
Excited! Testimonials Showcase Security & Risk Analysis
wordpress.org/plugins/excited-testimonials-showcaseWith Excited! Testimonials Showcase you can easily create awesome testimonials for your WordPress website or blog.
Is Excited! Testimonials Showcase Safe to Use in 2026?
Generally Safe
Score 85/100Excited! Testimonials Showcase has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "excited-testimonials-showcase" v1.0.5 plugin exhibits a strong security posture regarding its attack surface and known vulnerabilities. The absence of AJAX handlers, REST API routes, shortcodes, and cron events with unprotected entry points significantly reduces the plugin's exposure to common attack vectors. Furthermore, the complete lack of recorded CVEs, both historical and current, suggests a history of stable and secure development, or at least a lack of publicly disclosed vulnerabilities.
However, the static analysis reveals a significant concern with output escaping. With 339 total outputs and only 6% properly escaped, there's a high probability of Cross-Site Scripting (XSS) vulnerabilities. This is a critical weakness that could allow attackers to inject malicious scripts into a WordPress site if user-supplied data is not adequately sanitized before being displayed. The presence of file operations also warrants attention, though without further analysis, it's impossible to determine if these operations are handled securely. The plugin also lacks nonce and capability checks, which are fundamental security measures for protecting against CSRF attacks and ensuring proper authorization.
In conclusion, while the plugin benefits from a minimal attack surface and a clean vulnerability history, the poor output escaping practices and absence of critical security checks like nonce and capability checks represent substantial risks. The potential for XSS vulnerabilities is the most immediate and severe concern, outweighing the positive aspects of its attack surface and historical security record. Improvements in output escaping and the implementation of nonce and capability checks are strongly recommended.
Key Concerns
- Low percentage of properly escaped output
- Missing nonce checks
- Missing capability checks
Excited! Testimonials Showcase Security Vulnerabilities
Excited! Testimonials Showcase Code Analysis
Output Escaping
Excited! Testimonials Showcase Attack Surface
WordPress Hooks 16
Maintenance & Trust
Excited! Testimonials Showcase Maintenance & Trust
Maintenance Signals
Community Trust
Excited! Testimonials Showcase Alternatives
CustomView: Display Reviews Your Way for Google Reviews
customview-display-reviews-your-way-for-google-reviews
Display your business's Google Reviews anywhere on your WordPress site using the [customview_reviews] shortcode.
Review Fetcher
review-fetcher
Display your Google Business reviews in a beautiful responsive grid using a simple shortcode. Clean, lightweight, and easy to use.
Revora
revora
Lightweight, category-based review system with AJAX submission, spam detection, admin moderation, and beautiful Elementor widgets.
RicReviews
ricreviews
Display Google Places reviews on your WordPress site using a simple shortcode. Fetches reviews from Google Places API (New).
Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More
reviews-feed
No API key required. Display Yelp and Google reviews for any business in a clean, customizable feed on your site.
Excited! Testimonials Showcase Developer Profile
3 plugins · 230 total installs
How We Detect Excited! Testimonials Showcase
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/excited-testimonials-showcase/css/vendor/awesome/theme.css/wp-content/plugins/excited-testimonials-showcase/css/vendor/bootstrap/bootstrap.css/wp-content/plugins/excited-testimonials-showcase/css/vendor/bootstrap/bootflat.css/wp-content/plugins/excited-testimonials-showcase/css/vendor/bootstrap/bootstrap-colorpicker.css/wp-content/plugins/excited-testimonials-showcase/css/vendor/selectize/selectize.css/wp-content/plugins/excited-testimonials-showcase/css/vendor/formstone/dropdown.css/wp-content/plugins/excited-testimonials-showcase/css/vendor/formstone/lightbox.css/wp-content/plugins/excited-testimonials-showcase/css/vendor/awesome/panel.css+3 more/wp-content/plugins/excited-testimonials-showcase/js/vendor/jquery/jquery.js/wp-content/plugins/excited-testimonials-showcase/js/vendor/bootstrap/bootstrap.js/wp-content/plugins/excited-testimonials-showcase/js/vendor/selectize/selectize.js/wp-content/plugins/excited-testimonials-showcase/js/vendor/formstone/core.js/wp-content/plugins/excited-testimonials-showcase/js/vendor/formstone/dropdown.js/wp-content/plugins/excited-testimonials-showcase/js/vendor/formstone/lightbox.js+3 moreexcited-testimonials-showcase/css/vendor/awesome/theme.css?ver=excited-testimonials-showcase/css/vendor/bootstrap/bootstrap.css?ver=excited-testimonials-showcase/css/vendor/bootstrap/bootflat.css?ver=excited-testimonials-showcase/css/vendor/bootstrap/bootstrap-colorpicker.css?ver=excited-testimonials-showcase/css/vendor/selectize/selectize.css?ver=excited-testimonials-showcase/css/vendor/formstone/dropdown.css?ver=excited-testimonials-showcase/css/vendor/formstone/lightbox.css?ver=excited-testimonials-showcase/css/vendor/awesome/panel.css?ver=excited-testimonials-showcase/css/style.css?ver=excited-testimonials-showcase/public/css/style.css?ver=excited-testimonials-showcase/css/all.min.css?ver=excited-testimonials-showcase/js/vendor/jquery/jquery.js?ver=excited-testimonials-showcase/js/vendor/bootstrap/bootstrap.js?ver=excited-testimonials-showcase/js/vendor/selectize/selectize.js?ver=excited-testimonials-showcase/js/vendor/formstone/core.js?ver=excited-testimonials-showcase/js/vendor/formstone/dropdown.js?ver=excited-testimonials-showcase/js/vendor/formstone/lightbox.js?ver=excited-testimonials-showcase/js/vendor/bootstrap/bootstrap-colorpicker.js?ver=excited-testimonials-showcase/js/script.js?ver=excited-testimonials-showcase/admin/js/script.js?ver=HTML / DOM Fingerprints
aetfree-wrapaetfree-blockaetfree-testimonial-itemaetfree-quoteaetfree-authoraetfree-rating<!-- START: Generated by A Group Showcase Free --><!-- END: Generated by A Group Showcase Free -->data-aetfree-iddata-aetfree-groupLA_Testimonials_Freeaetfree_testimonials[a-excited-testimonials]