Yotpo: Product & Photo Reviews for WooCommerce Security & Risk Analysis

wordpress.org/plugins/yotpo-social-reviews-for-woocommerce

Collect product reviews, photo reviews, site reviews & ratings

2K active installs v1.8.2 PHP + WP 3.5.1+ Updated Dec 12, 2024
reviewssocial-reviewswoocommercewoocommerce-product-reviewswoocommerce-reviews
91
A · Safe
CVEs total1
Unpatched0
Last CVENov 14, 2024
Safety Verdict

Is Yotpo: Product & Photo Reviews for WooCommerce Safe to Use in 2026?

Generally Safe

Score 91/100

Yotpo: Product & Photo Reviews for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Nov 14, 2024Updated 1yr ago
Risk Assessment

The static analysis of yotpo-social-reviews-for-woocommerce v1.8.2 reveals a generally strong security posture. The absence of any identified dangerous functions, unsanitized taint flows, raw SQL queries, or unescaped output are all positive indicators. The plugin also demonstrates good practice by implementing nonce and capability checks on its entry points, although the total number of entry points is zero, suggesting minimal direct exposure. The plugin's use of prepared statements for its SQL queries and proper output escaping further strengthens its security. The single external HTTP request is a minor concern but likely standard for plugin functionality.

However, the plugin's vulnerability history is a significant concern. A past medium-severity Cross-Site Scripting (XSS) vulnerability, though patched, indicates a potential for input sanitization or output encoding weaknesses. The fact that this vulnerability was reported very recently (2024-11-14) suggests that while it has been addressed, the underlying mechanisms that allowed it could still be present or require ongoing vigilance. The absence of any unpatched CVEs is positive, but the history itself warrants attention.

In conclusion, the plugin exhibits strong secure coding practices in its current version regarding direct code vulnerabilities. The primary risk lies in its past vulnerability history, which suggests a need for continued monitoring and robust security testing to prevent recurrence. The limited attack surface and proper use of WordPress security features are strengths, but the past XSS vulnerability tempers an otherwise excellent security assessment.

Key Concerns

  • Known medium severity vulnerability
Vulnerabilities
1

Yotpo: Product & Photo Reviews for WooCommerce Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-9356medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Yotpo: Product & Photo Reviews for WooCommerce <= 1.7.9 - Reflected Cross-Site Scripting

Nov 14, 2024 Patched in 1.7.10 (1d)
Code Analysis
Analyzed Mar 16, 2026

Yotpo: Product & Photo Reviews for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
0
52 escaped
Nonce Checks
5
Capability Checks
4
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

100% escaped52 total outputs
Attack Surface

Yotpo: Product & Photo Reviews for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
filtersafe_style_csstemplates\wc-yotpo-settings.php:181
actionplugins_loadedwc_yotpo.php:17
actioninitwc_yotpo.php:18
actionwoocommerce_order_status_changedwc_yotpo.php:19
actionbefore_woocommerce_initwc_yotpo.php:20
actionadmin_menuwc_yotpo.php:53
actionwp_enqueue_scriptswc_yotpo.php:58
actiontemplate_redirectwc_yotpo.php:59
actionwoocommerce_thankyouwc_yotpo.php:65
filtercomments_openwc_yotpo.php:84
filterposts_wherewc_yotpo.php:433
filterwoocommerce_tab_manager_integration_tab_allowedwc_yotpo.php:529
Maintenance & Trust

Yotpo: Product & Photo Reviews for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedDec 12, 2024
PHP min version
Downloads130K

Community Trust

Rating90/100
Number of ratings190
Active installs2K
Developer Profile

Yotpo: Product & Photo Reviews for WooCommerce Developer Profile

Yotpo

1 plugin · 2K total installs

94
trust score
Avg Security Score
91/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect Yotpo: Product & Photo Reviews for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/yotpo-social-reviews-for-woocommerce/assets/css/bottom-line.css/wp-content/plugins/yotpo-social-reviews-for-woocommerce/assets/css/yotpo-style.css/wp-content/plugins/yotpo-social-reviews-for-woocommerce/assets/js/v2/yotpo_main.js/wp-content/plugins/yotpo-social-reviews-for-woocommerce/assets/js/v2/yotpo_widget_loader.js/wp-content/plugins/yotpo-social-reviews-for-woocommerce/assets/js/v3/yotpo_reviews_widget.js/wp-content/plugins/yotpo-social-reviews-for-woocommerce/assets/js/v3/yotpo_qna_widget.js/wp-content/plugins/yotpo-social-reviews-for-woocommerce/assets/js/v3/yotpo_promoted_products_widget.js/wp-content/plugins/yotpo-social-reviews-for-woocommerce/assets/js/v3/yotpo_reviews_carousel_widget.js+2 more
Script Paths
/wp-content/plugins/yotpo-social-reviews-for-woocommerce/assets/js/v2/yotpo_main.js/wp-content/plugins/yotpo-social-reviews-for-woocommerce/assets/js/v2/yotpo_widget_loader.js/wp-content/plugins/yotpo-social-reviews-for-woocommerce/assets/js/v3/yotpo_reviews_widget.js/wp-content/plugins/yotpo-social-reviews-for-woocommerce/assets/js/v3/yotpo_qna_widget.js/wp-content/plugins/yotpo-social-reviews-for-woocommerce/assets/js/v3/yotpo_promoted_products_widget.js/wp-content/plugins/yotpo-social-reviews-for-woocommerce/assets/js/v3/yotpo_reviews_carousel_widget.js+2 more
Version Parameters
yotpo-social-reviews-for-woocommerce/assets/css/bottom-line.css?ver=yotpo-social-reviews-for-woocommerce/assets/css/yotpo-style.css?ver=yotpo-social-reviews-for-woocommerce/assets/js/v2/yotpo_main.js?ver=yotpo-social-reviews-for-woocommerce/assets/js/v2/yotpo_widget_loader.js?ver=yotpo-social-reviews-for-woocommerce/assets/js/v3/yotpo_reviews_widget.js?ver=yotpo-social-reviews-for-woocommerce/assets/js/v3/yotpo_qna_widget.js?ver=yotpo-social-reviews-for-woocommerce/assets/js/v3/yotpo_promoted_products_widget.js?ver=yotpo-social-reviews-for-woocommerce/assets/js/v3/yotpo_reviews_carousel_widget.js?ver=yotpo-social-reviews-for-woocommerce/assets/js/v3/yotpo_reviews_tab_widget.js?ver=yotpo-social-reviews-for-woocommerce/assets/js/yotpo_core.js?ver=

HTML / DOM Fingerprints

CSS Classes
yotpo-widgetyotpo-reviews-widgetyotpo-qna-widgetyotpo-promoted-products-widgetyotpo-reviews-carousel-widgetyotpo-reviews-tab-widgetyotpo-bottom-line
Data Attributes
data-yotpo-product-iddata-yotpo-app-keydata-yotpo-widget-id
JS Globals
YOTPOyotpo_core_settingsyotpo_review_widget_settingsyotpo_qna_widget_settingsyotpo_promoted_products_widget_settingsyotpo_reviews_carousel_widget_settings+1 more
REST Endpoints
/wp-json/yotpo/v1/reviews/wp-json/yotpo/v1/qna/wp-json/yotpo/v1/promoted_products
Shortcode Output
[yotpo_reviews_widget][yotpo_qna_widget][yotpo_promoted_products_widget][yotpo_reviews_carousel_widget]
FAQ

Frequently Asked Questions about Yotpo: Product & Photo Reviews for WooCommerce