
Elfsight Testimonials Slider Security & Risk Analysis
wordpress.org/plugins/elfsight-testimonials-sliderLevel up your website credibility with trustworthy testimonials
Is Elfsight Testimonials Slider Safe to Use in 2026?
High Risk
Score 47/100Elfsight Testimonials Slider carries significant security risk with 3 known CVEs, 3 still unpatched. Consider switching to a maintained alternative.
The "elfsight-testimonials-slider" plugin v1.0.1 exhibits a concerning security posture, despite some positive indicators. While the static analysis reveals a seemingly small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events without authentication or permission checks, this is overshadowed by critical findings in taint analysis and a significant vulnerability history. Two taint flows with unsanitized paths were identified, indicating potential for attackers to inject malicious code or manipulate data, even though the severity was classified as High. The plugin also has a history of 3 known medium severity vulnerabilities, all of which are currently unpatched. These past vulnerabilities commonly include Missing Authorization, Cross-site Scripting, and CSRF, suggesting recurring security flaws in how user input is handled and access is controlled. The fact that these vulnerabilities remain unpatched, with the last one listed as recently as March 31, 2025, is a major red flag. Furthermore, the low percentage of properly escaped output (24%) is a significant weakness, greatly increasing the risk of XSS attacks where user-provided data can be rendered directly in the browser without proper sanitization. The presence of a file operation also warrants scrutiny in conjunction with the unsanitized paths. In conclusion, while the plugin has a minimal direct attack surface, the high severity taint flows, pervasive output escaping issues, and unpatched historical vulnerabilities create a substantial risk profile for users.
Key Concerns
- Unpatched CVEs (3 medium)
- High severity taint flows (2)
- Low output escaping (24%)
- File operation present
- Unsanitized paths in taint flows
Elfsight Testimonials Slider Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Elfsight Testimonials Slider <= 1.0.1 - Missing Authorization
Elfsight Testimonials Slider <= 1.0.1 - Authenticated (Administrator+) Stored Cross-Site Scripting
Elfsight Testimonials Slider <= 1.0.1 - Cross-Site Request Forgery to Settings Update
Elfsight Testimonials Slider Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Elfsight Testimonials Slider Attack Surface
WordPress Hooks 4
Maintenance & Trust
Elfsight Testimonials Slider Maintenance & Trust
Maintenance Signals
Community Trust
Elfsight Testimonials Slider Alternatives
Strong Testimonials
strong-testimonials
An easy-to-use testimonial plugin to collect and show customer feedback in WordPress
Testimonials by BestWebSoft
bws-testimonials
Add testimonials and feedbacks from your customers to WordPress website posts, pages, and widgets.
Video Testimonial slider
video-testimonial-slider
Video Testimonial Slider plugin for WordPress website. Using plugin to display client Review and Testimonial with video popup through shortcode.
IG Testimonials
ig-testimonials
IG Testimonials is a clean and easy-to-use testimonials plugin for WordPress.
Simple WP Testimonials
simple-wp-testimonials
Simple WP Testimonials is a plugin that allows you to manage and display testimonials for your blog.
Elfsight Testimonials Slider Developer Profile
4 plugins · 5K total installs
How We Detect Elfsight Testimonials Slider
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/elfsight-testimonials-slider/assets/elfsight-testimonials-slider.js/wp-content/plugins/elfsight-testimonials-slider/assets/elfsight-admin.css/wp-content/plugins/elfsight-testimonials-slider/assets/elfsight-admin.js/wp-content/plugins/elfsight-testimonials-slider/assets/elfsight-testimonials-slider.js/wp-content/plugins/elfsight-testimonials-slider/preview/testimonials-slider-observer.jselfsight-testimonials-slider/assets/elfsight-admin.css?ver=elfsight-testimonials-slider/assets/elfsight-admin.js?ver=HTML / DOM Fingerprints
elfsight-adminelfsight-admin-wp-notifications-hackelfsight-admin-wrapperelfsight-admin-mainelfsight-admin-loadingelfsight-admin-loaderelfsight-admin-menu-containerelfsight-admin-pages-containerdata-elfsight-admin-slugdata-elfsight-admin-widgets-cloggedElfsightTestimonialsSliderPlugin