Mô tả
Universal Reviews is a WordPress review plugin that lets visitors rate and review anything on your site, and gives you one clean place to manage what they say.
Run a WooCommerce shop? A local business? An agency, a course, a directory or a membership site? You probably want the same few things: a simple review form, honest star ratings, a queue to approve reviews, and a good-looking way to show them. This plugin does exactly that, without turning your comments section into a rating system.
Reviews can be attached to posts, pages, custom post types, WooCommerce products, taxonomy terms, users or your whole business. Show them with Elementor widgets, Gutenberg blocks or shortcodes, whichever you prefer.
Reviews live in their own indexed database tables instead of the comments table or post meta. Rating summaries are precomputed, so your review lists and summaries don’t run a COUNT(*) on the reviews table for every page view.
Show your Google reviews too. Connect your own Google Business Profile and display recent Google reviews next to the reviews you collect yourself, with a shortcode, a block or an Elementor widget. Google Reviews is optional: nothing contacts Google unless you set it up, and Universal Reviews is not affiliated with, endorsed by or sponsored by Google.
Free features
- Review Forms & Field Builder — Drag-and-drop form builder with 12+ field types, photo uploads, and per-review-type rules. Import and export templates as JSON, and preview before publishing.
- Review Types — Define Product, Service, Place or any custom type, each with its own moderation policy and schema.org type. Choose whole or half-star rating scales per type.
- Moderation Dashboard — A focused React-powered queue to approve, reject, reply to and manage incoming reviews. Filter, search, sort and bulk-action across large review collections.
- Anti-Abuse Protection — Honeypot, signed time trap, per-IP rate limiting and duplicate-submission blocking — no CAPTCHA required. Sensible defaults out of the box, fully configurable.
- Elementor & Gutenberg — Native Review Form and Reviews List widgets/blocks with live previews and style controls. Shortcodes also available for any theme or page builder.
- Display & Schema.org — Star-rating summaries, filtering, helpful votes, owner replies and verified badges on the front end. AggregateRating JSON-LD output for real search-result rich snippets.
- Google Reviews (optional) — Connect your own Google Business Profile with OAuth (your own Google Cloud project; tokens are encrypted) and show up to 50 recent Google reviews from one location, refreshed daily, with a rating summary, Load more, display options and a Google attribution line. Use the
[unirev_google_reviews]shortcode, the Google Reviews block or the Google Reviews Elementor widget. Shown from a temporary local copy (kept for at most 30 days), so visitors never trigger a Google request. Disconnect any time to delete it. - Built for performance — Dedicated indexed database tables and precomputed rating totals, with server-side filtering and pagination. Stays fast even with large review collections.
Pro Features
adds 9 premium modules on top of everything above.
- Templates — 10 ready-made review forms for shops, restaurants, hotels, events and more. Import any template into a working form in one click.
- Social-Proof Widgets — A floating rating badge for every page, plus a reviews carousel block/shortcode. Server-rendered from a cached summary, so it appears instantly with no layout shift.
- Analytics — Server-side event tracking (created, approved, rejected, replies) with per-day charts. No visitor tracking or cookies involved.
- Migration — Move existing WooCommerce product reviews or rating-carrying comments into Universal Reviews. Batched, resumable, and safe to re-run.
- Webhooks — Signed JSON deliveries for every review event, retried automatically on failure. Full delivery history, with per-endpoint auto-disable after repeated failures.
- AI Assist — AI-generated summaries, sentiment scoring and reply drafts for your reviews. Reviewer names are never sent, and API keys are encrypted at rest.
- Review Requests — Invite customers by email with single-use links that prefill the review form. Track sent, opened and completed requests from one screen.
- Sources — Import reviews from any HTTPS JSON feed, with field mapping and deduplication. Scheduled syncs run safely in the background.
- More Google Reviews — Grid layout with 2–4 columns, carousel, card styles, star colour and rating filter, up to 500 reviews per location, and up to 25 Google locations with a location choice per block, shortcode or widget.
Set it up in about three minutes
- Install and activate the plugin.
- Open Reviews in the admin menu and look over Forms, Review Types and Settings. The defaults are sensible.
