Modern e-commerce architectures frequently extend beyond monolithic WordPress themes to embrace headless storefronts (Next.js, Nuxt, Gatsby), mobile native applications (iOS and Android), and custom ERP/CRM data pipelines. ReviewX features a comprehensive, fully authenticated REST API and Webhook Synchronization suite that gives developers programmatic control over reviews, ratings, reminders, and customer feedback.
REST API Base Endpoint
https://yourstore.com/wp-json/reviewx/api/v1/
Core Developer REST API Endpoints
1. Fetch Reviews for a Product
Retrieves a paginated list of approved reviews for a given product or custom post, complete with verified badges, multi-criteria scores, attachments, and admin replies:
GET /wp-json/reviewx/api/v1/storefront/{product_id}/reviews?per_page=10&cursor={cursor}&rating=all
2. Fetch Product Rating Insights & Distribution
Returns pre-aggregated rating totals, average star score, criteria averages, and 1-to-5 star breakdowns for quick rendering on headless product detail pages:
GET /wp-json/reviewx/api/v1/storefront/{product_id}/insight
3. Programmatically Submit a Customer Review
Submits a new customer testimonial. Submissions pass through ReviewX server-side validation guards (anti-spam, reCAPTCHA verification, consent checking, and purchase verification):
POST /wp-json/reviewx/api/v1/storefront/reviews
Content-Type: application/json
X-WP-Nonce: {wp_rest_nonce}
{
"product_id": 124,
"rating": 5,
"title": "Unmatched Build Quality",
"feedback": "Arrived promptly and works exactly as described.",
"reviewer_name": "Jane Doe",
"reviewer_email": "jane@example.com",
"criterias": { "quality": 5, "value": 5 },
"consent": true
}
Real-Time Event Dispatcher & Cloud Webhooks
ReviewX incorporates a non-blocking asynchronous event dispatcher (ReviewX\Sync\Dispatcher) that hooks into WordPress lifecycle events:
- Order Completion: When WooCommerce fires
woocommerce_order_status_completed, an event payload is dispatched to the ReviewX SaaS Cloud to queue automated review reminders. - Review Moderation Events: When comments transition between
approved,pending,spam, ortrash, webhook events update cloud analytics and flush cache transients across all connected storefronts. - Coupon Redemption: When a promotional discount code is used, usage increment events synchronize bi-directionally to enforce single-use restrictions.
Configuring Developer Security & Bot Protection
To protect your API endpoints from automated scrapers and brute-force spam attacks:
- Navigate to ReviewX → Settings → Security (Badge 1).
- Configure Google reCAPTCHA or Math Captcha bot protection (Badge 2).
- Click Save (Badge 3). All programmatic submissions lacking valid CAPTCHA tokens or active session nonces will be securely rejected with an HTTP 422 error.