
IG Testimonials Security & Risk Analysis
wordpress.org/plugins/ig-testimonialsIG Testimonials is a clean and easy-to-use testimonials plugin for WordPress.
Is IG Testimonials Safe to Use in 2026?
Generally Safe
Score 85/100IG Testimonials has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The ig-testimonials v1.8 plugin exhibits a generally good security posture with several strengths. Notably, it utilizes prepared statements for all SQL queries and has a reasonable number of capability checks and a nonce check in place, indicating an awareness of common WordPress security practices. The absence of known CVEs and a clean vulnerability history further contribute to this positive outlook. However, there are areas for improvement. The presence of the 'unserialize' function is a significant concern, as it can lead to Remote Code Execution (RCE) vulnerabilities if not handled with extreme care and proper input validation. Furthermore, the static analysis reveals that over half of the plugin's output is not properly escaped. This could lead to Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the site through the plugin's output. While the total attack surface is small and appears to be protected, these specific code signals warrant caution.
Key Concerns
- Dangerous function 'unserialize' used
- High percentage of unescaped output
IG Testimonials Security Vulnerabilities
IG Testimonials Release Timeline
IG Testimonials Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
IG Testimonials Attack Surface
Shortcodes 2
WordPress Hooks 18
Maintenance & Trust
IG Testimonials Maintenance & Trust
Maintenance Signals
Community Trust
IG Testimonials Alternatives
Elfsight Testimonials Slider
elfsight-testimonials-slider
Level up your website credibility with trustworthy testimonials
Simple WP Testimonials
simple-wp-testimonials
Simple WP Testimonials is a plugin that allows you to manage and display testimonials for your blog.
Mi Testimonial Slider
mi-testimonial-slider
Testimonial Slider For Showcase your clients, customer's testimonials. With 20+ trendy designs you can customize your wordpress site
Testimonial Carousel Block
testimonial-carousel-block
Easily add a testimonials carousel to your WordPress post or page via the new Gutenberg Editor.
Wiwitness Testimonials
wiwitness-testimonials
Collect, manage and display socially verifiable testimonials. Instill confidence in visitors about your website.
IG Testimonials Developer Profile
4 plugins · 160 total installs
How We Detect IG Testimonials
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ig-testimonials/ig-testimonials.css/wp-content/plugins/ig-testimonials/js/slick.js/wp-content/plugins/ig-testimonials/js/ig-testimonials-main.js/wp-content/plugins/ig-testimonials/includes/mce-button.jsig-testimonials.css?ver=slick.js?ver=ig-testimonials-main.js?ver=mce-button.js?ver=HTML / DOM Fingerprints
ig-testimonials-pageig-testimonialsig-testimonials-carouseldata-slick<div class="ig-testimonials-page"><div id="testimonial-<div class="ig-testimonials"><div class="image">