Wiremo – Customer reviews for WordPress Security & Risk Analysis

wordpress.org/plugins/wp-reviews-by-wiremo

Customer review platform for WordPress. Automatically gather, control and display your best reviews without tech hassles. Free up time to grow your br …

30 active installs v1.2.24 PHP + WP 4.4+ Updated May 2, 2024
collect-reviewsreviewssite-reviewstestimonialswordpress-reviews
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Wiremo – Customer reviews for WordPress Safe to Use in 2026?

Generally Safe

Score 92/100

Wiremo – Customer reviews for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "wp-reviews-by-wiremo" v1.2.24 plugin exhibits a mixed security posture. While it has no known CVEs and the taint analysis shows no critical or high severity issues, the static analysis reveals several areas for concern. A significant number of entry points (6 out of 20) lack proper authentication or permission checks, which could expose them to unauthorized access or manipulation. Furthermore, the complete absence of prepared statements for SQL queries is a major red flag, making the plugin highly susceptible to SQL injection vulnerabilities. The low percentage of properly escaped output also increases the risk of cross-site scripting (XSS) attacks. The plugin's history of no vulnerabilities might indicate a lack of targeted attacks or a fortunate absence of exploitable issues thus far, but the current static analysis findings point to a potentially fragile security foundation that requires immediate attention, especially regarding the unprotected entry points and unparameterized SQL queries.

Key Concerns

  • Unprotected AJAX handlers
  • Unprotected REST API routes
  • Raw SQL queries without prepared statements
  • Low output escaping percentage
  • Flows with unsanitized paths (Taint Analysis)
Vulnerabilities
None known

Wiremo – Customer reviews for WordPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Wiremo – Customer reviews for WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
0 prepared
Unescaped Output
95
46 escaped
Nonce Checks
8
Capability Checks
11
File Operations
1
External Requests
12
Bundled Libraries
0

SQL Query Safety

0% prepared2 total queries

Output Escaping

33% escaped141 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

5 flows1 with unsanitized paths
form_action_url (appsero\src\License.php:778)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
6 unprotected

Wiremo – Customer reviews for WordPress Attack Surface

Entry Points20
Unprotected6

AJAX Handlers 16

authwp_ajax_importWrStatisticsclasses\class-wrmr-administrator.php:45
noprivwp_ajax_importWrStatisticsclasses\class-wrmr-administrator.php:46
authwp_ajax_wrmr_oauth_userclasses\class-wrmr-ajax.php:21
noprivwp_ajax_wrmr_oauth_userclasses\class-wrmr-ajax.php:22
authwp_ajax_wrmr_get_site_idclasses\class-wrmr-ajax.php:23
noprivwp_ajax_wrmr_get_site_idclasses\class-wrmr-ajax.php:24
authwp_ajax_wrmr_auto_registerclasses\class-wrmr-ajax.php:25
noprivwp_ajax_wrmr_auto_registerclasses\class-wrmr-ajax.php:26
authwp_ajax_wrmr_validate_siteclasses\class-wrmr-ajax.php:27
noprivwp_ajax_wrmr_validate_siteclasses\class-wrmr-ajax.php:28
authwp_ajax_wrmr_no_validate_siteclasses\class-wrmr-ajax.php:29
noprivwp_ajax_wrmr_no_validate_siteclasses\class-wrmr-ajax.php:30
authwp_ajax_wrmr_add_api_keyclasses\class-wrmr-ajax.php:31
noprivwp_ajax_wrmr_add_api_keyclasses\class-wrmr-ajax.php:32
authwp_ajax_wrmr_add_register_hookclasses\class-wrmr-ajax.php:33
noprivwp_ajax_wrmr_add_register_hookclasses\class-wrmr-ajax.php:34

REST API Routes 2

GET/wp-json/wiremo/v1/hook-wpclasses\class-wrmr-routes.php:209
GET/wp-json/wiremo/v1/import-wpclasses\class-wrmr-routes.php:215

Shortcodes 2

[wr-widget-lite] classes\class-wrmr-shortcodes.php:25
[wr-widget-reviews] classes\class-wrmr-shortcodes.php:26
WordPress Hooks 32
actionswitch_themeappsero\src\Insights.php:134
actionswitch_themeappsero\src\Insights.php:135
actionadmin_footerappsero\src\Insights.php:147
actionadmin_noticesappsero\src\Insights.php:165
actionadmin_initappsero\src\Insights.php:168
filtercron_schedulesappsero\src\Insights.php:174
actionadmin_menuappsero\src\License.php:222
actionafter_switch_themeappsero\src\License.php:769
actionswitch_themeappsero\src\License.php:770
filterpre_set_site_transient_update_pluginsappsero\src\Updater.php:42
filterplugins_apiappsero\src\Updater.php:43
filterpre_set_site_transient_update_themesappsero\src\Updater.php:52
actionplugins_loadedclasses\class-wrmr-administrator.php:39
actionadmin_enqueue_scriptsclasses\class-wrmr-administrator.php:40
actionwp_enqueue_scriptsclasses\class-wrmr-administrator.php:41
actionadmin_headclasses\class-wrmr-administrator.php:42
actionadmin_menuclasses\class-wrmr-administrator.php:43
actionadmin_initclasses\class-wrmr-administrator.php:44
actioninitclasses\class-wrmr-administrator.php:454
actionadmin_enqueue_scriptsclasses\class-wrmr-administrator.php:477
actionwp_headclasses\class-wrmr-ajax.php:20
actioninitclasses\class-wrmr-ajax.php:278
actionrest_api_initclasses\class-wrmr-routes.php:21
actioninitclasses\class-wrmr-routes.php:224
actionwp_footerclasses\class-wrmr-shortcodes.php:260
actionwp_footerclasses\class-wrmr-shortcodes.php:584
actioninitclasses\class-wrmr-shortcodes.php:593
actioninitfunction.php:69
filtermce_external_pluginsfunction.php:92
filtermce_buttonsfunction.php:95
filteradmin_footer_textfunction.php:143
actionenqueue_block_editor_assetssrc\initBlocks.php:37
Maintenance & Trust

Wiremo – Customer reviews for WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedMay 2, 2024
PHP min version
Downloads5K

Community Trust

Rating60/100
Number of ratings4
Active installs30
Developer Profile

Wiremo – Customer reviews for WordPress Developer Profile

Wiremo

2 plugins · 830 total installs

65
trust score
Avg Security Score
80/100
Avg Patch Time
699 days
View full developer profile
Detection Fingerprints

How We Detect Wiremo – Customer reviews for WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-reviews-by-wiremo/assets/css/admin-fonts.css/wp-content/plugins/wp-reviews-by-wiremo/assets/css/font-awesome.min.css/wp-content/plugins/wp-reviews-by-wiremo/assets/css/style.css/wp-content/plugins/wp-reviews-by-wiremo/assets/js/shortcode.js/wp-content/plugins/wp-reviews-by-wiremo/src/initBlocks.php
Script Paths
/wp-content/plugins/wp-reviews-by-wiremo/appsero/src/Client.php

HTML / DOM Fingerprints

CSS Classes
rate
Data Attributes
onclick="window.open('https://wiremo.co/getreviews.php?rating=
JS Globals
window.open('https://wiremo.co/getreviews.php?rating=
FAQ

Frequently Asked Questions about Wiremo – Customer reviews for WordPress