Pre-built code blocks

Reviews and testimonials

Reviews — star picker, testimonials, moderation queue

For when the answer to “It shows reviews or testimonials from the public” is yes.

Rebuilt in ~16/20 projects. Takes text from strangers and puts it on your most-trusted page, so it is the easiest place on a small site to get XSS'd — and the easiest place to accidentally publish spam.

Built by hand again in 16 of 20 audited projects before this existed. Each rebuild was another chance to make the mistake below.

A queue of speech bubbles each carrying a row of stars waiting behind a closed gate, with the front one being stamped and passing through onto a broad board above

Skip the rebuild

You do not write this one. It arrives in your project as ordinary source you can read, change and keep, with its audit record and its caveats beside it.

  1. Download the Playground. It is free and runs on your own machine.
  2. Start a new app and tick “It shows reviews or testimonials from the public”.
  3. This block is written in, along with anything else you ticked.

Download the Playground See the other blocks

The mistake it removes

The two failure modes are structural, not stylistic: rendering submitted text as HTML, and publishing on submit because 'pending' felt like day-two work.

What is already handled

Each of these was checked by running the code, not by reading it.

What the audit found

Named rather than summarized. The reasoning behind each one ships inside the block, so it travels with the code instead of living on a page you have to trust.

What you still have to do

A copied file cannot own your secrets, your host or your legal obligations. This is the part the block deliberately does not claim.

What lands in your project

vanilla

  • vanilla/reviews.js

createReviews({ mount, load, limit }) rotates testimonials and returns { refresh, stop, destroy, count } — call destroy() when unmounting. createStarPicker({ mount, onChange }) is a radio group. Call installReviewStyles() or bring your own CSS.

node

  • node/reviews-api.js

createReviewsApi({ store, requireAdmin }) returns { submit, listPublic, listPending, moderate }. The admin routes guard themselves — omit requireAdmin and they answer 503 rather than opening up.

What you supply

Licensed MIT. It is a starting point, not a finished product.

Get it

Download the Playground See the other blocks

Nothing here is locked. The files are yours, in your folder, under a permissive license.

Questions

Is Reviews and testimonials audited?
Yes. A full due-diligence audit was run on 2026-07-17 and the verdict was a pass.
What do I still have to do myself?
Supply requireAdmin (admin-kit's, or your own) and serve over HTTPS. Without requireAdmin, moderate() and listPending() return 503 — the queue is unreachable rather than unguarded, which is safe but also unusable, so an install that skips it has no moderation at all.
How do I get this code?
Download the Playground, start a new app, and tick “It shows reviews or testimonials from the public”. The block is written into your project as ordinary source you can read and edit.

All pre-built code blocks · Learn to build from zero · The coding guide