MBT Testimonial Security & Risk Analysis

wordpress.org/plugins/mbt-testimonial

MBT Testimonial is a fully Responsive & mobile friendly WordPress plugin to manage your client Testimonials.

0 active installs v1.2.2 PHP 7.0+ WP 4.9+ Updated Jul 5, 2024
carousel-sliderclients-testimonialslider-testimonialtestimonial
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is MBT Testimonial Safe to Use in 2026?

Generally Safe

Score 92/100

MBT Testimonial has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The 'mbt-testimonial' v1.2.2 plugin exhibits a generally good security posture based on the provided static analysis and vulnerability history. The absence of any known CVEs and the lack of critical or high-severity findings in taint analysis are positive indicators. Furthermore, the plugin demonstrates good practices by using prepared statements for all SQL queries. However, there are areas of concern, particularly regarding output escaping, where only 33% of the identified outputs are properly escaped. This leaves room for potential cross-site scripting (XSS) vulnerabilities if user-supplied data is rendered directly to the browser without adequate sanitization. The complete absence of nonce checks and capability checks, while not immediately indicating a vulnerability without specific entry points that require them, suggests a potential oversight in robust authentication and authorization for all potential interactions, especially if the attack surface were to expand in future versions or through interactions with other plugins.

While the plugin's current attack surface is minimal and appears to be free of unprotected entry points, the lack of comprehensive output escaping is a notable weakness. The vulnerability history being clear is a strong positive, suggesting the developers have historically maintained security. The plugin's strengths lie in its secure handling of database interactions and the absence of known vulnerabilities. The primary weakness is the incomplete output escaping, which warrants attention. The lack of nonce and capability checks, though not a direct vulnerability based on the provided data, represents a less-than-ideal security practice that could become an issue if the plugin's functionality or integration with other components changes.

Key Concerns

  • Output escaping is not consistently applied
  • No nonce checks are implemented
  • No capability checks are implemented
Vulnerabilities
None known

MBT Testimonial Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

MBT Testimonial Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

33% escaped6 total outputs
Attack Surface

MBT Testimonial Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[mbt_testimonial] _inc\mbt-testimonial-page.php:3
WordPress Hooks 4
actioninit_inc\mbt-testimonial-cpt.php:68
actionadd_meta_boxes_inc\mbt-testimonial-fields.php:6
actionsave_post_inc\mbt-testimonial-fields.php:30
actionwp_enqueue_scripts_inc\mbt-testimonial-scripts.php:13
Maintenance & Trust

MBT Testimonial Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.13
Last updatedJul 5, 2024
PHP min version7.0
Downloads8K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

MBT Testimonial Developer Profile

Mehmood Baig Mughal

1 plugin · 0 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect MBT Testimonial

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mbt-testimonial/assets/css/mbt-testimonial-style.css/wp-content/plugins/mbt-testimonial/assets/owl-carousel-style/owl.carousel.min.css/wp-content/plugins/mbt-testimonial/assets/owl-carousel-style/owl.theme.default.min.css/wp-content/plugins/mbt-testimonial/assets/js/mbt-testimonial-js.js/wp-content/plugins/mbt-testimonial/assets/owl-carousel-js/owl.carousel.js
Script Paths
/wp-content/plugins/mbt-testimonial/assets/js/mbt-testimonial-js.js/wp-content/plugins/mbt-testimonial/assets/owl-carousel-js/owl.carousel.js
Version Parameters
mbt-testimonial-style.css?ver=1.0.1owl.carousel.min.css?ver=1.4owl.theme.default.min.css?ver=1.5mbt-testimonial-js.js?ver=1.2owl.carousel.js?ver=1.3

HTML / DOM Fingerprints

CSS Classes
mbt-containermbt-contentmbt-author-imgmbt-author-namembt-content-descriptionmbt-author-destinationmbt-company-name
Data Attributes
mbt-userrolembt-company
Shortcode Output
<div class="mbt-container"><div class="owl-carousel"><div class="mbt-content"><div class="mbt-author-img">
FAQ

Frequently Asked Questions about MBT Testimonial