
Kento Testimonial Slider Security & Risk Analysis
wordpress.org/plugins/kento-testimonial-sliderSlide Your Unlimited Testimonial or Clients Feedback By using Shortcode Anywhere With Clients Thumbnail.
Is Kento Testimonial Slider Safe to Use in 2026?
Generally Safe
Score 85/100Kento Testimonial Slider has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "kento-testimonial-slider" v1.0 plugin exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by avoiding dangerous functions, performing all SQL queries using prepared statements, and having no recorded vulnerability history. The attack surface is minimal, consisting of only one shortcode and no AJAX handlers, REST API routes, or cron events, which reduces the potential for external interaction.
However, significant concerns arise from the code analysis. A critical weakness is the complete lack of output escaping, meaning any data rendered by the plugin could potentially be manipulated and injected, leading to cross-site scripting (XSS) vulnerabilities. Furthermore, the absence of nonce checks and capability checks on the identified shortcode entry point leaves it vulnerable to CSRF attacks or unauthorized access to its functionality if it were to interact with sensitive data or perform privileged actions, though the current limited entry points mitigate this to some extent.
Given the complete absence of past vulnerabilities, it might suggest a history of secure development or limited exposure. However, the presence of critical code-level weaknesses, particularly the lack of output escaping, poses a substantial risk that is not reflected in its vulnerability history. The plugin's current security relies heavily on the hope that no malicious input will be processed and that its limited functionality prevents exploitation, which is an insufficient security strategy.
Key Concerns
- Output escaping is not used
- No nonce checks on entry points
- No capability checks on entry points
Kento Testimonial Slider Security Vulnerabilities
Kento Testimonial Slider Code Analysis
Output Escaping
Kento Testimonial Slider Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
Kento Testimonial Slider Maintenance & Trust
Maintenance Signals
Community Trust
Kento Testimonial Slider Alternatives
PPM Testimonial
ppm-testimonial
This plugin will add fade in out testimonials via shortcode in page or post.
Testimonial Grid and Testimonial Slider plus Carousel with Rotator Widget
wp-testimonial-with-widget
A quick, easy way to add and display responsive, clean client's testimonial on your website using a shortcode, widget or Gutenberg block.
WP Testimonial
wp-testimonial
Add Testimonials on Your Website.
Kento Clients Feedback
kento-clients-feedback
Display Cleants Feedback or Testimonials
Real Testimonials – Testimonial Slider, Collect Customer Reviews and Video Testimonials
testimonial-free
A Customizable Testimonial plugin to Automate Collecting, Filtering, and Publishing Customer Reviews. Testimonial Slider, Grid & More to Grow Sales
Kento Testimonial Slider Developer Profile
20 plugins · 600 total installs
How We Detect Kento Testimonial Slider
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/kento-testimonial-slider/css/kento-testimonial-plugin-style.css/wp-content/plugins/kento-testimonial-slider/js/jquery.quote_rotator.js/wp-content/plugins/kento-testimonial-slider/js/kento-testimonial-active.js/wp-content/plugins/kento-testimonial-slider/js/editor_plugin.js/wp-content/plugins/kento-testimonial-slider/js/jquery.quote_rotator.js/wp-content/plugins/kento-testimonial-slider/js/kento-testimonial-active.js/wp-content/plugins/kento-testimonial-slider/js/editor_plugin.jsHTML / DOM Fingerprints
kento-testimonialkento_quoteskento-testimonial-authorkento-testimonial-author-imgkento-testimonial-author-namekento-testimonial-author-commentsid="kento_quotes"kentotestimonial_register<div class="kento-testimonial"><ul id="kento_quotes">