
Testimonials by BestWebSoft Security & Risk Analysis
wordpress.org/plugins/bws-testimonialsAdd testimonials and feedbacks from your customers to WordPress website posts, pages, and widgets.
Is Testimonials by BestWebSoft Safe to Use in 2026?
Generally Safe
Score 100/100Testimonials by BestWebSoft has a strong security track record. Known vulnerabilities have been patched promptly.
The bws-testimonials plugin version 1.0.8 presents a mixed security posture. While it shows some good practices like a substantial number of nonce checks and some use of prepared statements for SQL, significant concerns remain. The presence of two AJAX handlers without authentication checks creates a direct attack vector. Furthermore, a high severity taint flow, indicating potential for malicious code execution or data compromise, is a critical finding that needs immediate attention. The plugin's vulnerability history reveals a past medium severity Cross-Site Scripting (XSS) vulnerability, and while currently unpatched CVEs are zero, the past pattern of XSS is a reminder of potential input validation weaknesses.
The static analysis highlights specific areas of concern. With a total of 9 entry points, 2 of which are unprotected AJAX handlers, the plugin's attack surface is not fully secured. The taint analysis showing a high-severity flow is particularly worrying, suggesting a potential for significant security breaches. The SQL query usage is also a concern, with only 22% of queries using prepared statements, increasing the risk of SQL injection vulnerabilities. Coupled with only 50% of output being properly escaped, the risk of Cross-Site Scripting (XSS) is elevated. The vulnerability history, although currently clear of active high-severity issues, suggests a recurring pattern of input validation problems, specifically XSS.
Key Concerns
- Unprotected AJAX handlers
- High severity taint flow
- SQL queries not using prepared statements
- Output not properly escaped
- Medium severity vulnerability in history
Testimonials by BestWebSoft Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Testimonials by BestWebSoft <= 0.1.8 - Reflected Cross-Site Scripting
Testimonials by BestWebSoft Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Testimonials by BestWebSoft Attack Surface
AJAX Handlers 4
Shortcodes 5
WordPress Hooks 32
Maintenance & Trust
Testimonials by BestWebSoft Maintenance & Trust
Maintenance Signals
Community Trust
Testimonials by BestWebSoft Alternatives
Elfsight Testimonials Slider
elfsight-testimonials-slider
Level up your website credibility with trustworthy testimonials
Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More
reviews-feed
No API key required. Display Yelp and Google reviews for any business in a clean, customizable feed on your site.
Rich Showcase for Google Reviews
widget-google-reviews
Display up to 10 Google reviews in less than a minute. Continue collecting new reviews. No limits on connected places, widgets, shortcodes and blocks.
Strong Testimonials
strong-testimonials
An easy-to-use testimonial plugin to collect and show customer feedback in WordPress
Site Reviews
site-reviews
Site Reviews is a complete review management solution that integrates with WooCommerce and SureCart and works similarly to reviews on Amazon, Tripadvi …
Testimonials by BestWebSoft Developer Profile
32 plugins · 17K total installs
How We Detect Testimonials by BestWebSoft
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bws-testimonials/css/font-awesome.min.css/wp-content/plugins/bws-testimonials/css/style.css/wp-content/plugins/bws-testimonials/js/main.js/wp-content/plugins/bws-testimonials/js/main.jsbws-testimonials/css/font-awesome.min.css?ver=bws-testimonials/css/style.css?ver=bws-testimonials/js/main.js?ver=HTML / DOM Fingerprints
tstmnls_formbws_testimonial_wrapperbws-testimonial-widgettstmnls_sectiontstmnls_section_titletstmnls_section_commenttstmnls_section_authortstmnls_section_author_name+2 more<!-- Start BWS Testimonials Section --><!-- End BWS Testimonials Section --><!-- Start BWS Testimonials Form --><!-- End BWS Testimonials Form -->data-tstmnls-iddata-tstmnls-post-id[tstmnls_reviews][tstmnls_review_form]