
FP Testimonials Security & Risk Analysis
wordpress.org/plugins/fp-testimonialsThis plugin will display testimonials in sidebar with several effects. You can manage the options from backend.Also you can use Shortcode for pages.
Is FP Testimonials Safe to Use in 2026?
Generally Safe
Score 85/100FP Testimonials has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The fp-testimonials plugin version 1.0.7 exhibits a mixed security posture, with some positive indicators but significant areas of concern. The plugin's attack surface is minimal, with only one shortcode identified as an entry point and no unprotected endpoints. The absence of known CVEs and a clean vulnerability history suggest a lack of historically exploited weaknesses. However, the static analysis reveals critical security flaws in the code itself. The presence of the dangerous `create_function` function is a major red flag, as it can be exploited for remote code execution if not handled with extreme care and sanitization. Furthermore, a very low percentage (6%) of output is properly escaped, indicating a high risk of cross-site scripting (XSS) vulnerabilities across numerous output points. The lack of nonce checks and capability checks on its single entry point also leaves it vulnerable to unauthorized actions or data manipulation if the shortcode can be triggered maliciously.
Key Concerns
- Presence of dangerous create_function
- Very low output escaping percentage
- Missing nonce checks on entry points
- Missing capability checks on entry points
FP Testimonials Security Vulnerabilities
FP Testimonials Code Analysis
Dangerous Functions Found
Output Escaping
FP Testimonials Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
FP Testimonials Maintenance & Trust
Maintenance Signals
Community Trust
FP Testimonials Alternatives
Testimonial & Review
testimonial-review
Testimonial Review plugin is a simple tool to display your customer's feedback on your WordPress website.
Testimonial Grid and Testimonial Slider plus Carousel with Rotator Widget
wp-testimonial-with-widget
A quick, easy way to add and display responsive, clean client's testimonial on your website using a shortcode, widget or Gutenberg block.
Advanced Testimonial Carousel For Elementor
advanced-testimonial-carousel-for-elementor
Advanced Testimonial Carousel For Elementor. You can add image, name, describes, title, added Unlimited slider.
BNE Testimonials
bne-testimonials
Display testimonials and reviews on any page or widget area as list or slider. Upgrade to PRO for additional layouts, themes, submission form, API, ra …
Stax Addons for Elementor
stax-addons-for-elementor
20+ lightweight widgets and enhancements for Elementor. Modular, fast, and zero bloat — assets load only when used.
FP Testimonials Developer Profile
6 plugins · 310 total installs
How We Detect FP Testimonials
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/fp-testimonials/js/jquery.bxSlider.min.js/wp-content/plugins/fp-testimonials/css/testimonial.css/wp-content/plugins/fp-testimonials/js/jquery.bxSlider.min.jsHTML / DOM Fingerprints
TestimonailWidgetfp_labelid="menu-posts-testimonial"class="wp-menu-image"[testimonial[textimonial