
Widgets for Google Reviews Security & Risk Analysis
wordpress.org/plugins/wp-reviews-plugin-for-googleEmbed Google reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Google reviews.
Is Widgets for Google Reviews Safe to Use in 2026?
Generally Safe
Score 93/100Widgets for Google Reviews has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "wp-reviews-plugin-for-google" plugin version 13.2.7 presents a mixed security posture. While it demonstrates good practices in areas like output escaping and the majority of SQL queries utilizing prepared statements, significant concerns arise from its unprotected entry points. All three identified entry points, including AJAX handlers and REST API routes, lack authentication or permission checks, creating a substantial attack surface for unauthorized actions. The presence of the 'unserialize' function, a known source of critical vulnerabilities if misused, also warrants caution, although no critical taint flows were detected in the static analysis.
The plugin's vulnerability history, with four known CVEs including one high-severity and three medium-severity issues, highlights a recurring pattern of past security weaknesses. The common types of vulnerabilities found, such as Cross-site Scripting and CSRF, often stem from inadequate input sanitization or authorization, which aligns with the findings of unprotected entry points in the current analysis. The last recorded vulnerability date suggests recent attention to security, but the historical pattern indicates a need for ongoing vigilance and robust security development.
In conclusion, while the plugin has strengths in code escaping and prepared SQL statements, the unprotected entry points and past vulnerability history introduce considerable risk. These factors, combined with the potentially dangerous 'unserialize' function, suggest that users should exercise caution and ensure the plugin is updated to the latest secure version. The lack of proper authorization on multiple entry points is a critical oversight that could be exploited.
Key Concerns
- Unprotected AJAX handler
- Unprotected REST API route
- Unprotected REST API route
- Presence of 'unserialize' function
- 1 High severity CVE historically
- 3 Medium severity CVEs historically
Widgets for Google Reviews Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
Widgets for Google Reviews <= 13.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via trustindex Shortcode
Widgets for Google Reviews <= 13.2.4 - Unauthenticated Stored Cross-Site Scripting via Google Reviews
Widgets for Google Reviews <= 10.9 - Cross-Site Request Forgery to Plugin Settings Reset
Widgets for Google Reviews < 9.8 - Authenticated (Contributor+) Stored XSS
Widgets for Google Reviews Release Timeline
Widgets for Google Reviews Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Widgets for Google Reviews Attack Surface
AJAX Handlers 1
REST API Routes 2
WordPress Hooks 36
Maintenance & Trust
Widgets for Google Reviews Maintenance & Trust
Maintenance Signals
Community Trust
Widgets for Google Reviews Alternatives
Free Google Reviews widget by OpenWidget
free-google-reviews-widget-by-openwidget
⭐️ Embed Google reviews into your WordPress site. Improve trust, sales & SEO of your Wordpress site with Google reviews.
Widgets for Google Business Reviews and Ratings
widgets-for-google-reviews-and-ratings
🛠️ Display Google Business Reviews on your WordPress website to build credibility, boost customer trust, and improve SEO with Google Rich Snippets
Widget for Google Reviews
business-reviews-wp
Shortcode and widget for Google Reviews. Display Google Business Reviews on your WordPress website to increase user confidence and SEO.
Smart Showcase for Google Reviews
smart-showcase-for-google-reviews
Smart Showcase for Google Reviews is a WordPress plugin that lets businesses display Google customer reviews on their websites easily.
GMB Club Connect
gmb-club-connect
Google reviews, social media scheduling, AI-powered articles, and Store Locator with auto-generated SEO pages. The official GMB Club plugin.
Widgets for Google Reviews Developer Profile
34 plugins · 975K total installs
How We Detect Widgets for Google Reviews
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-reviews-plugin-for-google/include/elementor-widgets.php/wp-content/plugins/wp-reviews-plugin-for-google/trustindex-plugin.class.phphttps://cdn.trustindex.io/loader.jswp-reviews-plugin-for-google/trustindex-plugin.class.php?ver=wp-reviews-plugin-for-google/include/schema.php?ver=wp-reviews-plugin-for-google/include/elementor-widgets.php?ver=wp-reviews-plugin-for-google/trustindex-plugin.class.php?ver=13.2.7wp-reviews-plugin-for-google/include/schema.php?ver=13.2.7wp-reviews-plugin-for-google/include/elementor-widgets.php?ver=13.2.7HTML / DOM Fingerprints
trustindex-notification-rowCopyright 2019 Trustindex Kft (email: support@trustindex.io)data-ccm-injectedTrustindexPlugin_googleTrustindexCollectorPlugin/wp-json/trustindex-plugin/v1/admin-ajax.php