
MBT Testimonial Security & Risk Analysis
wordpress.org/plugins/mbt-testimonialMBT Testimonial is a fully Responsive & mobile friendly WordPress plugin to manage your client Testimonials.
Is MBT Testimonial Safe to Use in 2026?
Generally Safe
Score 92/100MBT Testimonial has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'mbt-testimonial' v1.2.2 plugin exhibits a generally good security posture based on the provided static analysis and vulnerability history. The absence of any known CVEs and the lack of critical or high-severity findings in taint analysis are positive indicators. Furthermore, the plugin demonstrates good practices by using prepared statements for all SQL queries. However, there are areas of concern, particularly regarding output escaping, where only 33% of the identified outputs are properly escaped. This leaves room for potential cross-site scripting (XSS) vulnerabilities if user-supplied data is rendered directly to the browser without adequate sanitization. The complete absence of nonce checks and capability checks, while not immediately indicating a vulnerability without specific entry points that require them, suggests a potential oversight in robust authentication and authorization for all potential interactions, especially if the attack surface were to expand in future versions or through interactions with other plugins.
While the plugin's current attack surface is minimal and appears to be free of unprotected entry points, the lack of comprehensive output escaping is a notable weakness. The vulnerability history being clear is a strong positive, suggesting the developers have historically maintained security. The plugin's strengths lie in its secure handling of database interactions and the absence of known vulnerabilities. The primary weakness is the incomplete output escaping, which warrants attention. The lack of nonce and capability checks, though not a direct vulnerability based on the provided data, represents a less-than-ideal security practice that could become an issue if the plugin's functionality or integration with other components changes.
Key Concerns
- Output escaping is not consistently applied
- No nonce checks are implemented
- No capability checks are implemented
MBT Testimonial Security Vulnerabilities
MBT Testimonial Code Analysis
Output Escaping
MBT Testimonial Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
MBT Testimonial Maintenance & Trust
Maintenance Signals
Community Trust
MBT Testimonial Alternatives
Smart Testimonials plugin
smart-testimonials
Smart testimonials plugin will allow webmaster to turn the boring looking testimonials into a fancy attractive page with several formatting options.
Ultimate 3D Testimonial Slider, List & Grid
ultimate-3d-testimonial-slider
Easily create responsive 3D Testimonial Slider, list and Grid layout for WordPress website. Display clean client's testimonial on any page or pos …
CP Testimonial
cp-testimonial
settings, star ratings Requires at least: 4.4.2 Tested Up to: 4.4.2 Stable tag: 1.0.0 Third party plugins: Owl Carousel License: GPLv2 CP Testimonial …
Kento Clients Feedback
kento-clients-feedback
Display Cleants Feedback or Testimonials
WP Client Testimonials
alpharage-testimonials
This plugin allows you to create and display testimonials on multiple Styles.
MBT Testimonial Developer Profile
1 plugin · 0 total installs
How We Detect MBT Testimonial
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mbt-testimonial/assets/css/mbt-testimonial-style.css/wp-content/plugins/mbt-testimonial/assets/owl-carousel-style/owl.carousel.min.css/wp-content/plugins/mbt-testimonial/assets/owl-carousel-style/owl.theme.default.min.css/wp-content/plugins/mbt-testimonial/assets/js/mbt-testimonial-js.js/wp-content/plugins/mbt-testimonial/assets/owl-carousel-js/owl.carousel.js/wp-content/plugins/mbt-testimonial/assets/js/mbt-testimonial-js.js/wp-content/plugins/mbt-testimonial/assets/owl-carousel-js/owl.carousel.jsmbt-testimonial-style.css?ver=1.0.1owl.carousel.min.css?ver=1.4owl.theme.default.min.css?ver=1.5mbt-testimonial-js.js?ver=1.2owl.carousel.js?ver=1.3HTML / DOM Fingerprints
mbt-containermbt-contentmbt-author-imgmbt-author-namembt-content-descriptionmbt-author-destinationmbt-company-namembt-userrolembt-company<div class="mbt-container"><div class="owl-carousel"><div class="mbt-content"><div class="mbt-author-img">