Yelp Reviews Ticker Security & Risk Analysis

wordpress.org/plugins/yelp-reviews-ticker

Yelp Reviews Ticker is an easy to use widget that allows you to show your business yelp reviews.

100 active installs v2.1 PHP + WP 3.3+ Updated Mar 19, 2014
reviewsyelpyelp-apiyelp-business-listingsyelp-reviews
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Yelp Reviews Ticker Safe to Use in 2026?

Generally Safe

Score 85/100

Yelp Reviews Ticker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The 'yelp-reviews-ticker' v2.1 plugin exhibits a strong security posture based on the provided static analysis. The complete absence of identified entry points like AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface. Furthermore, the code shows good practices with no dangerous functions, all SQL queries utilizing prepared statements, and a reasonable output escaping rate. The plugin also correctly leverages capability checks for its operations and avoids bundled libraries.

While the static analysis did not reveal any critical or high-severity issues in taint flows, the low rate of output escaping (72%) for 25 outputs presents a potential concern. This means that roughly 7 outputs might not be properly sanitized before being displayed to users, potentially leading to cross-site scripting (XSS) vulnerabilities if the data originates from an untrusted source. The lack of any recorded vulnerabilities in its history is a positive indicator of past security diligence. However, the absence of nonce checks, while not explicitly tied to any current entry points, is a general security best practice that should ideally be implemented if any user-facing interactions were to be introduced.

In conclusion, 'yelp-reviews-ticker' v2.1 appears to be a securely coded plugin with a minimal attack surface and good adherence to secure coding practices, particularly concerning database interactions. The primary area for improvement lies in ensuring all output is consistently and properly escaped to mitigate potential XSS risks, even in the absence of immediately exploitable vulnerabilities.

Key Concerns

  • Unescaped output potential
  • No nonce checks implemented
Vulnerabilities
None known

Yelp Reviews Ticker Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Yelp Reviews Ticker Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
18 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

72% escaped25 total outputs
Attack Surface

Yelp Reviews Ticker Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionwp_enqueue_scriptsyrt.php:425
actionwidgets_inityrt.php:428
Maintenance & Trust

Yelp Reviews Ticker Maintenance & Trust

Maintenance Signals

WordPress version tested3.7.41
Last updatedMar 19, 2014
PHP min version
Downloads10K

Community Trust

Rating62/100
Number of ratings7
Active installs100
Developer Profile

Yelp Reviews Ticker Developer Profile

flaviodj

1 plugin · 100 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Yelp Reviews Ticker

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/yelp-reviews-ticker/images/miniMapLogo.png/wp-content/plugins/yelp-reviews-ticker/images/rating.png/wp-content/plugins/yelp-reviews-ticker/images/yelp_logo_50x25.png
Version Parameters
yelp-reviews-ticker/style.css?ver=yelp-reviews-ticker/yrt.js?ver=

HTML / DOM Fingerprints

CSS Classes
yrtstars_0_lyrtstars_1_lyrtstars_1h_lyrtstars_2_lyrtstars_2h_lyrtstars_3_lyrtstars_3h_lyrtstars_4_l+18 more
HTML Comments
<!-- Start Yelp Reviews Ticker jQuery --><!-- End Yelp Reviews Ticker jQuery -->
Data Attributes
id="ticker_"id="yrtcssmarkup"id="ticker_"id="yrtFoot"data-speeddata-pause+4 more
JS Globals
jQuery
FAQ

Frequently Asked Questions about Yelp Reviews Ticker