
B Testimonial – Customer Testimonials in Custom Layouts Security & Risk Analysis
wordpress.org/plugins/b-testimonialTestimonial slider are an important part of any website. You can add as many as testimonial carousel you want easily.
Is B Testimonial – Customer Testimonials in Custom Layouts Safe to Use in 2026?
Generally Safe
Score 99/100B Testimonial – Customer Testimonials in Custom Layouts has a strong security track record. Known vulnerabilities have been patched promptly.
The b-testimonial plugin, version 1.2.4, presents a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for SQL queries and having a high percentage of properly escaped output. The absence of dangerous functions, file operations, and bundled libraries also contributes to a generally safer codebase. The fact that there are no currently unpatched CVEs is also a strong indicator of responsible maintenance.
However, significant concerns arise from the attack surface. With 10 total entry points, 4 of which lack authentication checks, there is a considerable risk of unauthorized access or actions being performed. Specifically, the presence of unprotected AJAX handlers is a prime area for potential exploitation. While the taint analysis didn't reveal critical or high severity issues, the 3 flows with unsanitized paths warrant careful consideration and suggest potential weaknesses in input validation that could lead to vulnerabilities if exploited in conjunction with other factors.
The vulnerability history shows a single medium severity CVE related to Cross-Site Scripting, which was recently patched. While this is positive, it highlights that XSS vulnerabilities have been a past issue for this plugin, and the remaining unprotected entry points could potentially reintroduce such risks if input isn't rigorously sanitized.
Key Concerns
- Unprotected AJAX handlers
- Unsanitized taint flows
- Medium severity XSS vulnerability history
B Testimonial – Customer Testimonials in Custom Layouts Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
B Testimonial – testimonial plugin for WP <= 1.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
B Testimonial – Customer Testimonials in Custom Layouts Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
B Testimonial – Customer Testimonials in Custom Layouts Attack Surface
AJAX Handlers 9
Shortcodes 1
WordPress Hooks 71
Maintenance & Trust
B Testimonial – Customer Testimonials in Custom Layouts Maintenance & Trust
Maintenance Signals
Community Trust
B Testimonial – Customer Testimonials in Custom Layouts Alternatives
Testimonial Carousel For Elementor
testimonials-carousel-elementor
The compact Testimonial Carousel for Elementor lets you show long text reviews in Pop-Up of Carousel Slider.
Responsive Owl Carousel for Elementor
responsive-owl-carousel-elementor
A highly customizable, powerful & responsive carousel plugin for Elementor page builder that is based on the Owl Carousel jQuery plugin.
Testimonial Slider, Grid & Carousel
testimonial-awesome
Create and display Testimonial slider, testimonial grid & testimonial carousel under. Easy to create. Easy to customize.
Vertical Carousel
vertical-carousel-slider
Display vertical carousel slider with the help of a shortcode.
Multimedia Slider Carousel – Image Slider, Video Slider, Testimonial Slider
powr-multi-slider
Create image slideshows, powerful call-to-action banners, sliding video galleries, event sliders, and more.
B Testimonial – Customer Testimonials in Custom Layouts Developer Profile
120 plugins · 738K total installs
How We Detect B Testimonial – Customer Testimonials in Custom Layouts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/b-testimonial/assets/css/frontend.css/wp-content/plugins/b-testimonial/assets/css/slick.css/wp-content/plugins/b-testimonial/assets/css/style.css/wp-content/plugins/b-testimonial/assets/js/frontend.js/wp-content/plugins/b-testimonial/assets/js/slick.js/wp-content/plugins/b-testimonial/admin/codestar-framework/assets/css/style.css/wp-content/plugins/b-testimonial/admin/codestar-framework/assets/js/script.js/wp-content/plugins/b-testimonial/src/block/block.json/wp-content/plugins/b-testimonial/assets/js/frontend.js/wp-content/plugins/b-testimonial/assets/js/slick.js/wp-content/plugins/b-testimonial/admin/codestar-framework/assets/js/script.js/wp-content/plugins/b-testimonial/src/init.phpb-testimonial/assets/css/frontend.css?ver=b-testimonial/assets/css/slick.css?ver=b-testimonial/assets/css/style.css?ver=b-testimonial/assets/js/frontend.js?ver=b-testimonial/assets/js/slick.js?ver=b-testimonial/admin/codestar-framework/assets/css/style.css?ver=b-testimonial/admin/codestar-framework/assets/js/script.js?ver=HTML / DOM Fingerprints
btsshortcodecarouselslick-slideslick-trackslick-listslick-initializedslick-dottedslick-prev+4 more<!-- get shortcode meta --><!-- And here goes the uninstallation function: --><!-- Footer Review Request --><!-- display the result -->+3 moredata-b-testimonial-idwindow.btsvar bts[b_testimonialb_testimonial