
Gifted Testimonials Security & Risk Analysis
wordpress.org/plugins/gifted-testimonialsDisplays a nice testimonial carousel
Is Gifted Testimonials Safe to Use in 2026?
Generally Safe
Score 100/100Gifted Testimonials has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "gifted-testimonials" plugin version 1.0.1 exhibits a mixed security posture. On the positive side, the plugin does not appear to have any known CVEs, uses prepared statements for all SQL queries, and reports zero taint flows of critical or high severity. The absence of dangerous functions, file operations, and external HTTP requests further contributes to a relatively clean static analysis. However, significant concerns arise from the lack of output escaping and the absence of nonce and capability checks. With 5 total outputs and 0% properly escaped, there's a high risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the WordPress admin area or publicly visible pages. The single shortcode also represents an entry point that lacks essential security checks, potentially exposing the site if user-supplied data is processed without proper sanitization or authorization.
The vulnerability history being completely clear is a positive indicator, suggesting that past development might have been cautious. However, this does not negate the immediate risks identified in the static analysis. The lack of output escaping is a fundamental security practice that is missing, and its absence on all outputs is particularly concerning. While the attack surface is small (one shortcode), the lack of authentication checks on this entry point combined with unescaped output creates a tangible risk. In conclusion, while the plugin benefits from clean SQL and no known vulnerabilities, the severe lack of output escaping and missing security checks on its entry point present significant security weaknesses that require immediate attention.
Key Concerns
- Unescaped output on all outputs
- Missing nonce/capability checks on shortcode
Gifted Testimonials Security Vulnerabilities
Gifted Testimonials Code Analysis
Output Escaping
Gifted Testimonials Attack Surface
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
Gifted Testimonials Maintenance & Trust
Maintenance Signals
Community Trust
Gifted Testimonials Alternatives
Testimonial Slider, Grid & Carousel
testimonial-awesome
Create and display Testimonial slider, testimonial grid & testimonial carousel under. Easy to create. Easy to customize.
IG Testimonials
ig-testimonials
IG Testimonials is a clean and easy-to-use testimonials plugin for WordPress.
Fancy Testimonials
fancy-testimonials
Plugin for displaying testimonials via a shortcode for use on posts and pages.
LSX Testimonials
lsx-testimonials
The LSX Testimonials plugin adds a section to your website for storing your testimonial information.
Reviews Carousel
reviews-carousel
Reviews Carousel is a free and powerful plugin that lets you create and showcase customer reviews in a dynamic carousel format.
Gifted Testimonials Developer Profile
3 plugins · 1K total installs
How We Detect Gifted Testimonials
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gifted-testimonials/assets/css/all.min.css/wp-content/plugins/gifted-testimonials/assets/css/owl.carousel.min.css/wp-content/plugins/gifted-testimonials/assets/css/owl.theme.default.min.css/wp-content/plugins/gifted-testimonials/assets/css/main.css/wp-content/plugins/gifted-testimonials/assets/js/owl.carousel.min.js/wp-content/plugins/gifted-testimonials/assets/js/main.js/wp-content/plugins/gifted-testimonials/assets/js/owl.carousel.min.js/wp-content/plugins/gifted-testimonials/assets/js/main.jsgifted-testimonials/assets/css/all.min.css?ver=gifted-testimonials/assets/css/owl.carousel.min.css?ver=gifted-testimonials/assets/css/owl.theme.default.min.css?ver=gifted-testimonials/assets/css/main.css?ver=gifted-testimonials/assets/js/owl.carousel.min.js?ver=gifted-testimonials/assets/js/main.js?ver=HTML / DOM Fingerprints
km-gifted-testimonialskm-gifted-control-prevkm-gifted-control-nextkm-gifted-testimonialkm-gifted-testimonial-contentkm-gifted-testimonial-userkm-gifted-testimonial-imagekm-gifted-testimonial-locationkm-location<div class="owl-carousel owl-theme owl-loaded km-gifted-testimonials"><div class="km-gifted-testimonial">