
WP Ultimate Review Security & Risk Analysis
wordpress.org/plugins/wp-ultimate-reviewWP Ultimate Review is the perfect plugin to collect & display customers' feedback effortlessly on products, services, & content in WordPress.
Is WP Ultimate Review Safe to Use in 2026?
Generally Safe
Score 95/100WP Ultimate Review has a strong security track record. Known vulnerabilities have been patched promptly.
The wp-ultimate-review plugin, version 2.3.8, presents a mixed security posture. On the positive side, the static analysis indicates good practices in several areas: no dangerous functions were detected, all SQL queries use prepared statements, file operations are absent, and there are several security checks like nonce and capability checks. The majority of output is properly escaped, and the attack surface from AJAX and REST API endpoints is zero, with no unprotected entry points. However, there are concerning signs. The presence of unsanitized paths in taint analysis, even without critical or high severity findings, suggests potential areas where input might not be fully trusted. Furthermore, the plugin has a significant history of vulnerabilities, with 8 medium-severity CVEs recorded, none of which are currently unpatched. The common types of past vulnerabilities – including missing authorization, CSRF, and XSS – are indicative of common plugin security weaknesses that require vigilant attention. The plugin's attack surface is primarily through its shortcodes. While current analysis shows no direct vulnerabilities in these entry points, the historical context warrants a cautious approach. The plugin's recent vulnerability was in late 2025, which might mean the provided data is not entirely up-to-date or reflects a very recent patch. However, the past patterns are a strong indicator of potential future risks if not continuously monitored and addressed.
Key Concerns
- Past vulnerabilities exist (8 medium CVEs)
- Taint analysis shows unsanitized paths
- External HTTP requests present
WP Ultimate Review Security Vulnerabilities
CVEs by Year
Severity Breakdown
8 total CVEs
Ultimate Review <= 2.3.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
Wp Ultimate Review <= 2.2.5 - Missing Authorization
Wp Ultimate Review <= 2.2.5 - Unauthenticated Review Restriction Bypass
Wp Ultimate Review <= 2.2.5 - Unauthenticated Insecure Direct Object Reference
Wp Ultimate Review <= 2.3.6 - IP Spoofing
Wp Ultimate Review <= 2.3.0 - Cross-Site Request Forgery via wur_settings_view
Wp Ultimate Review <= 2.0.3 - Cross-Site Request Forgery
Wp Ultimate Review <= 2.0.3 - Authenticated (Administrator+) Stored Cross-Site Scripting
WP Ultimate Review Code Analysis
Output Escaping
Data Flow Analysis
WP Ultimate Review Attack Surface
Shortcodes 2
WordPress Hooks 24
Maintenance & Trust
WP Ultimate Review Maintenance & Trust
Maintenance Signals
Community Trust
WP Ultimate Review Alternatives
BuzzHub
buzzhub
A powerful WordPress plugin to collect and display customer reviews with user submissions, multiple layouts, and full control.
Testimonials WP
testimonials-wp
Customizable plugin that creates and displays your Testimonials with shortcodes. Create the Testimonials as an Admin or as a User.
Customer Reviews for WooCommerce
customer-reviews-woocommerce
Customer Reviews for WooCommerce plugin helps you get more sales with social proof. Set up automated review reminders and increase conversion rate.
Testimonial – Testimonial Slider and Showcase Plugin
testimonial-slider-and-showcase
Display customer testimonials beautifully with responsive slider and grid layouts. Build trust and boost conversions with this WordPress testimonial p …
WP Social Ninja – Embed Social Feeds, User Reviews & Chat Widgets
wp-social-reviews
Add Facebook feeds, Instagram feeds, TikTok feeds, Facebook reviews, WhatsApp Chat, Messenger chat, Testimonial, and others using a single dashboard.
WP Ultimate Review Developer Profile
15 plugins · 3.0M total installs
How We Detect WP Ultimate Review
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-ultimate-review/assets/public/css/wp-ultimate-review.css/wp-content/plugins/wp-ultimate-review/assets/public/css/wp-ultimate-review-responsive.css/wp-content/plugins/wp-ultimate-review/assets/public/js/wp-ultimate-review.js/wp-content/plugins/wp-ultimate-review/assets/public/js/magnific-popup.js/wp-content/plugins/wp-ultimate-review/assets/public/js/owl.carousel.js/wp-content/plugins/wp-ultimate-review/assets/public/js/waypoints.js/wp-content/plugins/wp-ultimate-review/assets/public/js/owl.carousel.min.js/wp-content/plugins/wp-ultimate-review/assets/public/js/isotope.min.js+2 more/wp-content/plugins/wp-ultimate-review/assets/public/js/wp-ultimate-review.js/wp-content/plugins/wp-ultimate-review/assets/public/js/magnific-popup.js/wp-content/plugins/wp-ultimate-review/assets/public/js/owl.carousel.js/wp-content/plugins/wp-ultimate-review/assets/public/js/waypoints.js/wp-content/plugins/wp-ultimate-review/assets/public/js/owl.carousel.min.js/wp-content/plugins/wp-ultimate-review/assets/public/js/isotope.min.js+2 morewp-ultimate-review/assets/public/css/wp-ultimate-review.css?ver=wp-ultimate-review/assets/public/css/wp-ultimate-review-responsive.css?ver=wp-ultimate-review/assets/public/js/wp-ultimate-review.js?ver=wp-ultimate-review/assets/public/js/magnific-popup.js?ver=wp-ultimate-review/assets/public/js/owl.carousel.js?ver=wp-ultimate-review/assets/public/js/waypoints.js?ver=wp-ultimate-review/assets/public/js/owl.carousel.min.js?ver=wp-ultimate-review/assets/public/js/isotope.min.js?ver=wp-ultimate-review/assets/public/js/imagesloaded.min.js?ver=wp-ultimate-review/assets/public/js/custom.js?ver=HTML / DOM Fingerprints
wur-single-review-wrapperwur-single-review-metawur-review-content-areawur-review-form-titlewur-review-form-input-wrapperwur-review-form-textarea-wrapperwur-review-form-submit-btnxs-review-btn-submit+9 moredata-wur-review-idWUR_REVIEWwur_review_params/wp-json/wp-ultimate-review/v1/submit-review/wp-json/wp-ultimate-review/v1/load-more-comments[wp-reviews][wp-reviews-rating]