- Edit a post, page or product and add
[unirev_reviews show_form=1], or drop in the Reviews List block, or use the Reviews List widget in Elementor. - Visit the page, leave a test review, then approve it under Reviews Reviews.
- Optional: open Reviews Google Reviews to connect your Google Business Profile and show your Google reviews too.
You now have a rating summary, a review list and a review form on the page.
Who is it for?
- Online stores that want customer reviews and star ratings on WooCommerce product pages.
- Local businesses and service providers who want reviews of the business itself, including their Google reviews.
- Agencies, freelancers and course creators collecting testimonials.
- Directories and membership sites where people review listings, users or categories.
- Elementor and block-editor users who want review widgets that match their design.
The everyday workflow stays simple:
- Create or adjust a review form.
- Place the form and review list on your site.
- Moderate incoming reviews.
- Reply, feature or verify reviews when appropriate.
- Show the rating summary and approved reviews to visitors.
Elementor widgets
If you build with Elementor, you don’t need to paste shortcodes any more. Universal Reviews adds two Elementor widgets:
- Review Form – let visitors submit a rating and review right from your Elementor page.
- Reviews List – show approved reviews with the rating summary, star filters, owner replies, a “Load more reviews” button and helpful votes.
Both widgets use the same forms, review types and moderation queue as the shortcodes and blocks, so you can switch between them at any time. Elementor is optional. The plugin works the same without it.
Support and community
- Support Forum – ask questions and report issues.
- Facebook Community – share feedback and follow updates.
Collect reviews
- Create review forms with a drag-and-drop field builder.
- Rating field is included by default and uses a 1–5 star scale, in whole or half steps per review type.
- Let reviewers attach photos (JPEG, PNG, WebP or AVIF) with configurable size and count limits. SVG is never accepted.
- Available field types include rating, heading, text, textarea, select, radio, checkbox, number, email, URL, phone, date and hidden fields.
- Mark fields as required, use half-width layouts, add placeholders and help text, and assign custom CSS classes.
- Add headings and text blocks between fields with configurable HTML tag, size, color and alignment.
- Custom field answers are saved with the review and available to moderators.
- Import and export form templates as JSON.
- Preview forms before publishing them.
- Create review types such as Product, Service or Place, each with its own moderation policy, allowed targets and schema.org type.
Protect submissions
Universal Reviews includes several layers of basic anti-abuse protection without requiring a CAPTCHA.
- Honeypot field.
- Signed time trap with an expiring token.
- Per-IP rate limiting.
- One-review-per-person-per-item protection within a configurable time window.
- Consent checkbox.
- Same-site origin validation.
- Validation of review types and public targets.
- HTTP 429 responses when the configured rate limit is exceeded.
Default protection includes a limit of 12 submissions per 60 minutes per IP and a 72-hour duplicate-review window.
Moderate reviews
The React-powered admin dashboard gives moderators a focused place to work through incoming reviews.
- Filter reviews by status.
- Search and sort reviews.
- Cursor-based pagination for large review collections.
- Approve, reject, mark as spam, trash, feature or delete reviews.
- Apply moderation actions individually or in bulk.
- Reply to reviews as the site owner.
- Mark reviews as verified.
- View the original form answers.
- Keep a review change history.
- Receive a daily digest when reviews are waiting for moderation.
- Disable the digest with the
unirev_digest_enabledfilter.
The moderation interface uses server-side filtering, sorting and pagination so the browser does not need to load the complete review database.
Display reviews
Add reviews to your site with Elementor widgets, Gutenberg blocks or shortcodes.
Available shortcodes:
[unirev_form]
[unirev_reviews]
[unirev_summary]
The Reviews List and Review Form blocks are server-rendered. In the block editor you get a live preview, a dropdown of your saved forms, a searchable picker for posts, products, terms and users, and colour and size controls for the button, fields and star rating.
Front-end features include:
- Rating summary with average rating and total review count.
- 5-to-1 star distribution.
- Star-rating filtering such as 4+ stars.
- “Helpful” vote button on each review.
- “Load more reviews” button for long review lists.
