Customer Reviews for WooCommerce
by CusRev · eCommerce
Customer Reviews for WooCommerce plugin helps you get more sales with social proof. Set up automated review reminders and increase conversion rate.
98 health vs 68 average across 5,561 eCommerce plugins
Directory ranking optimization
How it's scored →How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.
Excellent listing optimization
Well tuned across the board
Daily downloads
Since 2022-10-05 · 1,421 days · wp.org + Plugin Pulse archive
30-day downloads
Rolling 30-day volume · peaks are release surges
89.8K
now · peak 203.6K
Directory rank vs rivals
wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you
Rating trend
Star average over time · dips mark rough releases
Update activity
How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.
Release cadence
Actively maintainedHow often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.
45
releases in the last 12 months
2mo ago
latest release · v5.114.0
116
tagged releases on record
Recent releases
What its installed base runs
via wordpress.orgShare of active installs on each version of this plugin. Green is the current release; a big slice on older versions is a user base that has stopped updating.
Estimated active installs
The public count shows “80K+”. Our estimate pins where the real number sits.
Refined from the date this plugin crossed into its current band.
Install history · since 2018-11-16 · 1,460 observations
Estimated value
What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.
Est. annual revenue
Est. acquisition value
No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price.
Details
Latest updates
via wp.org changelogRecent releases and news for this plugin
- — Version 5.115.0 Improvement: WPML compatibility to display replies to reviews in all languages for [cusrev_all_reviews] shortcode Improvement: accessibility improvements for the reviews summary bar 5.115.0
- — Version 5.114.0 Improvement: additional security validations of color code parameters in shortcodes and blocks for Trust Badges Improvement: include review location in [cusrev_reviews_grid] shortcode 5.114.0
- — Version 5.113.0 Improvement: additional security checks to prevent unauthorized uploads of media files via on-site review forms 5.113.0
- — Version 5.112.0 Bug fix: non-unique table/alias 5.112.0
- — Version 5.111.0 Improvement: additional security checks to prevent unauthorized uploads of media files on local review forms 5.111.0
- — Version 5.110.1 Improvement: CSS improvement for compatibility with third-party themes 5.110.1
Known vulnerabilities
via Wordfence Intelligence24 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.
- 2026-07-08 CVE-2026-13771 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 5.113.0 Patched in 5.114.0
- High · 7.2 Customer Reviews for WooCommerce <= 5.110.1 - Unauthenticated Stored Cross-Site Scripting ↗2026-06-24 CVE-2026-56043 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 5.110.1 Patched in 5.111.0
- Medium · 6.1 Customer Reviews for WooCommerce <= 5.101.0 - Reflected Cross-Site Scripting via 'crsearch' ↗2026-04-15 CVE-2026-3355 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 5.101.0 Patched in 5.102.0
- 2026-02-12 CVE-2026-1316 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 5.97.0 Patched in 5.98.0
- 2026-01-06 CVE-2025-14891 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 5.93.1 Patched in 5.94.0
- Medium · 6.4 Customer Reviews for WooCommerce <= 5.80.2 - Unauthenticated Stored Cross-Site Scripting via `author` Parameter ↗2025-07-30 CVE-2025-5720 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 5.80.2 Patched in 5.81.0
- 2024-04-18 CVE-2024-3731 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 5.47.0 Patched in 5.48.0
- High · 8.8 Customer Reviews for WooCommerce <= 5.38.9 - Authenticated (Author+) Arbitrary File Upload ↗2024-01-09 CVE-2023-6979 Unrestricted Upload of File with Dangerous Type Affects <= 5.38.9 Patched in 5.38.10
- Medium · 4.3 Customer Reviews for WooCommerce <= 5.38.1 - Cross-Site Request Forgery via manual review reminders ↗2023-11-19 Missing Authorization Affects < 5.38.2 Patched in 5.38.2
- Medium · 4.3 Customer Reviews for WooCommerce <= 5.38.1 - Missing Authorization via manual review reminders ↗2023-11-19 Missing Authorization Affects < 5.38.2 Patched in 5.38.2
- 2023-10-04 Missing Authorization Affects < 5.36.1 Patched in 5.36.1
- Medium · 6.4 Customer Reviews for WooCommerce <= 5.16.0 - Authenticated (Contributor+) Stored Cross-Site Scripting ↗2023-01-24 CVE-2023-0079 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 5.16.0 Patched in 5.17.0
- High · 8.1 Customer Reviews for WooCommerce <= 5.15.0 - Authenticated (Subscriber+) Local File Inclusion ↗2023-01-23 CVE-2023-0080 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 5.15.0 Patched in 5.16.0
Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.
CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.
Behavioral tests
via WP HiveAutomated install-time checks, tested on PHP 8.1.12 · WP 7.0.1
Languages
via translate.wordpress.orgTranslated into 57 languages, 7 at 90% or more
Plus 33 more locales with partial translations.
Growth timeline
Install-tier crossings we have observed, and how long each tier took to outgrow
- 2025-05-28 70K+ → 80K+ up after 1 days in tier
- 2025-05-27 80K+ → 70K+ down after 1 days in tier
- 2025-05-26 70K+ → 80K+ up after 305 days in tier
- 2024-07-25 60K+ → 70K+ up after 414 days in tier
- 2023-06-07 50K+ → 60K+ up
Competes with
The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).
-
Photo Reviews for WooCommerce 10K+ installs · 4.6★ · 2 shared tags A -
Google for WooCommerce 800K+ installs · 2.8★ · 1 shared tag B
-
WooCommerce PayPal Payments 800K+ installs · 2.9★ · 1 shared tag B -
WooCommerce Stripe Payment Gateway 700K+ installs · 3.1★ · 1 shared tag B -
WooCommerce Tax (formerly WooCommerce Shipping & Tax) 500K+ installs · 2.2★ · 1 shared tag C -
WooCommerce Legacy REST API 400K+ installs · 2.2★ · 1 shared tag D
Embed this report card
Drop a live Pulse card for Customer Reviews for WooCommerce into a readme, a review or a deck. It updates itself.
<iframe src="https://plugins.wpmayor.com/embed/customer-reviews-woocommerce" width="480" height="300" style="border:0" loading="lazy" title="Customer Reviews for WooCommerce — Plugin Pulse"></iframe> Customer Reviews for WooCommerce: 80K+ active installs, 4.8★ (1,529 reviews). Plugin Pulse (WP Mayor), as of 2026-08-25. https://plugins.wpmayor.com/plugin/customer-reviews-woocommerce