
Yelp Bar Security & Risk Analysis
wordpress.org/plugins/yelp-barA powerful bar that shows Yelp Rating & Reviews at the top of any WordPress theme, provides instant credibility.
Is Yelp Bar Safe to Use in 2026?
Generally Safe
Score 85/100Yelp Bar has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "yelp-bar" plugin version 1.3 exhibits a concerning security posture despite its limited attack surface and lack of known vulnerabilities. While it boasts zero AJAX handlers, REST API routes, shortcodes, or cron events, and performs no file operations or external HTTP requests (beyond one, which is not detailed), the static analysis reveals significant shortcomings in secure coding practices. A critical area of concern is the complete absence of output escaping for all 21 identified output points. This leaves the plugin highly susceptible to Cross-Site Scripting (XSS) vulnerabilities, where malicious code could be injected and executed in users' browsers. Furthermore, the lack of nonce checks and capability checks for its entry points (even though there are none reported) is a general weakness that would be problematic if new entry points were added without proper security. The plugin's vulnerability history being clean is a positive sign, but it cannot negate the immediate risks posed by the unescaped output. Therefore, while the attack surface is currently minimal, the plugin's internal coding practices present a substantial risk that needs immediate remediation.
Key Concerns
- 0% output escaping for 21 outputs
- No capability checks for entry points
- No nonce checks for entry points
Yelp Bar Security Vulnerabilities
Yelp Bar Code Analysis
Output Escaping
Yelp Bar Attack Surface
WordPress Hooks 7
Maintenance & Trust
Yelp Bar Maintenance & Trust
Maintenance Signals
Community Trust
Yelp Bar Alternatives
Widgets for Yelp Reviews
reviews-widgets-for-yelp
Embed Yelp reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Yelp reviews.
Widget for Google Reviews
business-reviews-wp
Shortcode and widget for Google Reviews. Display Google Business Reviews on your WordPress website to increase user confidence and SEO.
Get Google Reviews
get-google-reviews
Get your Google Reviews and display them on your website. Easily and without needing an API key.
Display Yelp Widget
display-yelp-widget
Displays your business's Yelp rating and reviews.
RicReviews
ricreviews
Display Google Places reviews on your WordPress site using a simple shortcode. Fetches reviews from Google Places API (New).
Yelp Bar Developer Profile
3 plugins · 340 total installs
How We Detect Yelp Bar
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/yelp-bar/css/yelpbar.cssyelpbar.css?ver=yelpadmin.css?ver=HTML / DOM Fingerprints
yelpstatusyelpapi