Advanced Testimonial Carousel For Elementor Security & Risk Analysis

wordpress.org/plugins/advanced-testimonial-carousel-for-elementor

Advanced Testimonial Carousel For Elementor. You can add image, name, describes, title, added Unlimited slider.

2K active installs v3.1.2 PHP 7.4+ WP 5.0+ Updated Dec 8, 2025
elementorelementor-testimonial-carouselelementor-widgetslidertestimonial
100
A · Safe
CVEs total1
Unpatched0
Last CVEApr 22, 2024
Safety Verdict

Is Advanced Testimonial Carousel For Elementor Safe to Use in 2026?

Generally Safe

Score 100/100

Advanced Testimonial Carousel For Elementor has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Apr 22, 2024Updated 5mo ago
Risk Assessment

The plugin "advanced-testimonial-carousel-for-elementor" v3.1.2 presents a mixed security posture. While it demonstrates good practices in areas like SQL query sanitization and output escaping, with 100% of SQL queries using prepared statements and 98% of outputs properly escaped, significant concerns remain due to its attack surface. The plugin exposes two AJAX handlers, both of which lack authentication checks, presenting a clear risk of unauthorized actions being performed. The vulnerability history, while showing no currently unpatched vulnerabilities, includes one past medium severity vulnerability related to missing authorization, which aligns with the identified AJAX handler issues and suggests a recurring pattern of authorization flaws.

The lack of authentication on AJAX endpoints is the most critical finding from the static analysis. This creates a direct pathway for unauthenticated users to potentially trigger sensitive functionality within the plugin. Although taint analysis and code signals indicate no dangerous functions or file operations, and external HTTP requests are absent, the unprotected AJAX endpoints represent a tangible and exploitable risk. The presence of nonces and capability checks on some entry points is a positive indicator, but it is insufficient when other entry points are entirely unprotected. In conclusion, while the plugin has made progress in secure coding practices for certain areas, the critical oversight of unauthenticated AJAX handlers significantly weakens its overall security.

Key Concerns

  • Unprotected AJAX handlers
  • Past medium severity vulnerability (missing authorization)
Vulnerabilities
1 published

Advanced Testimonial Carousel For Elementor Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-32783medium · 5.3Missing Authorization

Advanced Testimonial Carousel for Elementor <= 3.0.0 - Missing Authorization

Apr 22, 2024 Patched in 3.0.1 (8d)
Version History

Advanced Testimonial Carousel For Elementor Release Timeline

v3.1.2Current
v3.1.1
v3.1.0
v3.0.4
v3.0.3
v3.0.2
v3.0.1
v3.0.01 CVE
v2.0.61 CVE
v2.0.51 CVE
v2.0.41 CVE
v2.0.31 CVE
v2.0.21 CVE
v2.0.11 CVE
v2.0.01 CVE
v1.4.01 CVE
v1.3.01 CVE
v1.2.01 CVE
v1.1.01 CVE
v1.0.01 CVE
Code Analysis
Analyzed Mar 16, 2026

Advanced Testimonial Carousel For Elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
63 escaped
Nonce Checks
2
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

98% escaped64 total outputs
Attack Surface
2 unprotected

Advanced Testimonial Carousel For Elementor Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_atc_pro_lincese_ajax_actionsadvanced-testimonial-carousel-for-elementor.php:313
authwp_ajax_atc_pro_setup_addonsadvanced-testimonial-carousel-for-elementor.php:319
WordPress Hooks 14
actionplugins_loadedadvanced-testimonial-carousel-for-elementor.php:105
actionelementor/initadvanced-testimonial-carousel-for-elementor.php:142
actionadmin_noticesadvanced-testimonial-carousel-for-elementor.php:158
actionadmin_noticesadvanced-testimonial-carousel-for-elementor.php:243
actionadmin_noticesadvanced-testimonial-carousel-for-elementor.php:249
actionadmin_noticesadvanced-testimonial-carousel-for-elementor.php:255
actionelementor/widgets/widgets_registeredadvanced-testimonial-carousel-for-elementor.php:285
actionelementor/frontend/after_enqueue_stylesadvanced-testimonial-carousel-for-elementor.php:287
actionelementor/editor/after_enqueue_stylesadvanced-testimonial-carousel-for-elementor.php:293
actionelementor/frontend/after_enqueue_scriptsadvanced-testimonial-carousel-for-elementor.php:298
actionadmin_enqueue_scriptsadvanced-testimonial-carousel-for-elementor.php:310
actionadmin_initadvanced-testimonial-carousel-for-elementor.php:325
actionadmin_noticesadvanced-testimonial-carousel-for-elementor.php:328
actionadmin_initadvanced-testimonial-carousel-for-elementor.php:329
Maintenance & Trust

Advanced Testimonial Carousel For Elementor Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 8, 2025
PHP min version7.4
Downloads33K

Community Trust

Rating70/100
Number of ratings11
Active installs2K
Developer Profile

Advanced Testimonial Carousel For Elementor Developer Profile

Md Ruhel Khan

5 plugins · 3K total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
8 days
View full developer profile
Detection Fingerprints

How We Detect Advanced Testimonial Carousel For Elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/advanced-testimonial-carousel-for-elementor/assets/css/atc-testimonial.css/wp-content/plugins/advanced-testimonial-carousel-for-elementor/assets/css/atc-editor.css/wp-content/plugins/advanced-testimonial-carousel-for-elementor/assets/js/atc-testimonial.js
Script Paths
assets/js/atc-testimonial.js
Version Parameters
advanced-testimonial-carousel-for-elementor/assets/css/atc-testimonial.css?ver=advanced-testimonial-carousel-for-elementor/assets/css/atc-editor.css?ver=advanced-testimonial-carousel-for-elementor/assets/js/atc-testimonial.js?ver=

HTML / DOM Fingerprints

CSS Classes
atc-testimonial-carousel-wrapperatc-single-itematc-testimonial-itematc-testimonial-contentatc-testimonial-author-imageatc-testimonial-author-nameatc-testimonial-author-designationatc-testimonial-rating-stars+5 more
HTML Comments
<!-- START Advanced Testimonial Carousel --><!-- END Advanced Testimonial Carousel --><!-- Advanced Testimonial Carousel For Elementor -->
Data Attributes
data-atc-nav-nextdata-atc-nav-prevdata-atc-paginationdata-atc-loopdata-atc-autoplaydata-atc-items+2 more
JS Globals
atcSwiperVar
Shortcode Output
[advanced_testimonial_carousel
FAQ

Frequently Asked Questions about Advanced Testimonial Carousel For Elementor