
CP Testimonial Security & Risk Analysis
wordpress.org/plugins/cp-testimonialsettings, star ratings Requires at least: 4.4.2 Tested Up to: 4.4.2 Stable tag: 1.0.0 Third party plugins: Owl Carousel License: GPLv2 CP Testimonial …
Is CP Testimonial Safe to Use in 2026?
Generally Safe
Score 85/100CP Testimonial has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "cp-testimonial" v1.0.0 plugin exhibits a generally good security posture based on the provided static analysis. The absence of AJAX handlers and REST API routes without authentication checks, along with a single shortcode entry point, suggests a limited attack surface. Furthermore, the plugin demonstrates strong practices by utilizing prepared statements for all SQL queries and avoiding dangerous functions or file operations. The vulnerability history being clear of any recorded CVEs also points to a relatively stable and well-maintained code base. However, a significant concern lies in the output escaping. With only 30% of the 44 total outputs being properly escaped, there is a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. This weakness, coupled with the absence of nonce checks for any potential future interactions or the existing shortcode, indicates an area where attackers could potentially inject malicious scripts. The presence of only one capability check on the shortcode is a positive sign, but it doesn't mitigate the XSS risk from unescaped output. Overall, while the core functionality appears secure, the insufficient output escaping presents a notable weakness that needs immediate attention.
Key Concerns
- Low percentage of properly escaped outputs
- No nonce checks implemented
CP Testimonial Security Vulnerabilities
CP Testimonial Release Timeline
CP Testimonial Code Analysis
Output Escaping
CP Testimonial Attack Surface
Shortcodes 1
WordPress Hooks 12
Maintenance & Trust
CP Testimonial Maintenance & Trust
Maintenance Signals
Community Trust
CP Testimonial Alternatives
Strong Testimonials
strong-testimonials
An easy-to-use testimonial plugin to collect and show customer feedback in WordPress
Site Reviews
site-reviews
Site Reviews is a complete review management solution that integrates with WooCommerce and SureCart and works similarly to reviews on Amazon, Tripadvi …
WP Testimonials
testimonial-widgets
Display your Testimonials on your website fast and easily. 21 widget types, 25 widget styles available. (Free Plugin)
Better Business Reviews – Trustpilot WordPress Plugin
better-business-reviews
Better Business Reviews allows you to display your business reviews from a Trustpilot profile.
Gutena Star Ratings
gutena-star-ratings
Gutena Star Ratings is a great block that lets you add star rating to client testimonials and reviews. Not only the star rating will tell customers ho …
CP Testimonial Developer Profile
3 plugins · 120 total installs
How We Detect CP Testimonial
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cp-testimonial/assets/css/style.css/wp-content/plugins/cp-testimonial/assets/js/scripts.js/wp-content/plugins/cp-testimonial/assets/js/scripts.jscp-testimonial/assets/css/style.css?ver=cp-testimonial/assets/js/scripts.js?ver=HTML / DOM Fingerprints
testimonial-itemtestimonial-contenttestimonial-authortestimonial-image-wrappertestimonial-author-name[CPTESTIMONIAL]