Description
The Starfish Reviews (Premium) plugin is aimed at local businesses, marketing agencies, and service providers, with review funnels that create their own URL in WordPress, display satisfaction questions, and redirect happy customers to external review platforms. It helps organize feedback collection, handle negative responses internally, and display positive reviews on the site with more editorial control.
Main Features of Starfish Reviews (Premium)
- Review funnels
Creates feedback pages with an initial question and configurable destinations. - Review links
Directs customers to external platforms based on the response received. - Internal feedback
Records negative comments before publication on public sites. - Review import
Centralizes reviews collected from external platforms for display on the site. - Display filters
Filters reviews by rating, period, and layout settings.
Benefits of Starfish Reviews (Premium)
- More reputation control
Allows managing sensitive feedback before public exposure. - More organized collection
Standardizes review requests by service, product, or support. - Visible social proof
Displays positive reviews directly on WordPress pages. - Clear marketing routine
Makes it easy to include review requests in emails, messages, and campaigns.
Who is Starfish Reviews (Premium) For?
- Local businesses that depend on public reviews to build trust.
- Marketing agencies managing clients’ online reputation.
- Service providers needing to collect feedback after support.
How to Download Starfish Reviews (Premium)
Starfish Reviews (Premium) is available for download here at Ultrapack. After downloading the .zip file, go to Plugins > Add New > Upload Plugin, select the .zip, and activate it in the WordPress dashboard. After activation, set up the funnels in Starfish Reviews.
Starfish Reviews (Premium) fits sites that need to turn customer satisfaction into a predictable online reputation flow. By combining funnels, review destinations, private feedback, and review display, the plugin reduces guesswork in testimonial collection and helps sales, support, and marketing teams work with more organized perception data.
Frequently asked questions
Is Starfish Reviews (Premium) GPL-licensed?
Yes. Starfish Reviews (Premium) is distributed under the GPL (GNU General Public License). You may legally use, modify and redistribute it on as many sites as you want.
Can I use Starfish Reviews (Premium) on multiple sites?
Yes. You can install Starfish Reviews (Premium) on as many sites as you want. Only automatic updates through Ultrapack Auto Updater have a limit: from 3 to 80 sites, depending on the plan.
How much does Starfish Reviews (Premium) cost at Ultrapack?
Starfish Reviews (Premium) costs US$2.99 as a single purchase, and it is also included in the subscription plans starting at US$12/mo (VIP I).
Does Starfish Reviews (Premium) include updates?
Yes. The current version of Starfish Reviews (Premium) is 3.1.28, published at Ultrapack on Sep 22, 2026. Subscribers update straight from the WordPress dashboard with UAU (Ultrapack Auto Updater).
Is Starfish Reviews (Premium) scanned before publication?
Yes. Every version of Starfish Reviews (Premium) goes through a malware scan (ClamAV and YARA rules, at UltraHub) before it is published.
What changed in this version
Version 3.1.28 2026-09-21
- Fixed a faulty success check in profile creation that could treat a failed database insert as successful and return a stale, unrelated ID instead of reporting failure. This previously surfaced much later, and misleadingly, as "Failed to update review summary" when adding a profile with "Scrape for Reviews Now?" enabled.
- `add_profile` now inserts using the same table-prefix convention (`$wpdb->prefix`) as every other method in this class, instead of `$wpdb->base_prefix`. These are identical on a single-site install, but differ on any WordPress multisite subsite, where the mismatch would have inserted the profile into the wrong site's table entirely.
- A profile that genuinely fails to save is now reported correctly and immediately, instead of continuing on to also fail the review summary step.
Version 3.1.27 2026-09-19
- Fixed review profile URL validation ("Validate" button) incorrectly reporting a 403 error for valid Yelp profile URLs. The validation request sent the bare hostname as the User-Agent header instead of a browser User-Agent.
- Yelp and Tripadvisor profile URLs now skip the server-side HTTP validation request entirely once the domain is confirmed authorized. Both sites sit behind bot-protection (DataDome) that blocks server-side requests outright based on the requesting server's IP reputation, so the check could fail for a perfectly valid URL no matter what headers were sent.
