Excited! Testimonials Showcase Security & Risk Analysis

wordpress.org/plugins/excited-testimonials-showcase

With Excited! Testimonials Showcase you can easily create awesome testimonials for your WordPress website or blog.

60 active installs v1.0.5 PHP + WP 3.6+ Updated Jan 12, 2016
ajaxreviewreviewsshortcodetestimonials
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Excited! Testimonials Showcase Safe to Use in 2026?

Generally Safe

Score 85/100

Excited! Testimonials Showcase has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The "excited-testimonials-showcase" v1.0.5 plugin exhibits a strong security posture regarding its attack surface and known vulnerabilities. The absence of AJAX handlers, REST API routes, shortcodes, and cron events with unprotected entry points significantly reduces the plugin's exposure to common attack vectors. Furthermore, the complete lack of recorded CVEs, both historical and current, suggests a history of stable and secure development, or at least a lack of publicly disclosed vulnerabilities.

However, the static analysis reveals a significant concern with output escaping. With 339 total outputs and only 6% properly escaped, there's a high probability of Cross-Site Scripting (XSS) vulnerabilities. This is a critical weakness that could allow attackers to inject malicious scripts into a WordPress site if user-supplied data is not adequately sanitized before being displayed. The presence of file operations also warrants attention, though without further analysis, it's impossible to determine if these operations are handled securely. The plugin also lacks nonce and capability checks, which are fundamental security measures for protecting against CSRF attacks and ensuring proper authorization.

In conclusion, while the plugin benefits from a minimal attack surface and a clean vulnerability history, the poor output escaping practices and absence of critical security checks like nonce and capability checks represent substantial risks. The potential for XSS vulnerabilities is the most immediate and severe concern, outweighing the positive aspects of its attack surface and historical security record. Improvements in output escaping and the implementation of nonce and capability checks are strongly recommended.

Key Concerns

  • Low percentage of properly escaped output
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Excited! Testimonials Showcase Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Excited! Testimonials Showcase Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
318
21 escaped
Nonce Checks
0
Capability Checks
0
File Operations
4
External Requests
0
Bundled Libraries
0

Output Escaping

6% escaped339 total outputs
Attack Surface

Excited! Testimonials Showcase Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 16
actionadmin_menuadmin\Admin.php:41
actionadmin_noticesincludes\ActivatorFree.php:44
actionadmin_noticesincludes\ActivatorFree.php:75
filterimage_size_names_chooseincludes\PluginFree.php:90
actionplugins_loadedincludes\PluginFree.php:149
filtertiny_mce_before_initincludes\PluginFree.php:219
filterquicktags_settingsincludes\PluginFree.php:220
actionadmin_enqueue_scriptsincludes\PluginFree.php:238
actionadmin_enqueue_scriptsincludes\PluginFree.php:239
actioninitincludes\PluginFree.php:242
actionwp_enqueue_scriptsincludes\PluginFree.php:263
actionwp_enqueue_scriptsincludes\PluginFree.php:264
actionwp_enqueue_scriptsincludes\PluginFree.php:265
filterwidget_textincludes\PluginFree.php:266
filterscript_loader_tagincludes\PluginFree.php:268
actionadmin_initinit.php:52
Maintenance & Trust

Excited! Testimonials Showcase Maintenance & Trust

Maintenance Signals

WordPress version tested4.4.34
Last updatedJan 12, 2016
PHP min version
Downloads8K

Community Trust

Rating0/100
Number of ratings0
Active installs60
Developer Profile

Excited! Testimonials Showcase Developer Profile

Looks Awesome

3 plugins · 230 total installs

59
trust score
Avg Security Score
72/100
Avg Patch Time
1648 days
View full developer profile
Detection Fingerprints

How We Detect Excited! Testimonials Showcase

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/excited-testimonials-showcase/css/vendor/awesome/theme.css/wp-content/plugins/excited-testimonials-showcase/css/vendor/bootstrap/bootstrap.css/wp-content/plugins/excited-testimonials-showcase/css/vendor/bootstrap/bootflat.css/wp-content/plugins/excited-testimonials-showcase/css/vendor/bootstrap/bootstrap-colorpicker.css/wp-content/plugins/excited-testimonials-showcase/css/vendor/selectize/selectize.css/wp-content/plugins/excited-testimonials-showcase/css/vendor/formstone/dropdown.css/wp-content/plugins/excited-testimonials-showcase/css/vendor/formstone/lightbox.css/wp-content/plugins/excited-testimonials-showcase/css/vendor/awesome/panel.css+3 more
Script Paths
/wp-content/plugins/excited-testimonials-showcase/js/vendor/jquery/jquery.js/wp-content/plugins/excited-testimonials-showcase/js/vendor/bootstrap/bootstrap.js/wp-content/plugins/excited-testimonials-showcase/js/vendor/selectize/selectize.js/wp-content/plugins/excited-testimonials-showcase/js/vendor/formstone/core.js/wp-content/plugins/excited-testimonials-showcase/js/vendor/formstone/dropdown.js/wp-content/plugins/excited-testimonials-showcase/js/vendor/formstone/lightbox.js+3 more
Version Parameters
excited-testimonials-showcase/css/vendor/awesome/theme.css?ver=excited-testimonials-showcase/css/vendor/bootstrap/bootstrap.css?ver=excited-testimonials-showcase/css/vendor/bootstrap/bootflat.css?ver=excited-testimonials-showcase/css/vendor/bootstrap/bootstrap-colorpicker.css?ver=excited-testimonials-showcase/css/vendor/selectize/selectize.css?ver=excited-testimonials-showcase/css/vendor/formstone/dropdown.css?ver=excited-testimonials-showcase/css/vendor/formstone/lightbox.css?ver=excited-testimonials-showcase/css/vendor/awesome/panel.css?ver=excited-testimonials-showcase/css/style.css?ver=excited-testimonials-showcase/public/css/style.css?ver=excited-testimonials-showcase/css/all.min.css?ver=excited-testimonials-showcase/js/vendor/jquery/jquery.js?ver=excited-testimonials-showcase/js/vendor/bootstrap/bootstrap.js?ver=excited-testimonials-showcase/js/vendor/selectize/selectize.js?ver=excited-testimonials-showcase/js/vendor/formstone/core.js?ver=excited-testimonials-showcase/js/vendor/formstone/dropdown.js?ver=excited-testimonials-showcase/js/vendor/formstone/lightbox.js?ver=excited-testimonials-showcase/js/vendor/bootstrap/bootstrap-colorpicker.js?ver=excited-testimonials-showcase/js/script.js?ver=excited-testimonials-showcase/admin/js/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
aetfree-wrapaetfree-blockaetfree-testimonial-itemaetfree-quoteaetfree-authoraetfree-rating
HTML Comments
<!-- START: Generated by A Group Showcase Free --><!-- END: Generated by A Group Showcase Free -->
Data Attributes
data-aetfree-iddata-aetfree-group
JS Globals
LA_Testimonials_Freeaetfree_testimonials
Shortcode Output
[a-excited-testimonials]
FAQ

Frequently Asked Questions about Excited! Testimonials Showcase