
Simple Fading Testimonials Widget Security & Risk Analysis
wordpress.org/plugins/simple-fading-testimonials-widgetEasily add revolving and fading testimonials to your site, with a delayed author element, via a widget.
Is Simple Fading Testimonials Widget Safe to Use in 2026?
Generally Safe
Score 85/100Simple Fading Testimonials Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The overall security posture of this plugin, version 1.1.2, appears to be a mixed bag. On the positive side, there are no reported CVEs, no external HTTP requests, no file operations, and all SQL queries utilize prepared statements, indicating good practices in these areas. The absence of a significant attack surface with entry points is also a strong positive.
However, several concerning signals emerge from the static analysis. The presence of the `create_function` dangerous function is a significant red flag, as it can be exploited for code injection if used with untrusted input. Furthermore, the significantly low rate of proper output escaping (16%) suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities. The complete lack of nonce checks and capability checks, especially given the absence of authentication checks on any entry points (though the entry point count is zero), leaves the plugin vulnerable to CSRF and unauthorized actions if entry points were to be introduced or if internal functions are called without proper validation.
The vulnerability history being clean is encouraging, but it doesn't negate the risks identified in the static analysis. The clean history might be due to the low complexity of the plugin or the lack of deep security auditing. In conclusion, while the plugin exhibits strengths in SQL handling and attack surface management, the high potential for XSS due to poor output escaping and the presence of a dangerous function warrant significant caution.
Key Concerns
- Dangerous function detected (create_function)
- Low output escaping rate (16%)
- No nonce checks implemented
- No capability checks implemented
Simple Fading Testimonials Widget Security Vulnerabilities
Simple Fading Testimonials Widget Release Timeline
Simple Fading Testimonials Widget Code Analysis
Dangerous Functions Found
Output Escaping
Simple Fading Testimonials Widget Attack Surface
WordPress Hooks 12
Maintenance & Trust
Simple Fading Testimonials Widget Maintenance & Trust
Maintenance Signals
Community Trust
Simple Fading Testimonials Widget Alternatives
Organic Builder Widgets – Simple WordPress Page Builder
organic-customizer-widgets
A simple WordPress page builder, Organic Builder Widgets provides a collection of 12 custom widgets to be used in the Customizer as content sections.
Easy Quotes
easy-quotes
Collect and show your favorite Quotes / Reviews / Testimonials or any other short snippet of Text.
Simple Testimonials Showcase
simple-testimonials-showcase
This plugin allows you to create and display testimonials in multiple ways.
Stax Addons for Elementor
stax-addons-for-elementor
20+ lightweight widgets and enhancements for Elementor. Modular, fast, and zero bloat — assets load only when used.
Quotes Shortcode and Widget
quotes-shortcode-and-widget
Create Quotes. Nice and easy interface. Insert anywhere in your site - page/post editor, sidebars, template files.
Simple Fading Testimonials Widget Developer Profile
1 plugin · 10 total installs
How We Detect Simple Fading Testimonials Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/simple-fading-testimonials-widget/js/simple-fading-testimonials.js/wp-content/plugins/simple-fading-testimonials-widget/js/simple-fading-testimonials.jssimple-fading-testimonials-widget/js/simple-fading-testimonials.js?ver=simple-fading-testimonials-widget/css/simple-fading-testimonials.css?ver=HTML / DOM Fingerprints
simple-fade-testimonialsdata-sft-transition-timedata-sft-fade-in-timedata-sft-fade-out-timedata-sft-visible-itemsdata-sft-speedsimple_fade_testimonials[simple_fading_testimonials]