Advanced Testimonials Security & Risk Analysis

wordpress.org/plugins/advanced-testimonials

Awesome testimonials plugin easy to create and embed.

0 active installs v1.0.0 PHP 5.2+ WP 4.5.0+ Updated Mar 7, 2018
advanced-testimonialsclientcodeincepttestimonialtestimonials
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Advanced Testimonials Safe to Use in 2026?

Generally Safe

Score 85/100

Advanced Testimonials has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The "advanced-testimonials" v1.0.0 plugin exhibits a generally good security posture based on the provided static analysis. It has no recorded vulnerabilities and demonstrates several positive security practices, including the absence of dangerous functions, file operations, and external HTTP requests. Notably, all SQL queries utilize prepared statements, and nonce and capability checks are implemented, indicating an awareness of fundamental WordPress security principles.

However, a significant concern arises from the limited output escaping. With only 20% of the total output properly escaped, there is a considerable risk of Cross-Site Scripting (XSS) vulnerabilities. This is particularly worrying given that there are 10 output points. The lack of taint analysis results also means that potential vulnerabilities through chained or complex attack vectors remain unevaluated, though the limited attack surface might mitigate this to some extent.

While the plugin has no historical vulnerabilities, this alone does not guarantee future security. The current version's weakness in output escaping presents a clear and present danger that needs immediate attention. In conclusion, the plugin has a solid foundation in preventing common attack types, but the severe lack of output sanitization is a critical flaw that significantly lowers its overall security rating.

Key Concerns

  • Insufficient output escaping (80% unescaped)
Vulnerabilities
None known

Advanced Testimonials Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Advanced Testimonials Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Advanced Testimonials Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
2 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

20% escaped10 total outputs
Attack Surface

Advanced Testimonials Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[advanced_testimonials_slider] public/class-advanced-testimonial-public.php:55
WordPress Hooks 9
actioninitadmin/class-advanced-testimonial-admin.php:54
actioninitadmin/class-advanced-testimonial-admin.php:55
actionadd_meta_boxesadmin/class-advanced-testimonial-admin.php:56
actionsave_post_advtestimonialsadmin/class-advanced-testimonial-admin.php:57
actionplugins_loadedincludes/class-advanced-testimonial.php:142
actionadmin_enqueue_scriptsincludes/class-advanced-testimonial.php:157
actionadmin_enqueue_scriptsincludes/class-advanced-testimonial.php:158
actionwp_enqueue_scriptsincludes/class-advanced-testimonial.php:173
actionwp_enqueue_scriptsincludes/class-advanced-testimonial.php:174
Maintenance & Trust

Advanced Testimonials Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedMar 7, 2018
PHP min version5.2
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

Advanced Testimonials Developer Profile

codeincept

4 plugins · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Advanced Testimonials

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/advanced-testimonials/public/css/advanced-testimonials.css/wp-content/plugins/advanced-testimonials/public/js/advanced-testimonials.js
Script Paths
/wp-content/plugins/advanced-testimonials/public/js/advanced-testimonials.js
Version Parameters
advanced-testimonials/public/css/advanced-testimonials.css?ver=advanced-testimonials/public/js/advanced-testimonials.js?ver=

HTML / DOM Fingerprints

CSS Classes
ci-advanced-testimonials-wrapper
JS Globals
window.ci_advanced_testimonials_params
Shortcode Output
[advanced_testimonials]
FAQ

Frequently Asked Questions about Advanced Testimonials