
Advanced Testimonials Security & Risk Analysis
wordpress.org/plugins/advanced-testimonialsAwesome testimonials plugin easy to create and embed.
Is Advanced Testimonials Safe to Use in 2026?
Generally Safe
Score 85/100Advanced Testimonials has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "advanced-testimonials" v1.0.0 plugin exhibits a generally good security posture based on the provided static analysis. It has no recorded vulnerabilities and demonstrates several positive security practices, including the absence of dangerous functions, file operations, and external HTTP requests. Notably, all SQL queries utilize prepared statements, and nonce and capability checks are implemented, indicating an awareness of fundamental WordPress security principles.
However, a significant concern arises from the limited output escaping. With only 20% of the total output properly escaped, there is a considerable risk of Cross-Site Scripting (XSS) vulnerabilities. This is particularly worrying given that there are 10 output points. The lack of taint analysis results also means that potential vulnerabilities through chained or complex attack vectors remain unevaluated, though the limited attack surface might mitigate this to some extent.
While the plugin has no historical vulnerabilities, this alone does not guarantee future security. The current version's weakness in output escaping presents a clear and present danger that needs immediate attention. In conclusion, the plugin has a solid foundation in preventing common attack types, but the severe lack of output sanitization is a critical flaw that significantly lowers its overall security rating.
Key Concerns
- Insufficient output escaping (80% unescaped)
Advanced Testimonials Security Vulnerabilities
Advanced Testimonials Release Timeline
Advanced Testimonials Code Analysis
Output Escaping
Advanced Testimonials Attack Surface
Shortcodes 1
WordPress Hooks 9
Maintenance & Trust
Advanced Testimonials Maintenance & Trust
Maintenance Signals
Community Trust
Advanced Testimonials Alternatives
Testimonial Grid and Testimonial Slider plus Carousel with Rotator Widget
wp-testimonial-with-widget
A quick, easy way to add and display responsive, clean client's testimonial on your website using a shortcode, widget or Gutenberg block.
CPO Content Types
cpo-content-types
Add support for special content types in your website, such as a portfolio, features, and slides.
Gutena Testimonial Slider
gutena-testimonial
This block allows you to display client testimonial slider on websites. This plugin provides a user-friendly interface to add, manage, and display tes …
Super Testimonial – Testimonial & Customer Review Slider Plugin for WordPress
super-testimonial
Testimonials are easy to use the plugin that allows users to add Testimonials to the sidebar, as a widget, or to embed testimonials into a Page or Pos …
Testimonial Customer Feedback
testimonial-maker
Display client testimonials with customizable layouts, slider effects, and responsive design. Simple setup with shortcode support.
Advanced Testimonials Developer Profile
4 plugins · 20 total installs
How We Detect Advanced Testimonials
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/advanced-testimonials/public/css/advanced-testimonials.css/wp-content/plugins/advanced-testimonials/public/js/advanced-testimonials.js/wp-content/plugins/advanced-testimonials/public/js/advanced-testimonials.jsadvanced-testimonials/public/css/advanced-testimonials.css?ver=advanced-testimonials/public/js/advanced-testimonials.js?ver=HTML / DOM Fingerprints
ci-advanced-testimonials-wrapperwindow.ci_advanced_testimonials_params[advanced_testimonials]