
Super Easy Testimonials Security & Risk Analysis
wordpress.org/plugins/super-easy-testimonialsSuper Easy Testimonials adds flexibility to your wordpress site in creating and managing testimonials.
Is Super Easy Testimonials Safe to Use in 2026?
Generally Safe
Score 85/100Super Easy Testimonials has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "super-easy-testimonials" plugin v1.1.1 exhibits a mixed security posture. On the positive side, there are no known CVEs, a relatively small attack surface consisting of a single shortcode, and no external HTTP requests or bundled libraries. The code also shows a good proportion of SQL queries utilizing prepared statements.
However, significant concerns arise from the static analysis. The most critical issue is a single flow identified by taint analysis as having unsanitized paths with high severity. This is particularly worrying as it bypasses all capability checks and nonce verifications. Furthermore, a low percentage of output escaping (37%) indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, especially in conjunction with the potential for unsanitized paths. The presence of file operations also warrants careful review, as it could be exploited if combined with other weaknesses.
While the plugin has no recorded vulnerability history, this does not guarantee future safety, especially given the identified critical taint flow and poor output escaping. The lack of nonce and capability checks on its entry points is a major oversight. Overall, the plugin has several critical security weaknesses that need immediate attention, outweighing its positive aspects.
Key Concerns
- High severity taint flow with unsanitized paths
- Low percentage of output escaping (37%)
- 0 Nonce checks on entry points
- 0 Capability checks on entry points
- Presence of file operations
Super Easy Testimonials Security Vulnerabilities
Super Easy Testimonials Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Super Easy Testimonials Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
Super Easy Testimonials Maintenance & Trust
Maintenance Signals
Community Trust
Super Easy Testimonials Alternatives
Testimonial Slider – Free Testimonials Slider Plugin
testimonial-add
Testimonial Slider plugin is the only plugin you will need to display testimonials on your site, Create testimonial slider or list and design as per y …
WP Testimonial
wp-testimonial
Add Testimonials on Your Website.
Migrate away from Easy Testimonials
strong-testimonials-migrate-from-easy-testimonials
Migrate away from Easy Testimonials is the official migrator from Easy Testimonials to Strong Testimonials
LR WP Testimonials with slider
lr-wp-testimonials-with-slider
This plugin adds a "LR Testimonials" section to the admin panel. A flexible plugin with everything you need to display testimonials.
Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More
reviews-feed
No API key required. Display Yelp and Google reviews for any business in a clean, customizable feed on your site.
Super Easy Testimonials Developer Profile
1 plugin · 10 total installs
How We Detect Super Easy Testimonials
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/super-easy-testimonials/images/photo-bg.png/wp-content/plugins/super-easy-testimonials/images/photo.jpgHTML / DOM Fingerprints
photo-bglaquoraquocontentsign<div id='block'><p class='content'><span class='laquo'> </span><span class='raquo'> </span></p><div class='sign'>