
Material Testimonials Security & Risk Analysis
wordpress.org/plugins/material-testimonialsThis is a simple Testimonials plugin.
Is Material Testimonials Safe to Use in 2026?
Generally Safe
Score 100/100Material Testimonials has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "material-testimonials" v1.5 plugin exhibits a generally good security posture with several strong security practices in place. The absence of known CVEs and the successful use of prepared statements for all SQL queries are significant strengths. Furthermore, the presence of nonce and capability checks indicates an awareness of securing entry points. The plugin also boasts a low attack surface, with only one shortcode identified as an entry point, and importantly, no unprotected entry points were found in the static analysis. The lack of dangerous functions, file operations, and external HTTP requests further contributes to its secure design.
However, there are areas for improvement that introduce minor risks. The primary concern lies in the output escaping, where only 59% of outputs are properly escaped. This leaves a considerable portion of the plugin's output potentially vulnerable to Cross-Site Scripting (XSS) attacks if user-supplied data is not sanitized before being displayed. While no critical or high severity taint flows were detected, this percentage of unescaped output is a notable weakness. The limited scope of the taint analysis (0 flows analyzed) means that the absence of critical findings in this area might be due to insufficient analysis rather than an inherent absence of risk.
In conclusion, "material-testimonials" v1.5 is a relatively secure plugin due to its robust foundation of secure coding practices and its clean vulnerability history. The primary weakness is the significant percentage of unescaped output, which presents a tangible risk of XSS vulnerabilities. Addressing this would significantly enhance the plugin's overall security. The limited taint analysis warrants cautious optimism, suggesting further investigation might be beneficial.
Key Concerns
- Unescaped output present
Material Testimonials Security Vulnerabilities
Material Testimonials Code Analysis
Output Escaping
Material Testimonials Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
Material Testimonials Maintenance & Trust
Maintenance Signals
Community Trust
Material Testimonials Alternatives
Testimonial Slider, Grid & Carousel
testimonial-awesome
Create and display Testimonial slider, testimonial grid & testimonial carousel under. Easy to create. Easy to customize.
Fancy Testimonials
fancy-testimonials
Plugin for displaying testimonials via a shortcode for use on posts and pages.
Reviews Carousel
reviews-carousel
Reviews Carousel is a free and powerful plugin that lets you create and showcase customer reviews in a dynamic carousel format.
Testimonial Carousel Block
testimonial-carousel-block
Easily add a testimonials carousel to your WordPress post or page via the new Gutenberg Editor.
Devgirl Reviews Slider
devgirl-reviews-slider
A slider to show the reviews from your customer. Autoplay, style options, easy to add and use the shortcode anywhere.
Material Testimonials Developer Profile
2 plugins · 100 total installs
How We Detect Material Testimonials
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/material-testimonials/css/style.css/wp-content/plugins/material-testimonials/css/owl.carousel.min.css/wp-content/plugins/material-testimonials/css/font-awesome.min.css/wp-content/plugins/material-testimonials/js/owl.carousel.min.jsmaterial-testimonials/css/style.css?ver=material-testimonials/css/owl.carousel.min.css?ver=material-testimonials/css/font-awesome.min.css?ver=material-testimonials/js/owl.carousel.min.js?ver=HTML / DOM Fingerprints
material-testimonialstestimonialstyle1style2style3style4testimonial-wrappertestimonial-image+9 moremattesti-bg-colormattesti-text-colormattesti-sub-titlemattesti-facebook-urlmattesti-twitter-urlmattesti-linkedin-url+1 moreMATTESTI_PLUGIN<div id='material-testimonials-class="material-testimonials owl-carousel owl-theme"<div class="item"><div class="testimonial style4 shadow"