
Yelp Reviews Ticker Security & Risk Analysis
wordpress.org/plugins/yelp-reviews-tickerYelp Reviews Ticker is an easy to use widget that allows you to show your business yelp reviews.
Is Yelp Reviews Ticker Safe to Use in 2026?
Generally Safe
Score 85/100Yelp Reviews Ticker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'yelp-reviews-ticker' v2.1 plugin exhibits a strong security posture based on the provided static analysis. The complete absence of identified entry points like AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface. Furthermore, the code shows good practices with no dangerous functions, all SQL queries utilizing prepared statements, and a reasonable output escaping rate. The plugin also correctly leverages capability checks for its operations and avoids bundled libraries.
While the static analysis did not reveal any critical or high-severity issues in taint flows, the low rate of output escaping (72%) for 25 outputs presents a potential concern. This means that roughly 7 outputs might not be properly sanitized before being displayed to users, potentially leading to cross-site scripting (XSS) vulnerabilities if the data originates from an untrusted source. The lack of any recorded vulnerabilities in its history is a positive indicator of past security diligence. However, the absence of nonce checks, while not explicitly tied to any current entry points, is a general security best practice that should ideally be implemented if any user-facing interactions were to be introduced.
In conclusion, 'yelp-reviews-ticker' v2.1 appears to be a securely coded plugin with a minimal attack surface and good adherence to secure coding practices, particularly concerning database interactions. The primary area for improvement lies in ensuring all output is consistently and properly escaped to mitigate potential XSS risks, even in the absence of immediately exploitable vulnerabilities.
Key Concerns
- Unescaped output potential
- No nonce checks implemented
Yelp Reviews Ticker Security Vulnerabilities
Yelp Reviews Ticker Code Analysis
Output Escaping
Yelp Reviews Ticker Attack Surface
WordPress Hooks 2
Maintenance & Trust
Yelp Reviews Ticker Maintenance & Trust
Maintenance Signals
Community Trust
Yelp Reviews Ticker Alternatives
Reviews Widgets for Google, Yelp & TripAdvisor
fb-reviews-widget
Combine Facebook recommendations with Google, Yelp and TripAdvisor reviews in a widget, block or shortcode. Build a trusted website!
Widgets for Yelp Reviews
reviews-widgets-for-yelp
Embed Yelp reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Yelp reviews.
Widget for Yelp Reviews
widget-yelp-reviews
Yelp reviews widget and shortcode! Shows Yelp business reviews on your WordPress website to increase user trust and SEO.
Review Map by RevuKangaroo
review-map-by-revukangaroo
Show off your customer's online reviews with Review Map by Revukangaroo.
Proton Reviews
proton-reviews
Proton Reviews is the Best Reviews Funnel for Google and Yelp
Yelp Reviews Ticker Developer Profile
1 plugin · 100 total installs
How We Detect Yelp Reviews Ticker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/yelp-reviews-ticker/images/miniMapLogo.png/wp-content/plugins/yelp-reviews-ticker/images/rating.png/wp-content/plugins/yelp-reviews-ticker/images/yelp_logo_50x25.pngyelp-reviews-ticker/style.css?ver=yelp-reviews-ticker/yrt.js?ver=HTML / DOM Fingerprints
yrtstars_0_lyrtstars_1_lyrtstars_1h_lyrtstars_2_lyrtstars_2h_lyrtstars_3_lyrtstars_3h_lyrtstars_4_l+18 more<!-- Start Yelp Reviews Ticker jQuery --><!-- End Yelp Reviews Ticker jQuery -->id="ticker_"id="yrtcssmarkup"id="ticker_"id="yrtFoot"data-speeddata-pause+4 morejQuery