Awesome Testimonials Security & Risk Analysis

wordpress.org/plugins/awesome-testimonials

Integrate a testimonial into your WordPress web site.

50 active installs v2.2.1 PHP + WP 4.0.0+ Updated Aug 1, 2022
auto-rotate-testimonialcustomizable-testimonialtestimonialtestimonialstestimony
63
C · Use Caution
CVEs total1
Unpatched1
Last CVEOct 7, 2025
Safety Verdict

Is Awesome Testimonials Safe to Use in 2026?

Use With Caution

Score 63/100

Awesome Testimonials has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Oct 7, 2025Updated 3yr ago
Risk Assessment

The "awesome-testimonials" v2.2.1 plugin exhibits a mixed security posture. While it has no critical or high severity vulnerabilities in its history, and the static analysis shows no dangerous functions, file operations, or external HTTP requests, there are significant areas of concern. A notable weakness is the complete absence of nonce checks and capability checks, which are fundamental security mechanisms in WordPress. The analysis of SQL queries reveals that only 11% use prepared statements, leaving a substantial portion potentially vulnerable to SQL injection. Furthermore, 35% of output escaping is not properly handled, creating risks of Cross-Site Scripting (XSS). The vulnerability history indicates a medium severity Cross-Site Request Forgery (CSRF) vulnerability that remains unpatched, suggesting a pattern of security oversight that needs immediate attention. Overall, while the plugin avoids some common pitfalls, the lack of essential security controls and the presence of unpatched vulnerabilities present a considerable risk.

Key Concerns

  • Unpatched CVE (Medium Severity)
  • Raw SQL queries (89% not prepared)
  • Unescaped output (35% not escaped)
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
1 published

Awesome Testimonials Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-62933medium · 4.3Cross-Site Request Forgery (CSRF)

Awesome Testimonials <= 2.2.1 - Cross-Site Request Forgery

Oct 7, 2025Unpatched
Version History

Awesome Testimonials Release Timeline

v2.01 CVE
Code Analysis
Analyzed Mar 16, 2026

Awesome Testimonials Code Analysis

Dangerous Functions
0
Raw SQL Queries
17
2 prepared
Unescaped Output
8
15 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

11% prepared19 total queries

Output Escaping

65% escaped23 total outputs
Attack Surface

Awesome Testimonials Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[pra_testimonial] main.php:303
[pra_alltestimonials] main.php:307
WordPress Hooks 7
actionwp_enqueue_scriptsmain.php:52
actionadmin_enqueue_scriptsmain.php:53
actionadmin_menumain.php:131
actioninitmain.php:145
actionadmin_initmain.php:210
actionsave_postmain.php:211
actionwidgets_initmain.php:338
Maintenance & Trust

Awesome Testimonials Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedAug 1, 2022
PHP min version
Downloads4K

Community Trust

Rating100/100
Number of ratings2
Active installs50
Developer Profile

Awesome Testimonials Developer Profile

Prakash

4 plugins · 80 total installs

81
trust score
Avg Security Score
81/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Awesome Testimonials

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/awesome-testimonials/css/pra_testimonial.css/wp-content/plugins/awesome-testimonials/js/jquery.carouFredSel-6.2.1.js/wp-content/plugins/awesome-testimonials/js/pra_testimonials.js/wp-content/plugins/awesome-testimonials/css/admin-style.css
Script Paths
/wp-content/plugins/awesome-testimonials/js/jquery.carouFredSel-6.2.1.js/wp-content/plugins/awesome-testimonials/js/pra_testimonials.js
Version Parameters
awesome-testimonials/css/pra_testimonial.css?ver=awesome-testimonials/js/jquery.carouFredSel-6.2.1.js?ver=awesome-testimonials/js/pra_testimonials.js?ver=awesome-testimonials/css/admin-style.css?ver=

HTML / DOM Fingerprints

CSS Classes
pra_rating_sectionpra_starsrating
Data Attributes
name="pra_ratings"name="pra_designation"
FAQ

Frequently Asked Questions about Awesome Testimonials