Easy Testimonials Slider Plugin Security & Risk Analysis

wordpress.org/plugins/epizy-easy-testimonials

Easy Testimonials Plugin is a WordPress plugin to display your client review or testimonial in your WordPress website.

0 active installs v2.6 PHP + WP 5.2+ Updated Oct 25, 2025
star-ratingstestimonial-formtestestimonialstimonial-sliderwp-testimonial
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Easy Testimonials Slider Plugin Safe to Use in 2026?

Generally Safe

Score 100/100

Easy Testimonials Slider Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The Epizy Easy Testimonials plugin v2.6 exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests are positive indicators. Furthermore, the lack of any recorded CVEs suggests a history of secure development or prompt patching. However, a significant concern arises from the output escaping, where only 56% of outputs are properly escaped, leaving potential avenues for cross-site scripting (XSS) vulnerabilities, especially given the presence of a shortcode as a potential entry point. The lack of explicit nonce and capability checks on any identified entry points, while seemingly mitigated by the limited attack surface, still represents a missed security best practice that could be exploited if the attack surface were to expand in future versions or through interactions with other plugins. While the current known vulnerability history is clean, the identified output escaping issue warrants attention and mitigation.

Key Concerns

  • Low percentage of properly escaped output
  • Missing nonce checks on entry points
  • Missing capability checks on entry points
Vulnerabilities
None known

Easy Testimonials Slider Plugin Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Easy Testimonials Slider Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
16
20 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

56% escaped36 total outputs
Attack Surface

Easy Testimonials Slider Plugin Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[WPETPTESTIMONIAL] WP-Easy-Testimonials-Plugin.php:212
WordPress Hooks 11
actionadmin_menuinc\functions.php:15
actionadd_meta_boxesinc\meta-box.php:8
actionsave_postinc\meta-box.php:51
actionwp_headinc\wpetp-dynamic-css.php:29
actionwp_enqueue_scriptsWP-Easy-Testimonials-Plugin.php:23
actionwp_enqueue_scriptsWP-Easy-Testimonials-Plugin.php:32
actionadmin_enqueue_scriptsWP-Easy-Testimonials-Plugin.php:44
actioninitWP-Easy-Testimonials-Plugin.php:101
actionwp_footerWP-Easy-Testimonials-Plugin.php:206
actioninitWP-Easy-Testimonials-Plugin.php:214
actionadmin_initWP-Easy-Testimonials-Plugin.php:226
Maintenance & Trust

Easy Testimonials Slider Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 25, 2025
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Easy Testimonials Slider Plugin Developer Profile

Riyadh Ahmed

3 plugins · 10K total installs

88
trust score
Avg Security Score
100/100
Avg Patch Time
40 days
View full developer profile
Detection Fingerprints

How We Detect Easy Testimonials Slider Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/epizy-easy-testimonials/css/owl.carousel.min.css/wp-content/plugins/epizy-easy-testimonials/css/owl.theme.min.css/wp-content/plugins/epizy-easy-testimonials/css/wpetp-style.css/wp-content/plugins/epizy-easy-testimonials/js/owl.carousel.min.js/wp-content/plugins/epizy-easy-testimonials/css/wpetp-admin-style.css/wp-content/plugins/epizy-easy-testimonials/js/cp-active.js
Script Paths
js/owl.carousel.min.jsjs/cp-active.js
Version Parameters
epizy-easy-testimonials/css/owl.carousel.min.css?ver=epizy-easy-testimonials/css/owl.theme.min.css?ver=epizy-easy-testimonials/css/wpetp-style.css?ver=epizy-easy-testimonials/js/owl.carousel.min.js?ver=epizy-easy-testimonials/css/wpetp-admin-style.css?ver=epizy-easy-testimonials/js/cp-active.js?ver=

HTML / DOM Fingerprints

CSS Classes
testimonial-slidertestimonialpictitledescriptiontestimonial-contenttestimonial-profilename+2 more
HTML Comments
<!-- WP_Query arguments --><!-- The Query --><!-- The Loop --><!-- do something -->+3 more
Data Attributes
id="testimonial-slider"class="owl-carousel"class="testimonial"class="pic"class="title"class="description"+7 more
JS Globals
jQuery(document).readyjQuery("#testimonial-slider").owlCarousel
Shortcode Output
<div id="testimonial-slider" class="owl-carousel">
FAQ

Frequently Asked Questions about Easy Testimonials Slider Plugin