Stars Testimonials — Responsive Reviews & Star Ratings Security & Risk Analysis

wordpress.org/plugins/stars-testimonials-with-slider-and-masonry-grid

Testimonials & reviews WordPress plugin for your website. Display responsive website testimonials and customer reviews with ease ⭐

1K active installs v3.3.5 PHP + WP 3.5+ Updated Dec 11, 2025
collect-reviewscollect-testimonialscustomers-reviewsreviewstestimonials
95
A · Safe
CVEs total3
Unpatched0
Last CVENov 10, 2025
Safety Verdict

Is Stars Testimonials — Responsive Reviews & Star Ratings Safe to Use in 2026?

Generally Safe

Score 95/100

Stars Testimonials — Responsive Reviews & Star Ratings has a strong security track record. Known vulnerabilities have been patched promptly.

3 known CVEsLast CVE: Nov 10, 2025Updated 3mo ago
Risk Assessment

The "stars-testimonials-with-slider-and-masonry-grid" plugin v3.3.5 presents a mixed security posture. While it demonstrates good practices in several areas, such as the consistent use of prepared statements for all SQL queries and a high percentage of properly escaped output, there are significant areas of concern. The presence of one AJAX handler without authentication checks represents a direct entry point for potential unauthorized actions or information disclosure. Furthermore, the static analysis reveals two flows with unsanitized paths, indicating a potential risk of vulnerabilities like Local File Inclusion if not handled carefully by the application logic.

The plugin's vulnerability history is particularly noteworthy, with three known CVEs, including one high and two medium severity vulnerabilities. These historical issues, specifically related to Improper Control of Filename for Include/Require Statement and Cross-site Scripting, suggest recurring weaknesses in how the plugin handles user-supplied input and file operations. The fact that the last vulnerability was relatively recent (2025-11-10) implies that past patching efforts may not have fully addressed underlying architectural flaws or that new vulnerabilities continue to be discovered. While there are currently no unpatched CVEs, the historical pattern warrants vigilance.

In conclusion, the plugin exhibits strengths in its SQL handling and output escaping. However, the unprotected AJAX handler, unsanitized input paths identified in taint analysis, and a history of serious vulnerabilities, particularly RFI and XSS, significantly elevate its risk profile. Users should be aware of these ongoing risks and ensure they are using the latest patched version, as well as implement additional security measures on their WordPress sites.

Key Concerns

  • Unprotected AJAX handler
  • Flows with unsanitized paths detected
  • History of High severity CVEs
  • History of Medium severity CVEs
Vulnerabilities
3

Stars Testimonials — Responsive Reviews & Star Ratings Security Vulnerabilities

CVEs by Year

2 CVEs in 2024
2024
1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

High
1
Medium
2

3 total CVEs

CVE-2025-67912medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Stars Testimonials <= 3.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

Nov 10, 2025 Patched in 3.3.5 (40d)
CVE-2024-11429high · 8.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

Free Responsive Testimonials, Social Proof Reviews, and Customer Reviews – Stars Testimonials <= 3.3.3 - Authenticated (Contributor+) Local File Inclusion

Dec 4, 2024 Patched in 3.3.4 (1d)
CVE-2024-8989medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Stars Testimonials <= 3.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via stars_testimonials Shortcode

Sep 30, 2024 Patched in 3.3.2 (1d)
Code Analysis
Analyzed Mar 16, 2026

Stars Testimonials — Responsive Reviews & Star Ratings Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
7 prepared
Unescaped Output
98
945 escaped
Nonce Checks
11
Capability Checks
23
File Operations
0
External Requests
8
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

100% prepared7 total queries

Output Escaping

91% escaped1043 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

7 flows2 with unsanitized paths
<add-new-shortcode> (add-new-shortcode.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Stars Testimonials — Responsive Reviews & Star Ratings Attack Surface

Entry Points10
Unprotected1

AJAX Handlers 8

authwp_ajax_save_testimonial_settingplugin.class.php:36
authwp_ajax_remove_testimonial_recordplugin.class.php:38
authwp_ajax_testimonial_pro_popupplugin.class.php:40
authwp_ajax_save_premio_testimonial_postplugin.class.php:42
authwp_ajax_update_premio_testimonial_postplugin.class.php:44
authwp_ajax_wcp_star_testimonial_send_message_to_ownerplugin.class.php:56
authwp_ajax_star_testimonials_plugin_deactivateplugin.class.php:67
authwp_ajax_stars_testimonials_update_statusplugin.class.php:69