- Photo reviews with image thumbnails.
- Owner replies.
- Verified review badges.
- Keyboard-friendly star selection.
- Inline validation and form status messages.
- Loading and success states.
- Theme-friendly CSS variables using the
--unirev-*naming system.
Plugin CSS and JavaScript are loaded only on pages that actually show a Universal Reviews widget, and in the page head when a post contains the shortcode or block, so your layout doesn’t jump.
SEO and structured data
Universal Reviews can output AggregateRating JSON-LD (the review schema behind star ratings in search results) for supported public review targets.
Structured data is printed only when the page actually displays the target’s review list or summary and the target has approved reviews. The plugin uses the schema.org type configured for the review type and avoids outputting review structured data for private content.
This keeps structured data tied to the content visitors can actually see rather than adding review markup site-wide.
Schema output is built to play nicely with other plugins: it uses the correct worst rating for half-star types, a stable @id, merges multiple reviewed items into one @graph, limits types to a list of valid schema.org types (filter unirev_schema_types), and has a unirev_schema_output filter so you can avoid duplicates with WooCommerce or your SEO plugin.
Important: structured data does not guarantee rich results in search engines. Search engines decide whether and how eligible structured data is displayed.
Performance
Universal Reviews is designed for larger review collections.
- Reviews use dedicated database tables.
- Important review, moderation and lookup queries are indexed.
- Rating totals and distributions are precomputed.
- Public review lists and summaries do not run COUNT(*) on the reviews table for every page view.
- Background jobs support retry, cancellation and recovery from stuck jobs.
- Jobs and logs older than 30 days are automatically purged.
- Optional persistent object caching such as Redis or Memcached can make repeated public queries cheaper, but it is not required.
The architecture is intended to remain practical as a site grows from hundreds of reviews to much larger collections.
Import, export and diagnostics
The Tools area includes:
- Streaming CSV export.
- Streaming JSON export.
- Spreadsheet formula-injection protection during export.
- Batched CSV import with up to 5,000 rows per file.
- Row-level import errors.
- Background jobs.
- Job retry and cancellation.
- Logs.
- Database table-size diagnostics.
- Automatic cleanup of old jobs and logs.
Privacy
Privacy controls are built into the review workflow.
- Reviewer IP addresses are not stored by default.
- WordPress privacy exporter integration.
- WordPress privacy eraser integration.
- Custom form answers are included in privacy handling.
- Erasing personal data anonymises reviewer name, email and IP where applicable while keeping the review text as a business record.
- Optional data-retention settings.
- Review data remains after deactivation.
- Data is deleted on uninstall only when “Delete all data on uninstall” is enabled.
- Multisite sites manage their own uninstall-data setting.
- No telemetry is sent by the plugin.
Always configure retention, consent and privacy settings according to your site’s legal and business requirements.
External services
Universal Reviews works fully offline. The only external service it can contact is Google, and only if you choose to connect Google Reviews (Reviews Google Reviews). Nothing is sent to Google, and no Google code is loaded, otherwise.
When you connect Google Reviews, your server contacts these Google endpoints using your own Google Cloud project and the Google account you authorize:
accounts.google.comandoauth2.googleapis.com— OAuth 2.0 sign-in, token exchange, token refresh and token revocation. Data sent: your OAuth Client ID/Secret, the authorization code and your tokens.mybusinessaccountmanagement.googleapis.com,mybusinessbusinessinformation.googleapis.comandmybusiness.googleapis.com— the Google Business Profile APIs, used to list the accounts and locations you manage and to read reviews for the location you select. Data sent: your access token and the account/location IDs.
Requests happen when you press Sync Now, during the daily scheduled sync, and while you set up the connection — never when a visitor loads a page. If a reviewer has a Google profile photo, visitors’ browsers load that image from Google’s image servers (googleusercontent.com).
Google’s terms: https://policies.google.com/terms — privacy policy: https://policies.google.com/privacy — Business Profile API terms: https://developers.google.com/my-business/content/terms
Google Reviews
Show recent reviews from your Google Business Profile next to your own reviews. Google Reviews is optional and never required for the rest of the plugin.
