Best Slider Testimonial Security & Risk Analysis

wordpress.org/plugins/best-slider-testimonial

Best Slider Testimonial is a WordPress plugin to display your client review or testimonial in your WordPress website.

0 active installs v1.0 PHP 7.2+ WP 6.0+ Updated Dec 20, 2022
star-ratingstestimonial-formtestestimonial-slidertestimonialswp-testimonial
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Best Slider Testimonial Safe to Use in 2026?

Generally Safe

Score 85/100

Best Slider Testimonial has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "best-slider-testimonial" v1.0 plugin exhibits a generally positive security posture based on the provided static analysis. The absence of dangerous functions, file operations, external HTTP requests, and a complete reliance on prepared statements for SQL queries are strong indicators of good development practices. Furthermore, the excellent output escaping rate suggests that reflected or stored cross-site scripting vulnerabilities are unlikely to be present.

However, there are areas for concern. The lack of nonce checks and capability checks on the single identified shortcode is a significant weakness. While the shortcode is the only entry point and there are no AJAX handlers or REST API routes without permission callbacks, a shortcode can still be exploited if it performs sensitive operations or handles user-provided data without proper authentication and authorization checks. The taint analysis showing zero flows with unsanitized paths is reassuring, but it doesn't negate the risk posed by missing security checks on the shortcode.

The plugin's vulnerability history is completely clean, with no recorded CVEs. This is a very positive sign, suggesting a history of secure development and maintenance. While this is excellent, it does not excuse the identified security gap in the current version's code. In conclusion, the plugin is built on solid foundations regarding SQL and output handling, but the absence of nonce and capability checks on its sole entry point represents a notable security risk that should be addressed.

Key Concerns

  • Missing nonce checks on shortcode
  • Missing capability checks on shortcode
Vulnerabilities
None known

Best Slider Testimonial Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Best Slider Testimonial Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
16
68 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

81% escaped84 total outputs
Attack Surface

Best Slider Testimonial Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[BESTSLIDERTESTIMONIAL] best-slider-testimonial.php:195
WordPress Hooks 10
actionwp_enqueue_scriptsbest-slider-testimonial.php:27
actionadmin_enqueue_scriptsbest-slider-testimonial.php:38
actioninitbest-slider-testimonial.php:98
actioninitbest-slider-testimonial.php:197
actionwp_footerbest-slider-testimonial.php:228
actionadmin_initbest-slider-testimonial.php:235
actionadmin_menuinclude\fuction.php:15
actionadd_meta_boxesinclude\meta-box.php:8
actionsave_postinclude\meta-box.php:66
actionwp_headinclude\wpbt-dynamic-css.php:42
Maintenance & Trust

Best Slider Testimonial Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedDec 20, 2022
PHP min version7.2
Downloads715

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Best Slider Testimonial Developer Profile

hysabbir

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Best Slider Testimonial

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/best-slider-testimonial/css/all.min.css/wp-content/plugins/best-slider-testimonial/css/owl.carousel.min.css/wp-content/plugins/best-slider-testimonial/css/owl.theme.default.min.css/wp-content/plugins/best-slider-testimonial/css/wpbt-style.css/wp-content/plugins/best-slider-testimonial/js/owl.carousel.min.js/wp-content/plugins/best-slider-testimonial/css/wpbt-admin-style.css/wp-content/plugins/best-slider-testimonial/js/cp-active.js
Script Paths
/wp-content/plugins/best-slider-testimonial/js/owl.carousel.min.js/wp-content/plugins/best-slider-testimonial/js/cp-active.js
Version Parameters
best-slider-testimonial/css/all.min.css?ver=best-slider-testimonial/css/owl.carousel.min.css?ver=best-slider-testimonial/css/owl.theme.default.min.css?ver=best-slider-testimonial/css/wpbt-style.css?ver=best-slider-testimonial/js/owl.carousel.min.js?ver=best-slider-testimonial/css/wpbt-admin-style.css?ver=best-slider-testimonial/js/cp-active.js?ver=

HTML / DOM Fingerprints

CSS Classes
post-sliderowl-carouselowl-themepost-slider-contpost-imageimage-layerpost-datedate-spa+3 more
HTML Comments
<!--<a href="https://g.page/kabs_driving?share" target="_blank">-->
Data Attributes
data-testi_rating
Shortcode Output
<div class="post-slider owl-carousel owl-theme"><div class="post-slider-cont"><div class="post-image"><div class="image-layer">
FAQ

Frequently Asked Questions about Best Slider Testimonial