Simple Testimonials Showcase Security & Risk Analysis

wordpress.org/plugins/simple-testimonials-showcase

This plugin allows you to create and display testimonials in multiple ways.

600 active installs v1.1.6 PHP + WP 4.4+ Updated May 24, 2024
clients-feedbackgrid-layoutpublish-feedbackquote-layout-testimonialsquotes
49
D · High Risk
CVEs total3
Unpatched2
Last CVEOct 15, 2024
Safety Verdict

Is Simple Testimonials Showcase Safe to Use in 2026?

High Risk

Score 49/100

Simple Testimonials Showcase carries significant security risk with 3 known CVEs, 2 still unpatched. Consider switching to a maintained alternative.

3 known CVEs 2 unpatched Last CVE: Oct 15, 2024Updated 1yr ago
Risk Assessment

The "simple-testimonials-showcase" plugin exhibits a mixed security posture. On the positive side, the static analysis reveals a relatively small attack surface, with no unprotected AJAX handlers or REST API routes. The code also demonstrates good practices regarding SQL queries, with 100% using prepared statements, and a high percentage of output escaping (96%). There are also capability checks present in the code. However, there are significant concerns stemming from its vulnerability history. The plugin has a history of three known CVEs, with two currently unpatched. These past vulnerabilities predominantly involve Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF), which are critical security issues if left unaddressed. The lack of any nonce checks is also a notable weakness, especially given the history of CSRF vulnerabilities, as nonces are a primary defense against such attacks. The absence of taint analysis results is neutral, as it implies no critical flows were detected, but it doesn't mitigate the risks from known vulnerabilities.

Key Concerns

  • Unpatched CVEs
  • Missing nonce checks
  • Vulnerability history of XSS and CSRF
Vulnerabilities
3

Simple Testimonials Showcase Security Vulnerabilities

CVEs by Year

1 CVE in 2023 · unpatched
2023
2 CVEs in 2024 · unpatched
2024
Patched Has unpatched

Severity Breakdown

Medium
3

3 total CVEs

CVE-2024-49295medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Simple Testimonials Showcase <= 1.1.6 - Authenticated (Editor+) Stored Cross-Site Scripting

Oct 15, 2024Unpatched
CVE-2024-32530medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Simple Testimonials Showcase <= 1.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

Apr 15, 2024 Patched in 1.1.6 (45d)
CVE-2023-48283medium · 4.3Cross-Site Request Forgery (CSRF)

Simple Testimonials Showcase <= 1.1.6 - Cross-Site Request Forgery

Nov 23, 2023Unpatched
Code Analysis
Analyzed Mar 16, 2026

Simple Testimonials Showcase Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
103 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

96% escaped107 total outputs
Attack Surface

Simple Testimonials Showcase Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[simple_testimonials] includes\class-simple-testimonials-showcase-shortcode.php:24
WordPress Hooks 20
actionadmin_headadmin\simple-testimonials-showcase-admin-shortcode-generator.php:27
filtermce_external_pluginsadmin\simple-testimonials-showcase-admin-shortcode-generator.php:57
filtermce_buttonsadmin\simple-testimonials-showcase-admin-shortcode-generator.php:58
actionwp_headincludes\class-simple-testimonials-showcase-color-option.php:25
actionadd_meta_boxesincludes\class-simple-testimonials-showcase-meta-box.php:25
actionsave_postincludes\class-simple-testimonials-showcase-meta-box.php:28
actioninitincludes\class-simple-testimonials-showcase-post-type.php:24
actionadmin_initincludes\class-simple-testimonials-showcase-post-type.php:27
filtermanage_edit-simple_testimonials_columnsincludes\class-simple-testimonials-showcase-post-type.php:161
filtermanage_simple_testimonials_posts_custom_columnincludes\class-simple-testimonials-showcase-post-type.php:164
actionadmin_headincludes\class-simple-testimonials-showcase-post-type.php:167
actionadmin_menuincludes\class-simple-testimonials-showcase-settings.php:24
actionadmin_noticesincludes\class-simple-testimonials-showcase-settings.php:27
filterthe_contentincludes\class-simple-testimonials-showcase-shortcode.php:27
actionplugins_loadedincludes\class-simple-testimonials-showcase.php:127
actionadmin_enqueue_scriptsincludes\class-simple-testimonials-showcase.php:142
actionadmin_enqueue_scriptsincludes\class-simple-testimonials-showcase.php:143
actionwp_enqueue_scriptsincludes\class-simple-testimonials-showcase.php:158
actionwp_enqueue_scriptsincludes\class-simple-testimonials-showcase.php:159
filterbody_classpublic\class-simple-testimonials-showcase-public.php:62
Maintenance & Trust

Simple Testimonials Showcase Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedMay 24, 2024
PHP min version
Downloads37K

Community Trust

Rating100/100
Number of ratings1
Active installs600
Developer Profile

Simple Testimonials Showcase Developer Profile

PressTigers

12 plugins · 32K total installs

68
trust score
Avg Security Score
84/100
Avg Patch Time
317 days
View full developer profile
Detection Fingerprints

How We Detect Simple Testimonials Showcase

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/simple-testimonials-showcase/admin/css/simple-testimonials-showcase-admin.css/wp-content/plugins/simple-testimonials-showcase/admin/js/simple-testimonials-showcase-admin.js/wp-content/plugins/simple-testimonials-showcase/admin/js/wp-color-picker-alpha.js
Script Paths
/wp-content/plugins/simple-testimonials-showcase/admin/js/simple-testimonials-showcase-admin.js/wp-content/plugins/simple-testimonials-showcase/admin/js/wp-color-picker-alpha.js
Version Parameters
simple-testimonials-showcase/admin/css/simple-testimonials-showcase-admin.css?ver=simple-testimonials-showcase/admin/js/simple-testimonials-showcase-admin.js?ver=wp-color-picker-alpha?ver=1.0.0

HTML / DOM Fingerprints

CSS Classes
sts-containersts-block
Data Attributes
data-sts-id
JS Globals
sts_color_optionswpColorPickerL10n
Shortcode Output
[simple_testimonials]
FAQ

Frequently Asked Questions about Simple Testimonials Showcase