
TC Testimonials Security & Risk Analysis
wordpress.org/plugins/tc-testimonialTestimonial Slider carousel is an easy plugin to display testimonials of clients,business partners or affiliates along with title, URL on your website …
Is TC Testimonials Safe to Use in 2026?
Mostly Safe
Score 70/100TC Testimonials is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved.
The tc-testimonial plugin, version 1.1.1, presents a mixed security posture. While the static analysis indicates a very small attack surface, with no unprotected entry points, and all SQL queries utilizing prepared statements, several concerning signals emerge. A significant weakness is the complete lack of output escaping, meaning all 27 detected output points are vulnerable to Cross-Site Scripting (XSS) attacks. Furthermore, the absence of nonce and capability checks across all entry points, despite their limited number, exposes the plugin to potential unauthorized actions or data manipulation if an attacker can trigger these entry points.
The vulnerability history reveals a concerning pattern of a known, unpatched medium-severity CVE related to Cross-Site Scripting. This, combined with the static analysis findings of unescaped output, strongly suggests that the plugin is susceptible to XSS vulnerabilities. The fact that the last vulnerability was dated in the future (2025-08-19) might indicate an issue with data accuracy or a theoretical future vulnerability, but it still highlights the plugin's history of security flaws. The lack of taint analysis results could be due to the limited entry points or complexities in the analysis, but it doesn't negate the clear risks identified by other metrics.
In conclusion, while the plugin has a small attack surface and good SQL practices, the critical flaw of unescaped output and the presence of an unpatched XSS vulnerability are major security concerns. The lack of nonce and capability checks further amplifies these risks. Users should exercise extreme caution or consider alternative plugins until these issues are addressed. The overall security posture leans towards concerning due to the exploitable XSS and unpatched history.
Key Concerns
- Unpatched CVE (Medium Severity)
- No output escaping
- No nonce checks
- No capability checks
TC Testimonials Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
TC Testimonials <= 1.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
TC Testimonials Release Timeline
TC Testimonials Code Analysis
Output Escaping
TC Testimonials Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
TC Testimonials Maintenance & Trust
Maintenance Signals
Community Trust
TC Testimonials Alternatives
Strong Testimonials
strong-testimonials
An easy-to-use testimonial plugin to collect and show customer feedback in WordPress
WP Testimonials
testimonial-widgets
Display your Testimonials on your website fast and easily. 21 widget types, 25 widget styles available. (Free Plugin)
Widgets for Thumbtack Reviews
widgets-for-thumbtack-reviews
Embed Thumbtack reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Thumbtack reviews.
Clean Testimonials
clean-testimonials
Add Testimonials to your WordPress website. Simple, easy, quick and clean.
Widgets for Ebay Reviews
widgets-for-ebay-reviews
Embed Ebay reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Ebay reviews.
TC Testimonials Developer Profile
7 plugins · 3K total installs
How We Detect TC Testimonials
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tc-testimonial/vendors/owl-carousel/assets/owl.carousel.css/wp-content/plugins/tc-testimonial/assets/css/tc-testimonial.css/wp-content/plugins/tc-testimonial/assets/css/tc-admin.css/wp-content/plugins/tc-testimonial/vendors/owl-carousel/owl.carousel.min.jstc-testimonial/vendors/owl-carousel/owl.carousel.min.js?ver=tc-testimonial/assets/css/tc-testimonial.css?ver=tc-testimonial/assets/css/tc-admin.css?ver=HTML / DOM Fingerprints
tc-testimonial-wraptc-clienttc-contenttc-testimonial-singletc-client-thumbtc-author-detailsjQuery<style media="screen">.tc-testimonial-wrap .owl-theme .owl-nav [class*='owl-'] {.tc-testimonial-wrap .owl-theme .owl-dots .owl-dot span {.tc-content p:before,.tc-content p:after {