
Advanced Testimonial Security & Risk Analysis
wordpress.org/plugins/advanced-testimonialA general lightweight, easy-to-use slider plugin.
Is Advanced Testimonial Safe to Use in 2026?
Generally Safe
Score 100/100Advanced Testimonial has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'advanced-testimonial' plugin v2.0.0 exhibits a generally good security posture, with a strong emphasis on secure coding practices. The static analysis reveals a limited attack surface with all identified entry points (AJAX handlers, shortcodes) appearing to have appropriate authentication and capability checks. Furthermore, the complete absence of direct SQL queries, relying solely on prepared statements, is a significant strength, as is the limited number of file operations and external HTTP requests. The plugin also demonstrates good output escaping practices for the majority of its outputs.
However, a notable area for concern is the output escaping efficiency. While 76% of outputs are properly escaped, this still leaves 24% unescaped, which could potentially lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled carefully within those unescaped portions. The plugin also bundles jQuery v3.3.1, which is an older version and might be susceptible to known vulnerabilities if specific exploits targeting that version exist. The vulnerability history is a strong positive, showing no recorded CVEs, which suggests a history of diligent security practices by the developers. Despite the minor concerns around unescaped output and the bundled library version, the plugin's overall security is robust due to its secure handling of critical areas like SQL and authentication.
Key Concerns
- Unescaped output (24%)
- Bundled outdated library (jQuery v3.3.1)
Advanced Testimonial Security Vulnerabilities
Advanced Testimonial Code Analysis
Bundled Libraries
Output Escaping
Advanced Testimonial Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 57
Maintenance & Trust
Advanced Testimonial Maintenance & Trust
Maintenance Signals
Community Trust
Advanced Testimonial Alternatives
You can quote me on that
you-can-quote-me-on-that
The quickest and easiest way to create testimonial sliders.
Master Slider – Responsive Touch Slider
master-slider
Build SEO friendly sliders fast and easy with touch swipe navigation that works smoothly across all devices.
Real Testimonials – Testimonial Slider, Collect Customer Reviews and Video Testimonials
testimonial-free
A Customizable Testimonial plugin to Automate Collecting, Filtering, and Publishing Customer Reviews. Testimonial Slider, Grid & More to Grow Sales
Testimonial – Testimonial Slider and Showcase Plugin
testimonial-slider-and-showcase
Display customer testimonials beautifully with responsive slider and grid layouts. Build trust and boost conversions with this WordPress testimonial p …
Serious Slider
cryout-serious-slider
Serious Slider is a free highly efficient SEO friendly fully translatable accessibility ready image slider for WordPress. Seriously!
Advanced Testimonial Developer Profile
3 plugins · 30 total installs
How We Detect Advanced Testimonial
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/advanced-testimonial/css/testimonial.css/wp-content/plugins/advanced-testimonial/css/testimonial_carousel.css/wp-content/plugins/advanced-testimonial/js/testimonial-carousel.js/wp-content/plugins/advanced-testimonial/js/testimonial-frontend.js/wp-content/plugins/advanced-testimonial/js/testimonial-carousel.js/wp-content/plugins/advanced-testimonial/js/testimonial-frontend.jsadvanced-testimonial/css/testimonial.css?ver=advanced-testimonial/css/testimonial_carousel.css?ver=advanced-testimonial/js/testimonial-carousel.js?ver=advanced-testimonial/js/testimonial-frontend.js?ver=HTML / DOM Fingerprints
testimonial-carousel-wraptestimonial-carouseltestimonial-itemdata-testimonial-idtestimonialCarousel[testimonial-carousel][testimonial_carousel]