
Creta Testimonial Showcase Security & Risk Analysis
wordpress.org/plugins/creta-testimonial-showcaseShowcase client reviews with Creta Testimonial Showcase an easy, responsive WordPress testimonial plugin with free and premium templates.
Is Creta Testimonial Showcase Safe to Use in 2026?
Generally Safe
Score 99/100Creta Testimonial Showcase has a strong security track record. Known vulnerabilities have been patched promptly.
The 'creta-testimonial-showcase' plugin v1.2.5 presents a mixed security posture. On the positive side, the plugin utilizes prepared statements for all SQL queries, a strong indicator of protection against SQL injection. It also demonstrates a reasonable level of output escaping, with 79% of outputs properly handled. The absence of critical or high-severity taint flows further suggests a generally well-coded application in this regard.
However, significant concerns arise from the plugin's attack surface. With a total of 7 entry points, 5 of which are unprotected AJAX handlers, there is a substantial risk of unauthorized actions being performed. The presence of 3 nonce checks, while present, is insufficient to cover all potentially sensitive AJAX endpoints. The plugin's vulnerability history, although currently showing no unpatched issues, includes a past medium-severity 'Path Traversal' vulnerability. This historical context, combined with the current lack of robust authentication on its AJAX endpoints, raises flags for potential similar vulnerabilities in the future.
In conclusion, while the plugin shows good practices in database interaction and output handling, the lack of authentication on a majority of its AJAX handlers is a critical weakness. This oversight, coupled with a past path traversal vulnerability, necessitates caution. Addressing the unprotected AJAX endpoints should be a priority to improve the plugin's overall security.
Key Concerns
- 5 unprotected AJAX handlers
- Past medium severity vulnerability
- Only 2 capability checks for 7 entry points
- 79% output escaping (could be higher)
Creta Testimonial Showcase Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Creta Testimonial Showcase <= 1.2.3 - Authenticated (Editor+) Local File Inclusion
Creta Testimonial Showcase Code Analysis
Output Escaping
Creta Testimonial Showcase Attack Surface
AJAX Handlers 6
Shortcodes 1
WordPress Hooks 20
Maintenance & Trust
Creta Testimonial Showcase Maintenance & Trust
Maintenance Signals
Community Trust
Creta Testimonial Showcase Alternatives
Testimonial Customer Feedback
testimonial-maker
Display client testimonials with customizable layouts, slider effects, and responsive design. Simple setup with shortcode support.
Five Star Restaurant Reviews
good-reviews-wp
Restaurant reviews made easy. Add and display reviews on your restaurant site using SEO friendly schema markup.
Advance Review Manager
advance-review-manager
Advance Review Manager is a powerful yet easy-to-use plugin to effortlessly create and manage all kind of reviews.
GlowReviews – Smart Feedback & Testimonials
glowreviews
Collect and display customer feedback with star ratings, image uploads, and WordPress user integration.
Scorpiotek Testimonials
scorpiotek-testimonials
A modern WordPress testimonials plugin with slider and star rating.
Creta Testimonial Showcase Developer Profile
80 plugins · 12K total installs
How We Detect Creta Testimonial Showcase
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/creta-testimonial-showcase/assets/css/admin-inline.css/wp-content/plugins/creta-testimonial-showcase/assets/css/admin-style.css/wp-content/plugins/creta-testimonial-showcase/assets/js/admin-js.js/wp-content/plugins/creta-testimonial-showcase/assets/css/admin-theme-page.css/wp-content/plugins/creta-testimonial-showcase/assets/js/admin-theme-page.js/wp-content/plugins/creta-testimonial-showcase/assets/css/bootstrap.min.css/wp-content/plugins/creta-testimonial-showcase/assets/js/bootstrap.bundle.min.js/wp-content/plugins/creta-testimonial-showcase/assets/css/owl.carousel.min.css+5 more/wp-content/plugins/creta-testimonial-showcase/assets/js/admin-js.js/wp-content/plugins/creta-testimonial-showcase/assets/js/admin-theme-page.js/wp-content/plugins/creta-testimonial-showcase/assets/js/bootstrap.bundle.min.js/wp-content/plugins/creta-testimonial-showcase/assets/js/owl.carousel.min.js/wp-content/plugins/creta-testimonial-showcase/assets/js/color-picker.jsver=1.2.5HTML / DOM Fingerprints
cretats-popup-overlaycretats-popup-contentcretats-popup-dismisscretats-popup-wrapcretats-popup-template-btncretats-popup-bundle-btncretats-theme-bundle-bannerbundle-row+13 moredata-cretats-theme-showcase-columnscretats_ajax_objectcretats_testimonial_showcase