
Stars Testimonials — Responsive Reviews & Star Ratings Security & Risk Analysis
wordpress.org/plugins/stars-testimonials-with-slider-and-masonry-gridTestimonials & reviews WordPress plugin for your website. Display responsive website testimonials and customer reviews with ease ⭐
Is Stars Testimonials — Responsive Reviews & Star Ratings Safe to Use in 2026?
Generally Safe
Score 95/100Stars Testimonials — Responsive Reviews & Star Ratings has a strong security track record. Known vulnerabilities have been patched promptly.
The "stars-testimonials-with-slider-and-masonry-grid" plugin v3.3.5 presents a mixed security posture. While it demonstrates good practices in several areas, such as the consistent use of prepared statements for all SQL queries and a high percentage of properly escaped output, there are significant areas of concern. The presence of one AJAX handler without authentication checks represents a direct entry point for potential unauthorized actions or information disclosure. Furthermore, the static analysis reveals two flows with unsanitized paths, indicating a potential risk of vulnerabilities like Local File Inclusion if not handled carefully by the application logic.
The plugin's vulnerability history is particularly noteworthy, with three known CVEs, including one high and two medium severity vulnerabilities. These historical issues, specifically related to Improper Control of Filename for Include/Require Statement and Cross-site Scripting, suggest recurring weaknesses in how the plugin handles user-supplied input and file operations. The fact that the last vulnerability was relatively recent (2025-11-10) implies that past patching efforts may not have fully addressed underlying architectural flaws or that new vulnerabilities continue to be discovered. While there are currently no unpatched CVEs, the historical pattern warrants vigilance.
In conclusion, the plugin exhibits strengths in its SQL handling and output escaping. However, the unprotected AJAX handler, unsanitized input paths identified in taint analysis, and a history of serious vulnerabilities, particularly RFI and XSS, significantly elevate its risk profile. Users should be aware of these ongoing risks and ensure they are using the latest patched version, as well as implement additional security measures on their WordPress sites.
Key Concerns
- Unprotected AJAX handler
- Flows with unsanitized paths detected
- History of High severity CVEs
- History of Medium severity CVEs
Stars Testimonials — Responsive Reviews & Star Ratings Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Stars Testimonials <= 3.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
Free Responsive Testimonials, Social Proof Reviews, and Customer Reviews – Stars Testimonials <= 3.3.3 - Authenticated (Contributor+) Local File Inclusion
Stars Testimonials <= 3.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via stars_testimonials Shortcode
Stars Testimonials — Responsive Reviews & Star Ratings Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Stars Testimonials — Responsive Reviews & Star Ratings Attack Surface
AJAX Handlers 8
Shortcodes 2
WordPress Hooks 29
Maintenance & Trust
Stars Testimonials — Responsive Reviews & Star Ratings Maintenance & Trust
Maintenance Signals
Community Trust
Stars Testimonials — Responsive Reviews & Star Ratings Alternatives
Wiremo – Customer reviews for WordPress
wp-reviews-by-wiremo
Customer review platform for WordPress. Automatically gather, control and display your best reviews without tech hassles. Free up time to grow your br …
Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More
reviews-feed
No API key required. Display Yelp and Google reviews for any business in a clean, customizable feed on your site.
Rich Showcase for Google Reviews
widget-google-reviews
Display up to 10 Google reviews in less than a minute. Continue collecting new reviews. No limits on connected places, widgets, shortcodes and blocks.
Site Reviews
site-reviews
Site Reviews is a complete review management solution that integrates with WooCommerce and SureCart and works similarly to reviews on Amazon, Tripadvi …
WP Google Review Slider
wp-google-places-review-slider
Display Google reviews on your site and even show user images! No address, no problem! Also works with Service Area Businesses and Products! Lightwei …
Stars Testimonials — Responsive Reviews & Star Ratings Developer Profile
9 plugins · 651K total installs
How We Detect Stars Testimonials — Responsive Reviews & Star Ratings
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/stars-testimonials-with-slider-and-masonry-grid/assets/css/style.css/wp-content/plugins/stars-testimonials-with-slider-and-masonry-grid/assets/js/slider.js/wp-content/plugins/stars-testimonials-with-slider-and-masonry-grid/assets/js/masonry.js/wp-content/plugins/stars-testimonials-with-slider-and-masonry-grid/assets/js/frontend.js/wp-content/plugins/stars-testimonials-with-slider-and-masonry-grid/assets/css/frontend.css/wp-content/plugins/stars-testimonials-with-slider-and-masonry-grid/assets/js/slider.js/wp-content/plugins/stars-testimonials-with-slider-and-masonry-grid/assets/js/masonry.js/wp-content/plugins/stars-testimonials-with-slider-and-masonry-grid/assets/js/frontend.js/wp-content/plugins/stars-testimonials-with-slider-and-masonry-grid/assets/css/style.css?ver=/wp-content/plugins/stars-testimonials-with-slider-and-masonry-grid/assets/js/slider.js?ver=/wp-content/plugins/stars-testimonials-with-slider-and-masonry-grid/assets/js/masonry.js?ver=/wp-content/plugins/stars-testimonials-with-slider-and-masonry-grid/assets/js/frontend.js?ver=/wp-content/plugins/stars-testimonials-with-slider-and-masonry-grid/assets/css/frontend.css?ver=HTML / DOM Fingerprints
stars-testimonials-slider-wrapperstars-testimonials-masonry-wrapperstars-testimonials-itemstars-testimonials-author-namestars-testimonials-companystars-testimonials-ratingstars-testimonials-text<!-- Stars Testimonials Plugin --><!-- Stars Testimonials Slider --><!-- Stars Testimonials Masonry Grid -->data-testimonial-styledata-columnsdata-slides-to-scrolldata-scroll-speeddata-navigation-dotsdata-navigation-arrows+9 moreStarsTestimonialSliderStarsTestimonialMasonry[stars_testimonials_slider[stars_testimonials_masonry]