What you need
- A Google Business Profile you own or manage (verified and active).
- Your own Google Cloud project with the Business Profile APIs enabled and API access approved by Google. Google requires each business to use its own approved project, so Universal Reviews does not ship a shared one.
- An OAuth client ID of type “Web application” with this authorized redirect URI:
https://your-site.example/wp-admin/admin-post.php?action=unirev_google_oauth(the exact URL is shown on the setup screen).
Setup
- Open Reviews Google Reviews.
- Enter your Google Client ID and Client Secret and click Save Credentials.
- Click Connect Google, sign in with the Google account that manages the business, and approve access.
- Choose a location. The first sync runs immediately.
Changing the Google account or credentials: open Reviews Google Reviews and use Change Google account, Edit Client ID & Secret or Disconnect. These are also available on the location screen, so a failing Google request never leaves you stuck. Signing in with a different Google account clears the previous location and its cached reviews.
Free plan limits: one connection and location, up to 50 recent reviews displayed, daily automatic sync plus Sync Now, a basic list layout and basic styling. If your profile has more reviews, only the allowed number is displayed and a note is shown to administrators; the connection keeps working. Multiple locations, higher limits, advanced …
Ảnh màn hình






Khối
Plugin này cung cấp 3 khối.
- Reviews List Display approved reviews for a product, post, term, user or business — with optional star-rating filtering.
- Google Reviews Display recent reviews synchronized from your connected Google Business Profile. Not affiliated with Google.
- Review Form A submission form so visitors can leave a review for a product, post, term, user or business.
Cài đặt
Install from your dashboard (easiest)
- Go to Plugins Add New Plugin.
- Search for Universal Reviews.
- Click Install Now, then Activate.
Upload the ZIP from WordPress admin
- Download the
universal-reviewsplugin ZIP. - In WordPress, go to Plugins Add New Plugin.
- Select Upload Plugin.
- Choose the
universal-reviews.zipfile. - Click Install Now.
- After installation finishes, click Activate Plugin.
Install manually
- Download the plugin ZIP.
- Extract the
universal-reviewsfolder. - Upload the folder to
/wp-content/plugins/. - Open Plugins Installed Plugins in WordPress.
- Find Universal Reviews.
- Click Activate.
After activation
After activation, open Reviews in the WordPress admin menu.
Start with:
- Reviews Forms — review the default form or create another form.
- Reviews Review Types — configure Product, Service, Place or another review type.
- Reviews Settings — check moderation, anti-abuse, display, privacy and notification settings.
- Add a review form and review list using a shortcode or Gutenberg block.
- Submit a test review from the front end.
- Open Reviews Reviews and test the complete moderation workflow.
- Approve the test review and confirm that the review list and summary appear correctly.
For the quickest setup, add this shortcode to a post, page or product:
[unirev_reviews show_form=1]
This displays the review list and enables the form for the current supported target.
Using Elementor? Edit the page, search the widget panel for Reviews List or Review Form, and drag it where you want it.
Requirements: WordPress 6.2 or newer and PHP 7.4 or newer. WooCommerce and Elementor are optional.
Deactivation and uninstall
Deactivating Universal Reviews does not remove review data.
By default, database tables and settings remain available after deactivation. If you want WordPress to remove the plugin’s stored data during uninstall, enable Settings Privacy Delete all data on uninstall before deleting the plugin.
Use this option carefully because uninstall data deletion is intended to be permanent.
Hỏi đáp
-
Does Universal Reviews require WooCommerce?
-
No. WooCommerce is not required.
Reviews can target WordPress posts and custom post types, taxonomy terms, users, the site/business and other supported targets. WooCommerce products are supported as the
productpost type.Universal Reviews does not read WooCommerce orders for purchase verification. A moderator can mark a review as verified from the Reviews screen, and developers can add their own verification logic through the
unirev_verification_providersfilter. -
Can I use Universal Reviews for custom post types?
-
Yes. The
posttarget type can work with WordPress post types, including custom post types, when the target is public and supported by the plugin’s target validation. -
Does Universal Reviews work with Elementor?
