Quantivs Testimonials Security & Risk Analysis

wordpress.org/plugins/quantivs-testimonials

A powerful and flexible testimonial management plugin for WordPress. Display beautiful testimonials with ratings, custom layouts, and AJAX pagination.

0 active installs v1.0.0 PHP 7.4+ WP 5.0+ Updated Mar 11, 2026
customer-reviewsfeedbackreviewstestimonial-gridtestimonials
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Quantivs Testimonials Safe to Use in 2026?

Generally Safe

Score 100/100

Quantivs Testimonials has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "quantivs-testimonials" v1.0.0 plugin demonstrates a strong security posture based on the provided static analysis. The absence of dangerous functions, SQL injection vulnerabilities (100% prepared statements), and output escaping issues (100% properly escaped) are significant strengths. Furthermore, the plugin effectively utilizes nonces and capability checks for its entry points, and has no recorded vulnerability history, indicating a commitment to secure development practices. The limited attack surface, consisting of only AJAX handlers and shortcodes, is also a positive sign.

However, while the static analysis reveals no immediate critical flaws, a deeper understanding of the plugin's logic and potential interactions within a WordPress environment would be beneficial. The lack of taint analysis data, while not necessarily indicating a problem, means potential vulnerabilities in handling user-supplied data that could lead to exploits might have been missed. The fact that all AJAX handlers are protected by authentication checks is commendable, but the total number of entry points, though small, still represent potential areas for future vulnerabilities if not continuously monitored.

Overall, this plugin appears to be well-developed from a security perspective at this version. The historical lack of vulnerabilities further supports this. The key strengths lie in its clean code regarding SQL and output handling, and its robust use of WordPress security features. The primary area for vigilance would be ensuring continued secure development practices and potentially enriching static analysis with taint flow data in future versions to cover all potential exploit vectors.

Vulnerabilities
None known

Quantivs Testimonials Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Quantivs Testimonials Release Timeline

v1.0.0Current
Code Analysis
Analyzed Apr 16, 2026

Quantivs Testimonials Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
107 escaped
Nonce Checks
3
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped107 total outputs
Attack Surface

Quantivs Testimonials Attack Surface

Entry Points5
Unprotected0

AJAX Handlers 4

authwp_ajax_quantivs_load_more_testimonialspublic/class-quantivs-testimonial-public.php:46
noprivwp_ajax_quantivs_load_more_testimonialspublic/class-quantivs-testimonial-public.php:47
authwp_ajax_quantivs_paginate_testimonialspublic/class-quantivs-testimonial-public.php:48
noprivwp_ajax_quantivs_paginate_testimonialspublic/class-quantivs-testimonial-public.php:49

Shortcodes 1

[quantivs_testimonials] public/class-quantivs-testimonial-public.php:45
WordPress Hooks 12
actionadmin_menuadmin/class-quantivs-testimonial-admin.php:43
actionadmin_initadmin/class-quantivs-testimonial-admin.php:44
actioninitincludes/class-quantivs-testimonial-block.php:48
actionelementor/widgets/registerincludes/class-quantivs-testimonial-elementor-register.php:26
actionadmin_enqueue_scriptsincludes/class-quantivs-testimonial-loader.php:78
actionadmin_enqueue_scriptsincludes/class-quantivs-testimonial-loader.php:79
actionwp_enqueue_scriptsincludes/class-quantivs-testimonial-loader.php:88
actionwp_enqueue_scriptsincludes/class-quantivs-testimonial-loader.php:89
actioninitincludes/class-quantivs-testimonial-post-type.php:26
actionadd_meta_boxesincludes/class-quantivs-testimonial-post-type.php:27
actionsave_postincludes/class-quantivs-testimonial-post-type.php:28
actionplugins_loadedquantivs-testimonials.php:82
Maintenance & Trust

Quantivs Testimonials Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 11, 2026
PHP min version7.4
Downloads192

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Quantivs Testimonials Developer Profile

fahadquantivs

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Quantivs Testimonials

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/quantivs-testimonials/admin/css/quantivs-testimonial-admin.css/wp-content/plugins/quantivs-testimonials/admin/js/quantivs-testimonial-admin.js
Script Paths
/wp-content/plugins/quantivs-testimonials/admin/js/quantivs-testimonial-admin.js
Version Parameters
quantivs-testimonials/admin/css/quantivs-testimonial-admin.css?ver=quantivs-testimonials/admin/js/quantivs-testimonial-admin.js?ver=

HTML / DOM Fingerprints

JS Globals
QUANTIVS_TESTIMONIAL_VERSION
FAQ

Frequently Asked Questions about Quantivs Testimonials