
Solid Testimonials – Testimonial Slider, Video Testimonials & Customer Reviews Security & Risk Analysis
wordpress.org/plugins/gs-testimonialShowcase and automate customer reviews with ease - sliders, grids, filters, and more to boost trust and sales.
Is Solid Testimonials – Testimonial Slider, Video Testimonials & Customer Reviews Safe to Use in 2026?
Generally Safe
Score 96/100Solid Testimonials – Testimonial Slider, Video Testimonials & Customer Reviews has a strong security track record. Known vulnerabilities have been patched promptly.
The 'gs-testimonial' plugin v3.3.9 exhibits a mixed security posture. While it demonstrates good practices like a high percentage of prepared SQL statements and proper output escaping, significant concerns arise from its attack surface. The presence of three unprotected AJAX handlers represents a direct avenue for potential unauthorized actions or information disclosure, as these entry points lack crucial authentication checks.
Taint analysis further highlights these concerns, with five out of seven analyzed flows having unsanitized paths. The four high-severity taint flows are particularly worrying, suggesting that user-supplied input is not being adequately validated or sanitized before being used in sensitive operations, potentially leading to various injection vulnerabilities. The plugin's vulnerability history, with six medium-severity CVEs related to missing authorization, code injection, and cross-site scripting, reinforces the importance of robust security controls for this plugin. The recent vulnerability in 2025 indicates that past issues, while currently patched, have been present and require ongoing vigilance.
In conclusion, while the plugin employs some beneficial security measures, the unprotected AJAX handlers and high-severity taint flows, coupled with a history of common vulnerabilities, point to a moderate to high-risk profile. Addressing the unprotected entry points and ensuring comprehensive input sanitization are critical steps to improve its security. The bundled Freemius library at v1.0 also warrants attention for potential known vulnerabilities within that specific version.
Key Concerns
- Unprotected AJAX handlers
- High severity taint flows
- Unsanitized paths in taint flows
- History of medium CVEs (x6)
- Bundled outdated library (Freemius v1.0)
Solid Testimonials – Testimonial Slider, Video Testimonials & Customer Reviews Security Vulnerabilities
CVEs by Year
Severity Breakdown
6 total CVEs
GS Testimonial Slider <= 3.3.0 - Missing Authorization
GS Testimonial Slider <= 3.2.9 - Unauthenticated Arbitrary Shortcode Execution
GS Testimonial Slider <= 3.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
Appsero <= 1.2.1 - Missing Authorization
GS Testimonial Slider <= 1.9.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
GS Testimonial Slider <= 1.9.6 - Authenticated (Author+) Stored Cross-Site Scripting
Solid Testimonials – Testimonial Slider, Video Testimonials & Customer Reviews Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Solid Testimonials – Testimonial Slider, Video Testimonials & Customer Reviews Attack Surface
AJAX Handlers 22
Shortcodes 1
WordPress Hooks 84
Maintenance & Trust
Solid Testimonials – Testimonial Slider, Video Testimonials & Customer Reviews Maintenance & Trust
Maintenance Signals
Community Trust
Solid Testimonials – Testimonial Slider, Video Testimonials & Customer Reviews Alternatives
Reviewfic – The Ultimate Testimonial Slider, Carousel, Grid Plugin
reviewfic
Showcase testimonials, customer reviews, or quotes on your website. Easily display reviews across posts, pages, custom templates, widgets, and more.
Real Testimonials – Testimonial Slider, Collect Customer Reviews and Video Testimonials
testimonial-free
A Customizable Testimonial plugin to Automate Collecting, Filtering, and Publishing Customer Reviews. Testimonial Slider, Grid & More to Grow Sales
Testimonial – Responsive Testimonials Showcase
testimonial-by-weblizar
Testimonial is the Responsive Testimonials Showcase Plugin for WordPress built to display testimonials, reviews or quotes in multiple ways on any page …
Video Testimonial slider
video-testimonial-slider
Video Testimonial Slider plugin for WordPress website. Using plugin to display client Review and Testimonial with video popup through shortcode.
Ace Testimonials Slider
ace-testimonials-slider
A sleek, responsive, and highly customizable WordPress plugin to showcase client testimonials and customer reviews in a beautiful slider format.
Solid Testimonials – Testimonial Slider, Video Testimonials & Customer Reviews Developer Profile
19 plugins · 41K total installs
How We Detect Solid Testimonials – Testimonial Slider, Video Testimonials & Customer Reviews
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gs-testimonial/freemius/start.php/wp-content/plugins/gs-testimonial/includes/autoloader.php/wp-content/plugins/gs-testimonial/includes/plugin.php/wp-content/plugins/gs-testimonial/includes/asset-generator/gs-testimonial-asset-generator.phpHTML / DOM Fingerprints
gs_tstm_areacarousel_style_1testimonial-boxbox-client-namebox-tm-titlebox-contentgs-star-ratinggstm_popup_shortcodedata-gs-testimonial-idgstm_fs[gs_testimonial