-
Yes. Version 1.0.2 adds Elementor widgets for the Review Form and the Reviews List. Drag them onto any Elementor page, template or product layout. They share the same forms, review types and moderation queue as the blocks and shortcodes.
-
Can I use it without a page builder?
-
Yes. Elementor is optional. Universal Reviews also works with the WordPress block editor and with shortcodes, and you don’t need a special theme.
-
How do I add star ratings and customer reviews to a WordPress page?
-
Add
[unirev_reviews show_form=1]to the page, insert the Reviews List block, or drop in the Reviews List widget in Elementor. Visitors will see the rating summary, the approved reviews and the review form. -
How do I show reviews on WooCommerce product pages?
-
WooCommerce products are supported as a review target. Add the shortcode, block or Elementor widget to your product description, product template or product layout. Universal Reviews doesn’t take over the built-in WooCommerce reviews tab.
-
Can visitors upload photos with their review?
-
Yes. Reviewers can attach JPEG, PNG, WebP or AVIF photos, and you control the size and number of photos. SVG uploads are never accepted. Photos that can’t be verified as real images are rejected, and photos are deleted when a review is rejected or marked as spam.
-
Can I collect reviews for my business instead of a page?
-
Yes. Use the
businesstarget type to collect reviews about your company as a whole, then show them anywhere with the same widgets, blocks and shortcodes. -
Can I customize the review form?
-
Yes. The form builder supports multiple field types, required fields, half-width layouts, placeholders, help text, headings, text blocks and custom CSS classes. Form styling uses
--unirev-*CSS variables. -
Can I create different review forms?
-
Yes. Forms can be created and managed from Reviews Forms. Forms can be associated with supported review types and embedded with the form shortcode or Review Form block.
-
Can I use half-star ratings?
-
Yes, since version 1.0.1. Choose Half stars under Star steps when editing a review type in Reviews Review Types. Types default to whole stars (1 to 5).
-
Does the plugin store IP addresses?
-
Not by default. IP storage is disabled by default and can be enabled from the privacy settings when a site needs it.
-
Does the plugin use CAPTCHA?
-
No CAPTCHA is required. Universal Reviews uses a honeypot, signed time trap, rate limiting, duplicate-review protection, consent and request validation.
-
What happens when I deactivate the plugin?
-
Deactivation does not delete reviews, settings or database tables.
Data is removed during uninstall only when Delete all data on uninstall has been enabled in Settings Privacy.
-
Do I need Redis or another object cache?
-
No. Universal Reviews does not require Redis or Memcached.
Rating aggregates are precomputed in a summary table. A persistent object cache can further reduce repeated public queries when available.
-
Does the plugin add review schema automatically?
-
When enabled, Universal Reviews can output AggregateRating JSON-LD for supported targets whose review list or summary is actually displayed and which have approved reviews.
Structured data eligibility does not guarantee a search-engine rich result.
-
Does Universal Reviews guarantee Google star snippets?
-
No. The plugin outputs supported structured data according to its configuration and visible review content, but search engines independently decide whether structured data qualifies for or appears as a rich result.
-
Can visitors mark reviews as helpful?
-
Yes. Version 1.0.2 adds a “Helpful” vote button on each review. Voting can be enabled in the display settings, and votes have their own rate limit.
-
Does the review list have pagination?
-
Yes. Long lists show a “Load more reviews” button that loads the next page of reviews without reloading the page.
-
Does it work with full-page caching?
-
Yes. Review forms and vote buttons on cached pages fetch fresh security tokens when the visitor interacts, so they no longer fail with expired nonces.
-
Will it work with Hindi, Arabic, Chinese and emoji text?
-
Yes. Titles, names, answers and avatar initials are cut on character boundaries, so non-Latin text and emoji are no longer corrupted.
-
Can the business owner reply to reviews?
-
Yes. Moderators with the appropriate capability can add owner replies. Replies are displayed beneath the review on the front end.
-
Can I import existing reviews?
-
Version 1.0.0 includes Universal Reviews CSV import. Import files can contain up to 5,000 rows per file and report row-level errors.
Dedicated migration importers for other review plugins are planned for the Pro roadmap.