Version 3.1.26 2026-09-17
- Testimonials and Collections carousels no longer fail silently under Bootstrap 5; they now initialize via the Bootstrap 5 Carousel API instead of a jQuery plugin call that Bootstrap 5 no longer provides.
- Front-end pages no longer load Bootstrap and jQuery UI dialog/datepicker/sortable assets unconditionally; those now load only in wp-admin or when a Starfish shortcode is actually present, avoiding conflicts with other plugins/themes that use the same generic class names.
- Fixed the review-profile duplicate check, which previously passed the wrong number of arguments to the database query and never detected duplicates.
- The review-profiles admin list and job-id lookups no longer render empty on hosts where the database user lacks CREATE VIEW privileges.
- Cron review scraping no longer misclassifies expired profiles as active and logging spurious errors for them nightly.
- Saving a review profile no longer triggers PHP warnings for unchecked checkboxes or empty optional fields.
- Performance
- The debug log now rotates at 5MB instead of growing unbounded, and routine logging is skipped entirely when logging is disabled in settings.
Version 3.1.25 2026-08-20
- Security
- Fixed unauthenticated exposure of reviewer names, email addresses and phone numbers through the WordPress REST API.
- Feedback records are no longer published to the REST API, and reviewer contact fields now require administrator access.
- Feedback CSV exports are written to a protected location with an unguessable filename instead of the plugin folder.
- Review avatars fetched from third-party platforms are now validated and downloaded through WordPress' safe HTTP API.
- Adding a review profile now requires administrator rights rather than trusting the browser's Referer header.
- Testimonial submissions can no longer create new categories on the site.
- Corrected three admin menu registrations that used a role name where a capability was required.
- Fixed shortcode detection missing the element id when a page contained other markup first.
- Compatibility
- jQuery UI is now loaded from WordPress core rather than a bundled copy, for WordPress 7.1 compatibility.
- Tested against WordPress 7.0.4.
- Performance
- Rewrite rules are no longer regenerated on every admin request.
- Shortcode detection no longer re-renders page content multiple times per request.
- Template rendering now uses a compiled cache instead of recompiling on every view.
- Dashboard counts no longer load every matching post to count them.
Version 3.1.24 2026-07-29
- Compatibility
- Tested against WordPress 7.0.2; declared Requires at least 6.0 and Requires PHP 7.4 in the plugin header.
- Removed all uses of FILTER_SANITIZE_STRING, deprecated as of PHP 8.1.
- Fixed PHP 8 warnings in the logging and migration routines.
- Fixed plugin translations not loading due to an incorrect textdomain path.
- Security
- Fixed a SQL injection in the collection reviews query.
- Fixed SQL injection via the sort order on the Reviews and Review Profiles admin screens.
- Added missing capability checks to eight admin AJAX actions.
- Added missing capability and nonce checks to the review and profile bulk delete actions.
- Fixed stored cross-site scripting in the review details and review profile admin dialogs.
- Fixed cross-site scripting in the plugin log console and in dismissible admin notices.
- Moved the debug log out of the plugin directory to a protected, non-guessable location and removed any previously exposed log file.
- Hardened the review scrape callback endpoint against unsolicited and oversized payloads.
- Review URL validation now uses WordPress' safe HTTP API with TLS verification enabled.
- Fixed profile lookup by job id, which previously never matched a record.
- Fixed collection filter cleanup not running when a review profile was deleted.
- Fixed random sort order in collections.
- Removed a registered AJAX action whose handler did not exist.
Release notes published by the developer.
How to install
Automatic updates: this item is updated by the Ultrapack Auto Updater. With it installed, the new version shows up in your dashboard like any other WordPress update (how to set it up).
- Download the file
starfish-reviews-premium.zip. - In the WordPress dashboard, go to Plugins > Add New > Upload Plugin.
- Select the file
starfish-reviews-premium.zipand click Install Now. - Click Activate.
Stuck on a step? Open a ticket telling us which one you stopped at.

UAU Ready