
Advanced WP Testimonial Security & Risk Analysis
wordpress.org/plugins/advanced-wp-testimonialEasily Manage the Testimonials with WordPress Site
Is Advanced WP Testimonial Safe to Use in 2026?
Generally Safe
Score 85/100Advanced WP Testimonial has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'advanced-wp-testimonial' v1.0 plugin exhibits a generally positive security posture, with a clean vulnerability history and no reported CVEs. The static analysis reveals a small attack surface with zero entry points, and importantly, zero unprotected entry points. The plugin also correctly utilizes prepared statements for its single SQL query and performs capability checks, indicating adherence to good security practices in these areas. However, a significant concern arises from the taint analysis, which identified three flows with unsanitized paths. While no critical or high severity issues were flagged in this taint analysis, the presence of unsanitized paths, even if currently not leading to exploitable vulnerabilities, represents a potential risk that could be leveraged if other conditions were met.
Further review of the code signals shows that only 19% of outputs are properly escaped, which is a substantial weakness. This low rate of output escaping, combined with the unsanitized paths, could lead to cross-site scripting (XSS) vulnerabilities, especially if user-supplied data is involved in any of the unescaped outputs or unsanitized paths. The lack of nonce checks is also a notable omission, particularly in conjunction with the potential for unsanitized inputs. While the plugin has a history of being secure, this version shows concerning trends in input sanitization and output escaping that require immediate attention to maintain its good security record.
Key Concerns
- Flows with unsanitized paths
- Low output escaping rate
- Missing nonce checks
Advanced WP Testimonial Security Vulnerabilities
Advanced WP Testimonial Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Advanced WP Testimonial Attack Surface
WordPress Hooks 10
Maintenance & Trust
Advanced WP Testimonial Maintenance & Trust
Maintenance Signals
Community Trust
Advanced WP Testimonial Alternatives
Simple WP Testimonials
simple-wp-testimonials
Simple WP Testimonials is a plugin that allows you to manage and display testimonials for your blog.
Tg Testimonials – WordPress Testimonial Slider Plugin
tg-testimonials
TG Testimonials are simply the most effective WordPress plugin to present your testimonials in a beautiful way on your website.
Viavi WP Testimonials
viavi-wp-testimonials
Viavi WordPress Testimonials is a plugin that allows you to manage and display testimonials for your blog, product or service.
Advanced Testimonial
advanced-testimonial
A general lightweight, easy-to-use slider plugin.
Best Slider Testimonial
best-slider-testimonial
Best Slider Testimonial is a WordPress plugin to display your client review or testimonial in your WordPress website.
Advanced WP Testimonial Developer Profile
2 plugins · 20 total installs
How We Detect Advanced WP Testimonial
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/advanced-wp-testimonial/css/main.css/wp-content/plugins/advanced-wp-testimonial/js/main.jsjs/main.jsadvanced-wp-testimonial/js/main.js?ver=HTML / DOM Fingerprints
awt-testimonial-listawt-testimonial-itemdata-awt-idawt_testimonial[awt_testimonial][awt_testimonial id=