-
Do I need to connect Google?
-
No. Google Reviews is optional. Nothing contacts Google unless you set it up.
-
Why do I need my own Google Cloud project?
-
Google’s Business Profile API terms require each business to use its own approved project. Universal Reviews therefore never shares one project between sites: you create the OAuth client, and you authorize access to your own Business Profile.
-
Google says my API access is not approved, or the API is not enabled.
-
Business Profile API access must be requested from Google and approved (the quota for the APIs shows 0 until it is). Then enable the “My Business Account Management API”, “My Business Business Information API” and “Google My Business API” in your project. The plugin shows the exact problem and a recommended action, with technical details you can send to support.
-
Google no longer accepts the saved authorization — usually because access was revoked, the password changed, or the account lost access to the location. Click Reconnect Google.
-
Only some of my Google reviews show.
-
The Free plan displays up to 50 recent reviews. Your connection keeps working and the rest are not deleted from Google.
-
Are my Google reviews stored permanently?
-
No. They are a temporary copy kept for at most 30 days and refreshed daily. Disconnecting deletes them immediately.
-
Google says my server could not be reached, or the location list times out.
-
Your server must be able to make outgoing HTTPS requests to Google (
*.googleapis.comandaccounts.google.com). Ask your host to allow them, then press Try Again. If you connected the wrong account in the meantime, use Change Google account. -
My Google reviews disappeared.
-
Cached Google reviews are removed after 30 days if they are not refreshed. Check Reviews Google Reviews for a sync error, press Sync Now, and make sure WP-Cron is not disabled on your site.
-
Does the plugin send telemetry?
-
No. Universal Reviews does not send telemetry.
-
What happens to privacy data when a review is erased?
-
Universal Reviews integrates with the WordPress privacy exporter and eraser. Personal information such as reviewer name, email and stored IP data can be anonymised while the review text remains as a business record.
-
Where is the source code for the compiled admin app?
-
The admin dashboard (
assets/admin/index.jsandassets/admin/index.css) is compiled from the human-readable TypeScript/React source in theadmin-src/folder, which ships inside the plugin. To rebuild it, runnpm installand thennpm run buildin the plugin folder (esbuild bundles the JavaScript and the Tailwind CLI builds the CSS; seeadmin-src/README.md). The bundle includes React, React DOM, Radix UI, lucide-react, class-variance-authority, clsx and tailwind-merge, all under MIT-compatible licences. The front-end script (assets/admin/frontend.js), the block editor scripts (blocks/*/edit.js) and the PHP are not minified.
Đánh giá
Người đóng góp & Lập trình viên
“Universal Reviews – Ratings, Forms Reviews, Listing Reviews” là mã nguồn mở. Những người sau đã đóng góp vào plugin này.
Những người đóng gópDịch “Universal Reviews – Ratings, Forms Reviews, Listing Reviews” sang ngôn ngữ của bạn.
Muốn tham gia phát triển?
Duyệt code, check out SVN repository, hoặc theo dõi nhật ký phát triển qua RSS.
Nhật ký thay đổi
1.1.0
07 Oct 2026
* New: Google Reviews (optional). Connect your own Google Business Profile with OAuth (your own Google Cloud project; tokens and the client secret are encrypted) and show recent Google reviews from a temporary local copy. Free: one location, up to 50 reviews, daily sync plus Sync Now.
* New: [unirev_google_reviews] shortcode, Google Reviews block and Google Reviews Elementor widget.
* New: Google Reviews display options: layout, reviews per page, rating summary, reviewer name, date, text, Google attribution, rating filter, Load more, star style, size and colour, spacing, text size and button style.
* New (Pro): grid layout with 2–4 columns, carousel, card styles, star colour, rating filter, up to 500 reviews per location, and up to 25 locations with Add location and a location choice per block, shortcode or widget.
* New: Change Google account, Edit Client ID & Secret and Disconnect from the Google Reviews screen, a warning when the last successful sync is old, a Google Reviews card on the Dashboard, and a first-run Getting started checklist.
* Improved: translations. The language template now includes the admin app strings.
