances your WooCommerce product pages by displaying attractive and customizable rating and review summaries.
Is WP Rate And Review Safe to Use in 2026?
Generally Safe
Score 100/100WP Rate And Review has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-rate-and-review plugin v1.2.2 demonstrates a generally strong security posture, especially regarding SQL injection vulnerabilities due to the exclusive use of prepared statements. The absence of known CVEs and a clean vulnerability history further bolster confidence in its current security. The static analysis highlights a limited attack surface with only three entry points, all of which appear to be protected by authentication checks. This indicates good development practices in securing these critical interaction points.
However, a significant concern arises from the output escaping. With 52% of outputs properly escaped, there's a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. This means that user-supplied data or data processed by the plugin might be rendered directly in the browser without adequate sanitization, allowing attackers to inject malicious scripts. While there are no critical taint flows or dangerous functions identified, the high percentage of unescaped output presents a clear and actionable risk that needs immediate attention. The plugin also utilizes the Select2 library, and its version is not specified, which could pose a risk if it's outdated and has known vulnerabilities.
In conclusion, wp-rate-and-review v1.2.2 is architecturally sound in its handling of database interactions and has a favorable vulnerability history. The protected entry points are a major strength. Nevertheless, the widespread lack of output escaping is a critical weakness that significantly elevates the overall risk profile. Addressing this output sanitization issue should be the highest priority to mitigate potential XSS attacks.
Key Concerns
- Significant percentage of unescaped output
- Select2 bundled library, version unknown
WP Rate And Review Security Vulnerabilities
WP Rate And Review Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Rate And Review Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 9
Maintenance & Trust
WP Rate And Review Maintenance & Trust
Maintenance Signals
Community Trust
WP Rate And Review Alternatives
Photo Reviews for WooCommerce
woo-photo-reviews
Let customers attach photos to reviews, enhanced with filterable grids and overall ratings. Auto-send review reminders and coupon emails
ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema
reviewx
Drive woocommerce business growth with social proof: gather product reviews with multicriteria ratings, auto-reminder emails, discounts, and more.
Faview – Virtual Reviews for WooCommerce
woo-virtual-reviews
Faview - Virtual Reviews for WooCommerce generates and displays canned reviews to boost your customer engagement.
Customer Reviews Collector for WooCommerce
customer-reviews-collector-for-woocommerce
Collect reviews on Google, Facebook, Yelp, Trustindex and other platforms automatically, with the help of our system.
Ryviu – Product Reviews for WooCommerce
ryviu
Install Ryviu quickly and easily into your WordPress site. Boost eco-friendly eCommerce with trusted reviews and increased sales growth.
WP Rate And Review Developer Profile
3 plugins · 10 total installs
How We Detect WP Rate And Review
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-rate-and-review/assets/css/wphp-progressbar.css/wp-content/plugins/wp-rate-and-review/assets/css/all.min.css/wp-content/plugins/wp-rate-and-review/assets/css/wpic-frontend.css/wp-content/plugins/wp-rate-and-review/assets/js/wpic-frontend.jswp-rate-and-review/assets/css/wphp-progressbar.css?ver=wp-rate-and-review/assets/css/all.min.css?ver=wp-rate-and-review/assets/css/wpic-frontend.css?ver=wp-rate-and-review/templates/woocommerce/wp-rate-and-review/assets/js/wpic-frontend.js?ver=HTML / DOM Fingerprints
wcrr-rating-wrapperwcrr-review-listwcrr-single-reviewwcrr-review-titlewcrr-review-authorwcrr-review-datewcrr-review-contentwcrr-progress-bar-container+8 more<!-- AJAX handler for rating and review -->data-product_iddata-nonceWCRR_AJAX_URLWCRR_OBJ[wp_rate_review]