Buzzolt Reviews & Testimonials Security & Risk Analysis

wordpress.org/plugins/buzzolt-reviews-testimonials

Easily collect, manage, and display testimonials and reviews on your WordPress site.

50 active installs v1.0.1 PHP + WP + Updated May 27, 2025
customer-reviewsratingsreviewstestimonials
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Buzzolt Reviews & Testimonials Safe to Use in 2026?

Generally Safe

Score 100/100

Buzzolt Reviews & Testimonials has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10mo ago
Risk Assessment

The "buzzolt-reviews-testimonials" plugin v1.0.1 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of any recorded CVEs and the lack of critical or high-severity issues in the vulnerability history are positive indicators. The code analysis reveals excellent adherence to secure coding practices, with 100% of SQL queries utilizing prepared statements and a high percentage (89%) of output escaping. The presence of numerous nonce and capability checks further suggests a diligent approach to securing its functionalities.

However, a notable area of concern is the complete lack of identified entry points (AJAX handlers, REST API routes, shortcodes, cron events) during the static analysis. While this might indicate a very minimal plugin footprint, it could also suggest that the analysis tools were unable to detect or interpret certain plugin functionalities as entry points. If actual entry points exist and were missed, especially those without proper authentication or authorization, they could pose a significant risk. The taint analysis showing zero flows, while generally good, also contributes to this uncertainty, as it's difficult to fully assess the impact of potential data flows without them being identified.

In conclusion, the plugin demonstrates good fundamental security practices. The lack of historical vulnerabilities is a strong positive. The primary caution stems from the potential for undiscovered or unanalyzed attack vectors due to the reported zero entry points. This means the plugin might be secure, or it might have hidden vulnerabilities that were not detected by the static analysis.

Key Concerns

  • Zero detected entry points could indicate missed vulnerabilities
  • Potential for undiscovered taint flows
  • 89% output escaping is good but not perfect
Vulnerabilities
None known

Buzzolt Reviews & Testimonials Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Buzzolt Reviews & Testimonials Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
19 prepared
Unescaped Output
18
153 escaped
Nonce Checks
7
Capability Checks
8
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

100% prepared19 total queries

Output Escaping

89% escaped171 total outputs
Attack Surface

Buzzolt Reviews & Testimonials Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 13
actionadmin_enqueue_scriptsincludes\core\class-admin.php:31
actionenqueue_block_editor_assetsincludes\core\class-admin.php:32
actionadmin_menuincludes\core\class-admin.php:33
actionrest_api_initincludes\core\class-admin.php:34
actionwp_enqueue_scriptsincludes\core\class-frontend.php:31
filterbuzzolt_reviews_admin_js_variablesincludes\features\class-testimonial.php:43
filterbuzzolt_reviews_editor_js_variablesincludes\features\class-testimonial.php:44
filterbuzzolt_reviews_js_variablesincludes\features\class-testimonial.php:45
filterbuzzolt_reviews_admin_enqueueincludes\features\class-testimonial.php:46
actionrest_api_initincludes\features\class-testimonial.php:47
actioninitincludes\features\class-testimonial.php:48
actionwp_enqueue_scriptsincludes\features\class-testimonial.php:49
actionenqueue_block_editor_assetsincludes\features\class-testimonial.php:50
Maintenance & Trust

Buzzolt Reviews & Testimonials Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 27, 2025
PHP min version
Downloads599

Community Trust

Rating0/100
Number of ratings0
Active installs50
Developer Profile

Buzzolt Reviews & Testimonials Developer Profile

sproutient

9 plugins · 90 total installs

92
trust score
Avg Security Score
97/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Buzzolt Reviews & Testimonials

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/buzzolt-reviews-testimonials/assets/css/admin.css/wp-content/plugins/buzzolt-reviews-testimonials/assets/js/admin.js/wp-content/plugins/buzzolt-reviews-testimonials/assets/css/blockeditor.css/wp-content/plugins/buzzolt-reviews-testimonials/assets/js/blockeditor.js
Version Parameters
buzzolt-reviews-testimonials/assets/css/admin.css?ver=buzzolt-reviews-testimonials/assets/js/admin.js?ver=buzzolt-reviews-testimonials/assets/css/blockeditor.css?ver=buzzolt-reviews-testimonials/assets/js/blockeditor.js?ver=

HTML / DOM Fingerprints

CSS Classes
buzzolt-reviews-testimonials
Data Attributes
buzzoltReviewsAdminVariables
JS Globals
buzzoltReviewsAdminVariables
REST Endpoints
/wp-json/buzzolt-reviews-testimonials/v1/settings
FAQ

Frequently Asked Questions about Buzzolt Reviews & Testimonials