Simple WP Testimonials Security & Risk Analysis

wordpress.org/plugins/simple-wp-testimonials

Simple WP Testimonials is a plugin that allows you to manage and display testimonials for your blog.

20 active installs v1.0.0 PHP + WP 3.0+ Updated Apr 19, 2015
responsivereviewstestimonialstestimonials-widgetwp-testimonials
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Simple WP Testimonials Safe to Use in 2026?

Generally Safe

Score 85/100

Simple WP Testimonials has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The 'simple-wp-testimonials' plugin version 1.0.0 exhibits a generally good security posture based on the provided static analysis. There are no known CVEs, critical taint flows, or direct SQL injection vulnerabilities evident. The plugin also demonstrates good practices by utilizing prepared statements for its SQL queries and implementing capability checks for its entry points. However, a significant concern arises from the relatively low percentage of properly escaped output (29%). This suggests a potential for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not handled with sufficient sanitization before being displayed. While the attack surface is small and no direct unprotected entry points were found, the unescaped output remains a notable weakness.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

Simple WP Testimonials Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Simple WP Testimonials Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
36
15 escaped
Nonce Checks
3
Capability Checks
5
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

29% escaped51 total outputs
Attack Surface

Simple WP Testimonials Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[testimonials] shortcode.php:2
WordPress Hooks 15
actioninitadmin-functions.php:43
actionload-post.phpadmin-functions.php:143
actionload-post-new.phpadmin-functions.php:144
actionadd_meta_boxesadmin-functions.php:149
actionsave_postadmin-functions.php:152
actionadd_meta_boxesadmin-functions.php:218
actionsave_postadmin-functions.php:219
filtermanage_edit-testimonial-post_columnsadmin-functions.php:313
actionmanage_testimonial-post_posts_custom_columnadmin-functions.php:330
actionadmin_initauthor-image.php:51
actionadd_meta_boxesauthor-image.php:52
filterattachment_fields_to_editauthor-image.php:53
actiondelete_attachmentauthor-image.php:57
actionwp_headindex.php:17
actionwidgets_initwidgets.php:6
Maintenance & Trust

Simple WP Testimonials Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.32
Last updatedApr 19, 2015
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs20
Developer Profile

Simple WP Testimonials Developer Profile

Deepak Sharma

3 plugins · 120 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Simple WP Testimonials

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/simple-wp-testimonials/css/style.css/wp-content/plugins/simple-wp-testimonials/js/jcarousellite_1.0.1c5.js/wp-content/plugins/simple-wp-testimonials/js/ahi-admin.js
Script Paths
/wp-content/plugins/simple-wp-testimonials/js/jcarousellite_1.0.1c5.js/wp-content/plugins/simple-wp-testimonials/js/ahi-admin.js

HTML / DOM Fingerprints

CSS Classes
thickboxhide-if-no-js
Data Attributes
id="ahi_testimonial-image"id="remove-testimonial-image-image"onclick="kdMuFeaImgRemove( 'testimonial-image', 'testimonial-post',
JS Globals
var ahi_thickbox_ready = false;
FAQ

Frequently Asked Questions about Simple WP Testimonials