Kento Testimonial Slider Security & Risk Analysis

wordpress.org/plugins/kento-testimonial-slider

Slide Your Unlimited Testimonial or Clients Feedback By using Shortcode Anywhere With Clients Thumbnail.

100 active installs v1.0 PHP + WP 3.5+ Updated Nov 24, 2016
quotequote-rotatortestimonialtestimonial-rotatortestimonial-slider
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Kento Testimonial Slider Safe to Use in 2026?

Generally Safe

Score 85/100

Kento Testimonial Slider has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "kento-testimonial-slider" v1.0 plugin exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by avoiding dangerous functions, performing all SQL queries using prepared statements, and having no recorded vulnerability history. The attack surface is minimal, consisting of only one shortcode and no AJAX handlers, REST API routes, or cron events, which reduces the potential for external interaction.

However, significant concerns arise from the code analysis. A critical weakness is the complete lack of output escaping, meaning any data rendered by the plugin could potentially be manipulated and injected, leading to cross-site scripting (XSS) vulnerabilities. Furthermore, the absence of nonce checks and capability checks on the identified shortcode entry point leaves it vulnerable to CSRF attacks or unauthorized access to its functionality if it were to interact with sensitive data or perform privileged actions, though the current limited entry points mitigate this to some extent.

Given the complete absence of past vulnerabilities, it might suggest a history of secure development or limited exposure. However, the presence of critical code-level weaknesses, particularly the lack of output escaping, poses a substantial risk that is not reflected in its vulnerability history. The plugin's current security relies heavily on the hope that no malicious input will be processed and that its limited functionality prevents exploitation, which is an insufficient security strategy.

Key Concerns

  • Output escaping is not used
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

Kento Testimonial Slider Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Kento Testimonial Slider Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

Kento Testimonial Slider Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[KentoTestimonial] index.php:108
WordPress Hooks 5
actioninitindex.php:22
filterwidget_textindex.php:32
filtermce_external_pluginsindex.php:38
filtermce_buttonsindex.php:39
actioninitindex.php:86
Maintenance & Trust

Kento Testimonial Slider Maintenance & Trust

Maintenance Signals

WordPress version tested4.6.30
Last updatedNov 24, 2016
PHP min version
Downloads11K

Community Trust

Rating80/100
Number of ratings1
Active installs100
Developer Profile

Kento Testimonial Slider Developer Profile

PluginsPoint

20 plugins · 600 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
8 days
View full developer profile
Detection Fingerprints

How We Detect Kento Testimonial Slider

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/kento-testimonial-slider/css/kento-testimonial-plugin-style.css/wp-content/plugins/kento-testimonial-slider/js/jquery.quote_rotator.js/wp-content/plugins/kento-testimonial-slider/js/kento-testimonial-active.js/wp-content/plugins/kento-testimonial-slider/js/editor_plugin.js
Script Paths
/wp-content/plugins/kento-testimonial-slider/js/jquery.quote_rotator.js/wp-content/plugins/kento-testimonial-slider/js/kento-testimonial-active.js/wp-content/plugins/kento-testimonial-slider/js/editor_plugin.js

HTML / DOM Fingerprints

CSS Classes
kento-testimonialkento_quoteskento-testimonial-authorkento-testimonial-author-imgkento-testimonial-author-namekento-testimonial-author-comments
Data Attributes
id="kento_quotes"
JS Globals
kentotestimonial_register
Shortcode Output
<div class="kento-testimonial"><ul id="kento_quotes">
FAQ

Frequently Asked Questions about Kento Testimonial Slider