
Smooth Testimonials Security & Risk Analysis
wordpress.org/plugins/smooth-testimonialsSmooth Testimonial is a powerful and user-friendly WordPress plugin designed to showcase client testimonials with style and ease.
Is Smooth Testimonials Safe to Use in 2026?
Generally Safe
Score 92/100Smooth Testimonials has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "smooth-testimonials" v1.0.1 plugin demonstrates a generally good security posture with several positive indicators. The absence of known CVEs and a clean vulnerability history suggest diligent maintenance and a focus on security by the developers. The code analysis reveals no dangerous functions, no file operations, and no external HTTP requests, further contributing to a reduced attack surface. All SQL queries are properly prepared, and the presence of nonce and capability checks indicates an understanding of WordPress security best practices.
However, there are some areas for concern. A significant portion of output (33%) is not properly escaped, presenting a potential risk for Cross-Site Scripting (XSS) vulnerabilities. While the static analysis shows no critical or high severity taint flows, the unescaped outputs could be exploited if user-supplied data reaches these points without proper sanitization or escaping. The plugin has a single entry point via a shortcode, which, while currently unprotected, is a relatively minor attack vector in isolation. The lack of extensive static analysis, particularly taint analysis, also means that more subtle vulnerabilities might be missed.
Overall, the plugin is in a relatively secure state, primarily due to the lack of known vulnerabilities and the implementation of basic security checks. The main weakness lies in the incomplete output escaping, which requires attention to mitigate potential XSS risks. Developers should prioritize addressing the unescaped outputs to strengthen the plugin's security.
Key Concerns
- Unescaped output detected
- Shortcode without explicit auth check
Smooth Testimonials Security Vulnerabilities
Smooth Testimonials Code Analysis
Output Escaping
Smooth Testimonials Attack Surface
Shortcodes 1
WordPress Hooks 11
Maintenance & Trust
Smooth Testimonials Maintenance & Trust
Maintenance Signals
Community Trust
Smooth Testimonials Alternatives
Testimonial Customer Feedback
testimonial-maker
Display client testimonials with customizable layouts, slider effects, and responsive design. Simple setup with shortcode support.
Five Star Restaurant Reviews
good-reviews-wp
Restaurant reviews made easy. Add and display reviews on your restaurant site using SEO friendly schema markup.
GlowReviews – Smart Feedback & Testimonials
glowreviews
Collect and display customer feedback with star ratings, image uploads, and WordPress user integration.
Scorpiotek Testimonials
scorpiotek-testimonials
A modern WordPress testimonials plugin with slider and star rating.
Whook Testimonials
whook-testimonial
Whook Testimonials is a plugin to use the feedback form on your WordPress website. It is a user friendly and feature rich plugin to add a responsive T …
Smooth Testimonials Developer Profile
2 plugins · 0 total installs
How We Detect Smooth Testimonials
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/smooth-testimonials/frontend/assets/css/swiper-bundle.min.css/wp-content/plugins/smooth-testimonials/frontend/assets/css/style.css/wp-content/plugins/smooth-testimonials/frontend/assets/js/swiper-bundle.min.js/wp-content/plugins/smooth-testimonials/frontend/assets/js/scripts.js/wp-content/plugins/smooth-testimonials/admin/assets/css/all.min.css/wp-content/plugins/smooth-testimonials/admin/assets/css/admin-style.css/wp-content/plugins/smooth-testimonials/admin/assets/js/admin-script.jsfrontend/assets/js/swiper-bundle.min.jsfrontend/assets/js/scripts.jsadmin/assets/js/admin-script.jsstsm-swiperstsm-stylestsm-scriptsstsm-a-font-awesomestsm-admin-stylestsm-admin-scriptHTML / DOM Fingerprints
stsm-testimonial-sliderstsm-testimonial-griddata-slides-desktopdata-slides-laptopdata-slides-tabletdata-slides-mobiledata-slides-desktop-gapdata-slides-laptop-gap+24 morestsm_testimonial_params[stsm_testimonial id=