Material Testimonials Security & Risk Analysis

wordpress.org/plugins/material-testimonials

This is a simple Testimonials plugin.

0 active installs v1.5 PHP 5.2.4+ WP 4.6+ Updated Unknown
carouselmaterial-testimonialsslidertestimonials
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Material Testimonials Safe to Use in 2026?

Generally Safe

Score 100/100

Material Testimonials has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "material-testimonials" v1.5 plugin exhibits a generally good security posture with several strong security practices in place. The absence of known CVEs and the successful use of prepared statements for all SQL queries are significant strengths. Furthermore, the presence of nonce and capability checks indicates an awareness of securing entry points. The plugin also boasts a low attack surface, with only one shortcode identified as an entry point, and importantly, no unprotected entry points were found in the static analysis. The lack of dangerous functions, file operations, and external HTTP requests further contributes to its secure design.

However, there are areas for improvement that introduce minor risks. The primary concern lies in the output escaping, where only 59% of outputs are properly escaped. This leaves a considerable portion of the plugin's output potentially vulnerable to Cross-Site Scripting (XSS) attacks if user-supplied data is not sanitized before being displayed. While no critical or high severity taint flows were detected, this percentage of unescaped output is a notable weakness. The limited scope of the taint analysis (0 flows analyzed) means that the absence of critical findings in this area might be due to insufficient analysis rather than an inherent absence of risk.

In conclusion, "material-testimonials" v1.5 is a relatively secure plugin due to its robust foundation of secure coding practices and its clean vulnerability history. The primary weakness is the significant percentage of unescaped output, which presents a tangible risk of XSS vulnerabilities. Addressing this would significantly enhance the plugin's overall security. The limited taint analysis warrants cautious optimism, suggesting further investigation might be beneficial.

Key Concerns

  • Unescaped output present
Vulnerabilities
None known

Material Testimonials Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Material Testimonials Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
39
55 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

59% escaped94 total outputs
Attack Surface

Material Testimonials Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[material-testimonials] inc\mattesti-shortcode.php:264
WordPress Hooks 5
actionadmin_menuinc\mattesti-doc-page.php:3
actionadd_meta_boxesinc\mattesti-post-metabox.php:3
actionsave_postinc\mattesti-post-metabox.php:93
actioninitinc\mattesti-post-register.php:3
actionwp_enqueue_scriptsmaterial-testimonials.php:25
Maintenance & Trust

Material Testimonials Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedUnknown
PHP min version5.2.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Material Testimonials Developer Profile

imdr

2 plugins · 100 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Material Testimonials

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/material-testimonials/css/style.css/wp-content/plugins/material-testimonials/css/owl.carousel.min.css/wp-content/plugins/material-testimonials/css/font-awesome.min.css/wp-content/plugins/material-testimonials/js/owl.carousel.min.js
Version Parameters
material-testimonials/css/style.css?ver=material-testimonials/css/owl.carousel.min.css?ver=material-testimonials/css/font-awesome.min.css?ver=material-testimonials/js/owl.carousel.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
material-testimonialstestimonialstyle1style2style3style4testimonial-wrappertestimonial-image+9 more
Data Attributes
mattesti-bg-colormattesti-text-colormattesti-sub-titlemattesti-facebook-urlmattesti-twitter-urlmattesti-linkedin-url+1 more
JS Globals
MATTESTI_PLUGIN
Shortcode Output
<div id='material-testimonials-class="material-testimonials owl-carousel owl-theme"<div class="item"><div class="testimonial style4 shadow"
FAQ

Frequently Asked Questions about Material Testimonials