Advanced WP Testimonial Security & Risk Analysis

wordpress.org/plugins/advanced-wp-testimonial

Easily Manage the Testimonials with WordPress Site

10 active installs v1.0 PHP + WP 3.0+ Updated Dec 9, 2012
advanced-testimonialtestimonialwp-testimonial
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Advanced WP Testimonial Safe to Use in 2026?

Generally Safe

Score 85/100

Advanced WP Testimonial has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 13yr ago
Risk Assessment

The 'advanced-wp-testimonial' v1.0 plugin exhibits a generally positive security posture, with a clean vulnerability history and no reported CVEs. The static analysis reveals a small attack surface with zero entry points, and importantly, zero unprotected entry points. The plugin also correctly utilizes prepared statements for its single SQL query and performs capability checks, indicating adherence to good security practices in these areas. However, a significant concern arises from the taint analysis, which identified three flows with unsanitized paths. While no critical or high severity issues were flagged in this taint analysis, the presence of unsanitized paths, even if currently not leading to exploitable vulnerabilities, represents a potential risk that could be leveraged if other conditions were met.

Further review of the code signals shows that only 19% of outputs are properly escaped, which is a substantial weakness. This low rate of output escaping, combined with the unsanitized paths, could lead to cross-site scripting (XSS) vulnerabilities, especially if user-supplied data is involved in any of the unescaped outputs or unsanitized paths. The lack of nonce checks is also a notable omission, particularly in conjunction with the potential for unsanitized inputs. While the plugin has a history of being secure, this version shows concerning trends in input sanitization and output escaping that require immediate attention to maintain its good security record.

Key Concerns

  • Flows with unsanitized paths
  • Low output escaping rate
  • Missing nonce checks
Vulnerabilities
None known

Advanced WP Testimonial Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Advanced WP Testimonial Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
69
16 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

19% escaped85 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

4 flows3 with unsanitized paths
awt_clientmeta_form (html\client_meta_box.php:3)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Advanced WP Testimonial Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actioninitinit.php:26
actionadmin_initinit.php:27
actionwidgets_initinit.php:28
actionadmin_headinit.php:29
actionadmin_menuinit.php:30
actionadd_meta_boxesinit.php:31
actionsave_postinit.php:32
actiontemplate_redirectinit.php:33
filtermanage_edit-awt_testimonial_columnsinit.php:137
actionmanage_awt_testimonial_posts_custom_columninit.php:138
Maintenance & Trust

Advanced WP Testimonial Maintenance & Trust

Maintenance Signals

WordPress version tested3.4.2
Last updatedDec 9, 2012
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Advanced WP Testimonial Developer Profile

anthakkar08

2 plugins · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Advanced WP Testimonial

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/advanced-wp-testimonial/css/main.css/wp-content/plugins/advanced-wp-testimonial/js/main.js
Script Paths
js/main.js
Version Parameters
advanced-wp-testimonial/js/main.js?ver=

HTML / DOM Fingerprints

CSS Classes
awt-testimonial-listawt-testimonial-item
Data Attributes
data-awt-id
JS Globals
awt_testimonial
Shortcode Output
[awt_testimonial][awt_testimonial id=
FAQ

Frequently Asked Questions about Advanced WP Testimonial