
WP Reviews Security & Risk Analysis
wordpress.org/plugins/wp-reviews-liteBest Review Plugin. Customer reviews powered with shortcode to display both grid reviews and slider reviews.
Is WP Reviews Safe to Use in 2026?
Generally Safe
Score 85/100WP Reviews has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-reviews-lite" v1.1.4 plugin exhibits a generally good security posture based on the provided static analysis. The complete absence of dangerous functions, SQL queries executed with prepared statements, and no file operations or external HTTP requests are strong indicators of secure coding practices. The presence of nonce and capability checks, though only one each, is also a positive sign. However, the analysis does highlight areas for potential concern. The 24% of output that is not properly escaped represents a risk of Cross-Site Scripting (XSS) vulnerabilities, especially if user-supplied data is involved in these unescaped outputs. Furthermore, the lack of any taint analysis results could indicate either a very robust codebase or that the analysis itself had limitations in detecting potential data flow issues. The plugin's history of zero known CVEs is highly commendable and suggests a diligent approach to security over time, implying that past vulnerabilities, if any, have been addressed promptly. Overall, while the plugin demonstrates strong adherence to many security best practices, the unescaped output warrants attention to mitigate potential XSS risks.
Key Concerns
- Unescaped output detected
WP Reviews Security Vulnerabilities
WP Reviews Release Timeline
WP Reviews Code Analysis
Output Escaping
WP Reviews Attack Surface
Shortcodes 3
WordPress Hooks 8
Maintenance & Trust
WP Reviews Maintenance & Trust
Maintenance Signals
Community Trust
WP Reviews Alternatives
No alternatives data available yet.
WP Reviews Developer Profile
3 plugins · 10 total installs
How We Detect WP Reviews
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-reviews-lite/style.css/wp-content/plugins/wp-reviews-lite/js/isotope.min.js/wp-content/plugins/wp-reviews-lite/js/packery-mode.min.js/wp-content/plugins/wp-reviews-lite/js/jquery.flexslider-min.js/wp-content/plugins/wp-reviews-lite/js/review-script.js/wp-content/plugins/wp-reviews-lite/js/review-grid-script.js/wp-content/plugins/wp-reviews-lite/css/custom-metabox-styles.csshttps://stackpath.bootstrapcdn.com/font-awesome/4.7.0/css/font-awesome.min.csswp-reviews-lite/style.css?ver=wp-reviews-lite/js/isotope.min.js?ver=wp-reviews-lite/js/packery-mode.min.js?ver=wp-reviews-lite/js/jquery.flexslider-min.js?ver=wp-reviews-lite/js/review-script.js?ver=wp-reviews-lite/js/review-grid-script.js?ver=wp-reviews-lite/css/custom-metabox-styles.css?ver=HTML / DOM Fingerprints
review-grid-item-wrapperreview-grid-loadingreview-grid-innerreview-grid-itemreview-grid-item-innerrev-blurbrev-ratingsrev-content+8 moreDisable direct accessid="review_source"name="review_source"id="review_blurb"name="review_blurb"id="review_company"name="review_company"+9 morereview_grid_shortcodereview_grid_cat_shortcode<div class="review-grid-item-wrapper review-grid-loading"><div class="review-grid-inner"><div class="review-grid-item"><div class="review-grid-item-inner">