
BNE Testimonials Security & Risk Analysis
wordpress.org/plugins/bne-testimonialsDisplay testimonials and reviews on any page or widget area as list or slider. Upgrade to PRO for additional layouts, themes, submission form, API, ra …
Is BNE Testimonials Safe to Use in 2026?
Generally Safe
Score 85/100BNE Testimonials has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "bne-testimonials" v2.0.8 plugin exhibits a generally good security posture in its code, with no identified dangerous functions, external HTTP requests, or file operations. All SQL queries are properly prepared, and there are no critical or high-severity taint analysis findings. This indicates a developer conscious of common web application vulnerabilities. However, the plugin has a notable weakness in output escaping, with only 23% of outputs being properly escaped. This significantly increases the risk of Cross-Site Scripting (XSS) vulnerabilities, especially given that the plugin's last known vulnerability was an XSS issue.
While there are no currently unpatched CVEs, the history of one medium severity XSS vulnerability is a concern. The lack of documented nonce checks on its entry points, coupled with the low percentage of properly escaped output, suggests that even though the attack surface is contained and has capability checks, it may still be susceptible to certain client-side or unsalted attacks if malicious input can reach the insufficiently escaped output.
In conclusion, "bne-testimonials" v2.0.8 has strengths in its database and input handling. However, the significant deficiency in output escaping and the historical XSS vulnerability represent a tangible risk that needs to be addressed. The limited attack surface and the presence of capability checks mitigate some risks, but the insufficient output sanitization remains the primary security concern.
Key Concerns
- Low percentage of properly escaped output
- History of medium severity XSS vulnerability
- No nonce checks on entry points
BNE Testimonials Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
BNE Testimonials <= 2.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
BNE Testimonials Release Timeline
BNE Testimonials Code Analysis
Output Escaping
BNE Testimonials Attack Surface
Shortcodes 5
WordPress Hooks 11
Maintenance & Trust
BNE Testimonials Maintenance & Trust
Maintenance Signals
Community Trust
BNE Testimonials Alternatives
Creta Testimonial Showcase
creta-testimonial-showcase
Showcase client reviews with Creta Testimonial Showcase an easy, responsive WordPress testimonial plugin with free and premium templates.
Testimonial Customer Feedback
testimonial-maker
Display client testimonials with customizable layouts, slider effects, and responsive design. Simple setup with shortcode support.
Simple Testimonials Showcase
simple-testimonials-showcase
This plugin allows you to create and display testimonials in multiple ways.
Five Star Restaurant Reviews
good-reviews-wp
Restaurant reviews made easy. Add and display reviews on your restaurant site using SEO friendly schema markup.
Simple Testimonials
simple-testimonials
Easily manage testimonials and display them anywhere on your blog in seconds, via blocks, widgets or shortcodes.
BNE Testimonials Developer Profile
2 plugins · 2K total installs
How We Detect BNE Testimonials
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bne-testimonials/assets/css/bne-testimonials.css/wp-content/plugins/bne-testimonials/assets/css/bne-cmb-admin.css/wp-content/plugins/bne-testimonials/assets/js/flexslider.min.js/wp-content/plugins/bne-testimonials/assets/js/flexslider.min.jsbne-testimonials/assets/css/bne-testimonials.css?ver=bne-cmb-admin.css?ver=flexslider.min.js?ver=HTML / DOM Fingerprints
bne-admin-wrapperbne-innernav-tab-activebne-upsell<!-- Exit if accessed directly -->/*
* Plugin Name: BNE Testimonials
* Version: 2.0.8
* Description: Display testimonials on any page or widget area as list or slider. Upgrade to PRO for additional layouts, themes, API, 5-star ratings and schema markup.
* Author: Kerry Kline
* Author URI: https://www.bnecreative.com
* Requires at least: 5.0
* Text Domain: bne-testimonials
* License: GPL2
Copyright (C) 2013-2020 BNE Creative
This program is free software; you can redistribute it and/or modify
it under the terms of the GNU General Public License version 2,
as published by the Free Software Foundation.
You may NOT assume that you can use any other version of the GPL.
This program is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
GNU General Public License for more details.
The license for this software can likely be found here:
http://www.gnu.org/licenses/gpl-2.0.html
*/<!-- Init Class -->/*
* Constructor
*
* @since v2.0
*
*/+13 moredata-scrolldata-targetbne_testimonials_ajax_objectjQuery[bne_testimonials_list][bne_testimonials_slider]