
Smart Testimonials plugin Security & Risk Analysis
wordpress.org/plugins/smart-testimonialsSmart testimonials plugin will allow webmaster to turn the boring looking testimonials into a fancy attractive page with several formatting options.
Is Smart Testimonials plugin Safe to Use in 2026?
Generally Safe
Score 85/100Smart Testimonials plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "smart-testimonials" plugin, version 1.0, exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by utilizing prepared statements for all SQL queries and performing a reasonable number of capability checks (5). The absence of any recorded vulnerabilities in its history is also a significant strength, suggesting a developer who is either diligent or has not yet encountered exploitable flaws.
However, there are notable areas of concern. The static analysis reveals one unprotected AJAX handler, which represents a direct attack vector. Furthermore, the taint analysis indicates two flows with unsanitized paths, although these are not flagged as critical or high severity. The most significant weakness lies in output escaping, with only 10% of outputs being properly escaped, leaving the plugin susceptible to Cross-Site Scripting (XSS) vulnerabilities. The bundled jQuery v1.9.1 is also outdated, potentially introducing known security risks if not handled carefully by the theme or other plugins.
In conclusion, while the plugin has a clean vulnerability history and uses prepared statements, the unprotected AJAX handler and the pervasive issue with output escaping present tangible risks. The outdated jQuery version adds another layer of potential concern. The developer should prioritize addressing the XSS vulnerability and securing the AJAX endpoint to significantly improve the plugin's security.
Key Concerns
- Unprotected AJAX handler
- Low output escaping rate (10%)
- Taint flow with unsanitized path
- Bundled outdated jQuery v1.9.1
Smart Testimonials plugin Security Vulnerabilities
Smart Testimonials plugin Release Timeline
Smart Testimonials plugin Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Smart Testimonials plugin Attack Surface
AJAX Handlers 1
Shortcodes 3
WordPress Hooks 13
Maintenance & Trust
Smart Testimonials plugin Maintenance & Trust
Maintenance Signals
Community Trust
Smart Testimonials plugin Alternatives
CP Testimonial
cp-testimonial
settings, star ratings Requires at least: 4.4.2 Tested Up to: 4.4.2 Stable tag: 1.0.0 Third party plugins: Owl Carousel License: GPLv2 CP Testimonial …
WP Client Testimonials
alpharage-testimonials
This plugin allows you to create and display testimonials on multiple Styles.
MBT Testimonial
mbt-testimonial
MBT Testimonial is a fully Responsive & mobile friendly WordPress plugin to manage your client Testimonials.
Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More
reviews-feed
No API key required. Display Yelp and Google reviews for any business in a clean, customizable feed on your site.
Rich Showcase for Google Reviews
widget-google-reviews
Display up to 10 Google reviews in less than a minute. Continue collecting new reviews. No limits on connected places, widgets, shortcodes and blocks.
Smart Testimonials plugin Developer Profile
4 plugins · 240 total installs
How We Detect Smart Testimonials plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/smart-testimonials/inc/js/faq_asp.js/wp-content/plugins/smart-testimonials/inc/style.css/wp-content/plugins/smart-testimonials/inc/css/faq-admin.css/wp-content/plugins/smart-testimonials/inc/js/faq.admin.init.js/wp-content/plugins/smart-testimonials/inc/js/faq_asp.js/wp-content/plugins/smart-testimonials/inc/js/faq.admin.init.jsfaq_accordion_aspireasp_testi_frontfaq-adminHTML / DOM Fingerprints
asp_testidata-posttype="asp_testi"faq_accordion_aspire