Shortcodes 2

[stars_testimonials] plugin.class.php:26
[testimonial_stars] plugin.class.php:27
WordPress Hooks 29
actionadmin_enqueue_scriptsclass-review-box.php:84
actionadmin_noticesclass-review-box.php:85
actionadmin_noticesclass-upgrade-box.php:9
actioninitplugin.class.php:21
filterpost_updated_messagesplugin.class.php:22
actionadd_meta_boxes_stars_testimonialplugin.class.php:23
actionsave_postplugin.class.php:24
actionadmin_menuplugin.class.php:25
actionstars_testimonial_display_ratingplugin.class.php:28
actionstars_testimonial_display_companyplugin.class.php:29
actionvc_before_initplugin.class.php:30
filterenter_title_hereplugin.class.php:31
actionadmin_menuplugin.class.php:32
actionadmin_enqueue_scriptsplugin.class.php:33
actionadmin_enqueue_scriptsplugin.class.php:34
actionedit_form_topplugin.class.php:46
actionadmin_initplugin.class.php:49
actionadmin_footerplugin.class.php:53
actionplugins_loadedplugin.class.php:59
filtermanage_edit-stars_testimonial_columnsplugin.class.php:61
actionmanage_stars_testimonial_posts_custom_columnplugin.class.php:62
actionadmin_initplugin.class.php:64
actionadmin_footerplugin.class.php:66
actionwp_enqueue_scriptsplugin.class.php:71
actionadmin_initplugin.class.php:73
actionadmin_initst.php:103
actionadmin_headst.php:152
actionelementor/widgets/widgets_registeredstars-elementor-class.php:98
actionplugins_loadedstars-elementor.php:67
Maintenance & Trust

Stars Testimonials — Responsive Reviews & Star Ratings Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 11, 2025
PHP min version
Downloads63K

Community Trust

Rating96/100
Number of ratings64
Active installs1K
Developer Profile

Stars Testimonials — Responsive Reviews & Star Ratings Developer Profile

Premio

9 plugins · 651K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
168 days
View full developer profile
Detection Fingerprints

How We Detect Stars Testimonials — Responsive Reviews & Star Ratings

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/stars-testimonials-with-slider-and-masonry-grid/assets/css/style.css/wp-content/plugins/stars-testimonials-with-slider-and-masonry-grid/assets/js/slider.js/wp-content/plugins/stars-testimonials-with-slider-and-masonry-grid/assets/js/masonry.js/wp-content/plugins/stars-testimonials-with-slider-and-masonry-grid/assets/js/frontend.js/wp-content/plugins/stars-testimonials-with-slider-and-masonry-grid/assets/css/frontend.css
Script Paths
/wp-content/plugins/stars-testimonials-with-slider-and-masonry-grid/assets/js/slider.js/wp-content/plugins/stars-testimonials-with-slider-and-masonry-grid/assets/js/masonry.js/wp-content/plugins/stars-testimonials-with-slider-and-masonry-grid/assets/js/frontend.js
Version Parameters
/wp-content/plugins/stars-testimonials-with-slider-and-masonry-grid/assets/css/style.css?ver=/wp-content/plugins/stars-testimonials-with-slider-and-masonry-grid/assets/js/slider.js?ver=/wp-content/plugins/stars-testimonials-with-slider-and-masonry-grid/assets/js/masonry.js?ver=/wp-content/plugins/stars-testimonials-with-slider-and-masonry-grid/assets/js/frontend.js?ver=/wp-content/plugins/stars-testimonials-with-slider-and-masonry-grid/assets/css/frontend.css?ver=

HTML / DOM Fingerprints

CSS Classes
stars-testimonials-slider-wrapperstars-testimonials-masonry-wrapperstars-testimonials-itemstars-testimonials-author-namestars-testimonials-companystars-testimonials-ratingstars-testimonials-text
HTML Comments
<!-- Stars Testimonials Plugin --><!-- Stars Testimonials Slider --><!-- Stars Testimonials Masonry Grid -->
Data Attributes
data-testimonial-styledata-columnsdata-slides-to-scrolldata-scroll-speeddata-navigation-dotsdata-navigation-arrows+9 more
JS Globals
StarsTestimonialSliderStarsTestimonialMasonry
Shortcode Output
[stars_testimonials_slider[stars_testimonials_masonry]
FAQ

Frequently Asked Questions about Stars Testimonials — Responsive Reviews & Star Ratings