
WP Social Ninja – Embed Social Feeds, User Reviews & Chat Widgets Security & Risk Analysis
wordpress.org/plugins/wp-social-reviewsAdd Facebook feeds, Instagram feeds, TikTok feeds, Facebook reviews, WhatsApp Chat, Messenger chat, Testimonial, and others using a single dashboard.
Is WP Social Ninja – Embed Social Feeds, User Reviews & Chat Widgets Safe to Use in 2026?
Generally Safe
Score 96/100WP Social Ninja – Embed Social Feeds, User Reviews & Chat Widgets has a strong security track record. Known vulnerabilities have been patched promptly.
The wp-social-reviews plugin v4.1.0 exhibits a generally good security posture with a strong emphasis on prepared SQL statements and proper output escaping. The static analysis reveals a relatively small attack surface, with all identified entry points (AJAX handlers, shortcodes, cron events) appearing to have appropriate authentication and authorization checks. Taint analysis also shows no critical or high severity vulnerabilities, suggesting that user-supplied input is being handled securely within the analyzed code flows.
However, the presence of the `unserialize` function without further context on its usage is a potential concern. While not explicitly flagged as a vulnerability in the static or taint analysis, deserialization vulnerabilities can be severe if not handled with extreme care. The plugin's vulnerability history, which includes three medium severity CVEs for Cross-Site Scripting and Missing Authorization, is also noteworthy. Although there are no currently unpatched vulnerabilities, this pattern indicates past weaknesses that users should be aware of, even if they have been addressed in subsequent versions. The last reported vulnerability was in December 2025, which suggests recent attention to security fixes.
In conclusion, wp-social-reviews v4.1.0 appears to be a reasonably secure plugin, demonstrating good development practices in several key areas. The absence of critical issues in static and taint analysis, coupled with the lack of unpatched vulnerabilities, is positive. The primary areas for continued vigilance are the safe handling of the `unserialize` function and awareness of the types of past vulnerabilities to ensure they remain mitigated.
Key Concerns
- Presence of unserialize function
- 3 known medium severity CVEs in history
WP Social Ninja – Embed Social Feeds, User Reviews & Chat Widgets Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
WP Social Ninja - Embed Social Feeds, Customer Reviews, Chat Widgets (Google Reviews, YouTube Feed, Photo Feeds, and More) <= 4.0.1 - Missing Authorization to Unauthenticated Plugin's Settings Disclosure And Modification
WP Social Ninja – Embed Social Feeds, Customer Reviews, Chat Widgets (Google Reviews, YouTube Feed, Photo Feeds, and More) <= 3.20.3 - Unauthenticated Stored Cross-Site Scripting via External Content Import
Social Ninja <= 3.20.1 - Missing Authorization
WP Social Ninja – Embed Social Feeds, User Reviews & Chat Widgets Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Social Ninja – Embed Social Feeds, User Reviews & Chat Widgets Attack Surface
AJAX Handlers 4
Shortcodes 1
WordPress Hooks 59
Scheduled Events 1
Maintenance & Trust
WP Social Ninja – Embed Social Feeds, User Reviews & Chat Widgets Maintenance & Trust
Maintenance Signals
Community Trust
WP Social Ninja – Embed Social Feeds, User Reviews & Chat Widgets Alternatives
ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema
reviewx
Drive woocommerce business growth with social proof: gather product reviews with multicriteria ratings, auto-reminder emails, discounts, and more.
Customer Reviews Collector for WooCommerce
customer-reviews-collector-for-woocommerce
Collect reviews on Google, Facebook, Yelp, Trustindex and other platforms automatically, with the help of our system.
Merchant Center Reviews for Woocommerce
merchant-center-reviews-for-woocommerce
Merchant Center Reviews for WooCommerce automates the process of requesting reviews via Google Merchant Center, helping you collect valuable feedback.
Collect Reviews
collect-reviews
The ultimate WordPress plugin for automatically collecting reviews on any platform like Google or Facebook.
Reviews Sorted
reviews-sorted
Collect and display verified customer reviews with star ratings, schema markup, and Google reviews on your site.
WP Social Ninja – Embed Social Feeds, User Reviews & Chat Widgets Developer Profile
7 plugins · 40K total installs
How We Detect WP Social Ninja – Embed Social Feeds, User Reviews & Chat Widgets
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-social-reviews/assets/css/wpsocialreviews-frontend.css/wp-content/plugins/wp-social-reviews/assets/css/wpsocialreviews-editor.css/wp-content/plugins/wp-social-reviews/assets/js/wpsr-shortcode-block.js/wp-content/plugins/wp-social-reviews/assets/js/wpsocialreviews-frontend.js/wp-content/plugins/wp-social-reviews/assets/js/wpsocialreviews-editor.js/wp-content/plugins/wp-social-reviews/assets/js/wpsocialreviews-admin.js/wp-content/plugins/wp-social-reviews/assets/css/wpsocialreviews-admin.cssassets/js/wpsocialreviews-frontend.jsassets/js/wpsocialreviews-editor.jswp-social-reviews/assets/css/wpsocialreviews-frontend.css?ver=wp-social-reviews/assets/css/wpsocialreviews-editor.css?ver=wp-social-reviews/assets/js/wpsr-shortcode-block.js?ver=wp-social-reviews/assets/js/wpsocialreviews-frontend.js?ver=wp-social-reviews/assets/js/wpsocialreviews-editor.js?ver=wp-social-reviews/assets/js/wpsocialreviews-admin.js?ver=wp-social-reviews/assets/css/wpsocialreviews-admin.css?ver=HTML / DOM Fingerprints
wpsocialreviews-frontendwpsocialreviews-editor-wrapper<!-- START: WP Social Ninja Review --><!-- END: WP Social Ninja Review --><!-- START: WP Social Ninja Chat --><!-- END: WP Social Ninja Chat -->+2 moredata-wpsocialninja-optionsdata-wpsr-shortcode-idwpSocialReviewsFrontendWPSocialReviewsEditor[wpsocialreviews_reviews[wpsocialreviews_feed[wpsocialreviews_chat][wpsocialreviews_notification]