1.0.3
- Fixed : Improved and Bug Fixed
- Removed: the admin notice warning that an Nginx server needs manual config to protect the review-photos upload folder (the folder’s own protection still applies; this only removed the heads-up notice).
1.0.2
- New: Review Form block’s “Form” field is a dropdown of your saved forms, and adds full color/size style controls for the button, fields and star rating.
- New: Elementor widgets for Review Form and Reviews List.
- New: “Load more reviews” button on review lists (cursor pagination) and a “Helpful” vote button on each review.
- Added: an admin notice (with the exact config) when the server is Nginx, since the upload folder’s
.htaccessprotection doesn’t apply there. - Improved: schema.org output uses the correct worst rating for half-star types, a stable
@id, merges multiple reviewed items into one@graph, an allow-list of valid types (filterunirev_schema_types) and aunirev_schema_outputfilter to avoid duplicates with WooCommerce or SEO plugins. - Improved: the duplicate-review guard also checks the reviewer’s IP via a privacy-safe one-way hash — works regardless of the “store IP” setting, so a different email no longer bypasses it.
- Improved: Reviews List and Review Form blocks use block API v3, add editor previews, colour and font-size controls, and a searchable picker (posts, products, terms and users) instead of a raw ID field.
- Improved: admin rating-distribution chart is cached in a transient, same as the status-count badge.
- Improved: the public reviews API is now rate-limited per IP, separate from the submission limit; it also no longer runs a total count or resolves target titles, and returns nothing for posts that are no longer public.
- Improved: front-end CSS/JS load in the page head when a post contains the shortcode or block (no layout shift), and rate-limit counters use the persistent object cache when one is available instead of writing database options on every hit.
- Improved: the time-trap token is bound to the visitor’s IP; helpful votes use their own rate-limit bucket instead of the submission quota.
- Improved: the submit error no longer reveals whether an item ID exists.
- Improved: admin menu badge counts are cached in a short-lived transient; identical pending background jobs are no longer queued twice.
- Improved: bulk moderation now uses one lookup and one update per status group instead of several queries per review.
- Fixed: Review Form and Reviews List block previews were unstyled in the editor; they now match the front-end.
- Fixed: titles, names, answers and avatar initials are now cut on character boundaries, so Hindi, Arabic, CJK and emoji text is no longer corrupted.
- Fixed: “Highest rated” pagination skipped half-star (4.5) reviews after the first page.
- Fixed: a new auto-approved review now updates the review count, average rating and schema.org data immediately instead of waiting for WP-Cron.
- Fixed: review forms and vote buttons on full-page-cached pages no longer fail with stale nonce or time-trap tokens; fresh tokens are fetched on interaction.
- Fixed: a rate-limit window of 0 no longer disables the limit; window, reviews-per-page and cron interval settings are now range-limited.
- Privacy: the personal-data eraser also removes log entries containing the reviewer’s email, and vote records older than one year are pruned.
- Security: photos that cannot be verified (unreadable image header, including AVIF) are rejected; photos are deleted when a review is rejected or marked spam.
1.0.1
- New: photo reviews (JPEG, PNG, WebP and AVIF uploads with size and count limits; SVG is never accepted) and optional half-star ratings per review type.
- Improved: spam-check filter, vote nonce, admin REST rate limit and settings/summary caching; fixed empty stars showing as filled in review lists.
1.0.0
- Initial release.
- Dedicated indexed review tables.
[unirev_form],[unirev_reviews]and[unirev_summary]shortcodes.- Reviews List and Review Form Gutenberg blocks.
- Drag-and-drop review form builder.
- Review types with configurable targets and schema.org types.
- Review moderation with bulk actions.
- Owner replies, helpful votes and verified reviews.
- Review history and form-answer inspection.
- Honeypot, signed time trap, rate limiting and duplicate-review protection.
- Streaming CSV/JSON export.
- Batched CSV import with row-level errors.
- Background jobs, logs and diagnostics.
- Precomputed rating summaries and distributions.
- Conditional CSS and JavaScript loading.
- AggregateRating JSON-LD for eligible visible review content.
- WordPress privacy exporter and eraser integration.
- No telemetry.
