
Row Column Testimonials with widget Security & Risk Analysis
wordpress.org/plugins/row-column-testmonial-with-widgetA quick, easy way to add and display responsive, clean client's testimonial on your website using a shortcode or a widget.
Is Row Column Testimonials with widget Safe to Use in 2026?
Generally Safe
Score 100/100Row Column Testimonials with widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "row-column-testmonial-with-widget" version 1.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and implementing capability checks for its entry points. The absence of known CVEs and any recorded vulnerability history suggests a history of relative security, which is a significant strength. Furthermore, the limited attack surface, with only two shortcodes and no AJAX handlers or REST API routes, reduces the potential for exploitation.
However, there are notable concerns within the code analysis. The presence of the `create_function` dangerous function is a critical red flag, as it can be misused to execute arbitrary code if not handled with extreme care and sanitization, though the taint analysis doesn't currently show exploitable flows. More concerning is the low percentage of properly escaped output (30%). This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data or data that is not properly sanitized before being outputted to the browser can be injected with malicious scripts. While the taint analysis currently shows no unsanitized paths, the widespread lack of output escaping is a substantial and inherent risk that requires immediate attention.
In conclusion, while the plugin benefits from a clean vulnerability history and sound practices in areas like SQL querying and capability checks, the significant number of unescaped outputs and the presence of a dangerous function present substantial risks. The low output escaping percentage is the most pressing issue, as it directly points to likely XSS vulnerabilities. Addressing this and the use of `create_function` should be prioritized.
Key Concerns
- Low percentage of properly escaped output
- Presence of dangerous function 'create_function'
Row Column Testimonials with widget Security Vulnerabilities
Row Column Testimonials with widget Code Analysis
Dangerous Functions Found
Output Escaping
Row Column Testimonials with widget Attack Surface
Shortcodes 2
WordPress Hooks 10
Maintenance & Trust
Row Column Testimonials with widget Maintenance & Trust
Maintenance Signals
Community Trust
Row Column Testimonials with widget Alternatives
Rich Showcase for Google Reviews
widget-google-reviews
Display up to 10 Google reviews in less than a minute. Continue collecting new reviews. No limits on connected places, widgets, shortcodes and blocks.
WP Testimonials
testimonial-widgets
Display your Testimonials on your website fast and easily. 21 widget types, 25 widget styles available. (Free Plugin)
Testimonial Grid and Testimonial Slider plus Carousel with Rotator Widget
wp-testimonial-with-widget
A quick, easy way to add and display responsive, clean client's testimonial on your website using a shortcode, widget or Gutenberg block.
Organic Builder Widgets – Simple WordPress Page Builder
organic-customizer-widgets
A simple WordPress page builder, Organic Builder Widgets provides a collection of 12 custom widgets to be used in the Customizer as content sections.
BNE Testimonials
bne-testimonials
Display testimonials and reviews on any page or widget area as list or slider. Upgrade to PRO for additional layouts, themes, submission form, API, ra …
Row Column Testimonials with widget Developer Profile
5 plugins · 960 total installs
How We Detect Row Column Testimonials with widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/row-column-testmonial-with-widget/assets/css/testimonials-style.css/wp-content/plugins/row-column-testmonial-with-widget/assets/css/slick.css/wp-content/plugins/row-column-testmonial-with-widget/assets/js/slick.min.js/wp-content/plugins/row-column-testmonial-with-widget/assets/js/slick.min.jsrow-column-testmonial-with-widget/assets/css/testimonials-style.css?ver=row-column-testmonial-with-widget/assets/css/slick.css?ver=row-column-testmonial-with-widget/assets/js/slick.min.js?ver=HTML / DOM Fingerprints
wtwp-testimonials-slidelisttestimonials-slidelistquoteno-imagejQuery[rct_testimonials_slider][rct_get_testimonial