shouldiuse.io

Categories

VERDICT

Should I use Taggbox?

πŸŽ‰ Losing sales because visitors don't see enough reviews? Add them to your website β†’ forever free - taggbox.com

Depends. Buy Taggbox if you run an ecommerce or marketing site and want an affordable review or social-feed widget. Skip it if you can't tolerate third-party scripts or a WordPress plugin with a CVE history.

Confidence

Medium. Based on ~20 public sources including G2, Capterra, NVD/Wordfence, Shopify, Reddit, and Taggbox's own pages

Ratings

  • Value for money
  • Ease of use
  • Feature depth
  • Support quality
  • Security posture

Pricing

$0

Free

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
Paid widget plansFrom $19/mo

Best for

  • Ecommerce stores on Shopify or BigCommerce
  • Marketers adding social proof widgets
  • WordPress sites wanting review embeds
  • Event social walls

Not for

  • Security-sensitive sites β€” plugin has repeated CVEs
  • Anyone avoiding third-party scripts on every page
  • Teams needing only a simple static review page

Gotchas - check before you buy

high

Keep the WordPress plugin updated β€” missing-authorization and CSRF CVEs affect versions through 3.3

medium

Guess: free tier likely carries branding and display limits; key features gated to paid

medium

Separate product lines (Widget, Commerce, Social Walls) priced separately β€” total spend can creep

low

Third-party script adds an external dependency and load-time risk to every page

Pros and cons

Pros

  • Forever-free plan to start
  • Paid plans start at $19/mo
  • Social feeds, reviews, shoppable video in one platform
  • Native apps for Shopify, BigCommerce, and WordPress
  • Users call it good value versus competitors

Cons

  • WordPress plugin has repeated authorization and CSRF CVEs
  • Capterra rating only 4.0/5
  • Embeds depend on third-party scripts and uptime
  • Domain flagged with 374 infostealer credentials

Sources & method

Analyzed 9/27/2026 - 12 sources - Multiple WordPress plugin CVEs (missing authorization, CSRF); domain flagged with 374 infostealer credentials.

official x3review x5security x3news x1
  • CVE-2024-38754 β€” CSRF vulnerability, Cross-Site Request Forgery vulnerability disclosed in the Taggbox WordPress widget plugin.
  • CVE-2023-33215 β€” Missing authorization, Missing authorization vulnerability in the Taggbox widget plugin.
  • CVE-2023-52225 β€” WordPress plugin <= 3.1, Security vulnerability affecting Taggbox WordPress plugin versions up to 3.1.

Key stats

  • Value for money: 4/5

    Rating

  • $0

    Starting price

  • 12

    Sources

  • Analyzed

  • Value for money: 4/5. Free tier; $19/mo entry; called good value
  • Ease of use: 4/5. No-code embeds; plugin described as simple
  • Feature depth: 4/5. Feeds, reviews, shoppable video, rights management
  • Support quality: 4/5. G2 users describe support as polite, patient
  • Security posture: 2/5. Multiple plugin CVEs plus credential exposure flag
  • 4.0/5 Capterra rating Cited on Taggbox's own overview page
  • $19/mo Starting price Paid widget plans per third-party review
  • Yes Free tier 'Forever free' plan advertised on homepage
  • 841+ Sites using it Per Tomba website directory

Pricing

Free

$0

  • Forever-free plan advertised on homepage
  • Basic widget embedding

Paid widget plans

From $19/mo

  • Third-party review cites $19/mo entry
  • Paid features and higher limits

Security

Multiple WordPress plugin CVEs (missing authorization, CSRF); domain flagged with 374 infostealer credentials.

  • CVE-2024-38754 β€” CSRF vulnerabilityCross-Site Request Forgery vulnerability disclosed in the Taggbox WordPress widget plugin.
  • CVE-2023-33215 β€” Missing authorizationMissing authorization vulnerability in the Taggbox widget plugin.10
  • CVE-2023-52225 β€” WordPress plugin <= 3.1Security vulnerability affecting Taggbox WordPress plugin versions up to 3.1.

What users say

Independent feedback is positive but sparse β€” users cite good value, patient support, and ease versus rivals.

β€œThey are polite, patient”
G2 review

Companies that use it

  • Bose Professional
  • The Leela
  • QPS Employment
  • Reina Olga
Full analysis

Based on ~20 public sources including G2, Capterra, NVD/Wordfence, Shopify, Reddit, and Taggbox's own pages

Free/cheap social-proof widgets fine for stores; WordPress plugin CVE history scares off security-sensitive buyers.

Methodology

Based on ~20 public sources including G2, Capterra, NVD/Wordfence, Shopify, Reddit, and Taggbox's own pages

Sources

  1. Taggbox homepagetaggbox.com
    official
  2. official
  3. official
  4. review
  5. review
  6. review
  7. review
  8. review
  9. security
  10. security
  11. security
  12. news

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.