Testimonial Slider – Free Testimonials Slider Plugin Security & Risk Analysis

wordpress.org/plugins/testimonial-add

Testimonial Slider plugin is the only plugin you will need to display testimonials on your site, Create testimonial slider or list and design as per y …

800 active installs v3.5.8.6 PHP + WP 3.4+ Updated Apr 24, 2023
easy-testimonial-slidersimple-testimonialslidertestimonialtestimonials
59
C · Use Caution
CVEs total2
Unpatched1
Last CVESep 26, 2025
Safety Verdict

Is Testimonial Slider – Free Testimonials Slider Plugin Safe to Use in 2026?

Use With Caution

Score 59/100

Testimonial Slider – Free Testimonials Slider Plugin has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

2 known CVEs 1 unpatched Last CVE: Sep 26, 2025Updated 2yr ago
Risk Assessment

The "testimonial-add" plugin v3.5.8.6 exhibits a mixed security posture. On the positive side, the static analysis reveals strong adherence to secure coding practices in several areas. There are no dangerous functions used, all SQL queries are prepared, and a very high percentage of output is properly escaped. The plugin also implements nonce and capability checks, limiting its direct attack surface. However, a significant concern arises from its vulnerability history, which includes two known CVEs, one of which remains unpatched. The nature of these past vulnerabilities, particularly 'PHP Remote File Inclusion' and 'Cross-site Scripting,' suggests potential risks related to input sanitization and file handling, despite the current static analysis not flagging direct issues in these categories. The presence of an unpatched high-severity vulnerability is a critical indicator of ongoing risk.

While the current code analysis doesn't reveal immediate exploitable flaws, the historical pattern of vulnerabilities cannot be ignored. The unpatched high-severity CVE points to a significant, known risk that requires immediate attention. The plugin's strengths in secure coding practices are commendable, but they are overshadowed by the existence of an unpatched vulnerability. Therefore, while the plugin demonstrates good development habits in some aspects, the unaddressed historical vulnerability significantly elevates its risk profile.

Key Concerns

  • Unpatched high-severity CVE exists
  • One past medium severity CVE
Vulnerabilities
2

Testimonial Slider – Free Testimonials Slider Plugin Security Vulnerabilities

CVEs by Year

1 CVE in 2022
2022
1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

High
1
Medium
1

2 total CVEs

CVE-2025-60126high · 7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

Testimonial Slider <= 3.5.8.6 - Authenticated (Contributor+) Local File Inclusion

Sep 26, 2025Unpatched
CVE-2021-36851medium · 4.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Testimonials Slider <= 3.5.8.3 - Authenticated (Editor+) Stored Cross-Site Scripting

Apr 4, 2022 Patched in 3.5.8.4 (658d)
Code Analysis
Analyzed Mar 16, 2026

Testimonial Slider – Free Testimonials Slider Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
31
622 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

95% escaped653 total outputs
Attack Surface

Testimonial Slider – Free Testimonials Slider Plugin Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[tss_slider] mpsp_shortcode_gen.php:4
WordPress Hooks 16
actionadmin_noticesAsk-Rev.php:10
actionadmin_initAsk-Rev.php:13
actionadmin_initAsk-Rev.php:78
actionadd_meta_boxesmpsp_metaboxes.php:4
actionsave_postmpsp_metaboxes.php:17
filterinitmpsp_scripts.php:20
filterinitmpsp_scripts.php:29
actionadmin_enqueue_scriptsmpsp_scripts.php:46
actionadmin_initTestimonials.php:20
actionadmin_menutss_admin_pages.php:4
actioninittss_mpsp_cs_post_type.php:48
actioninittss_mpsp_cs_post_type.php:94
filtermanage_tss_slider_posts_columnstss_mpsp_cs_post_type.php:109
actionmanage_tss_slider_posts_custom_columntss_mpsp_cs_post_type.php:110
actionwp_headTss_Settings.php:5
actionadmin_initTss_Settings.php:29
Maintenance & Trust

Testimonial Slider – Free Testimonials Slider Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedApr 24, 2023
PHP min version
Downloads73K

Community Trust

Rating82/100
Number of ratings27
Active installs800
Developer Profile

Testimonial Slider – Free Testimonials Slider Plugin Developer Profile

PluginOps

11 plugins · 15K total installs

66
trust score
Avg Security Score
82/100
Avg Patch Time
445 days
View full developer profile
Detection Fingerprints

How We Detect Testimonial Slider – Free Testimonials Slider Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/testimonial-add/css/custom_style.css/wp-content/plugins/testimonial-add/owl-carousel/owl.carousel.css/wp-content/plugins/testimonial-add/owl-carousel/owl.theme.css/wp-content/plugins/testimonial-add/owl-carousel/owl.transitions.css/wp-content/plugins/testimonial-add/image-upload.js/wp-content/plugins/testimonial-add/lpp_color_picker.js
Script Paths
/wp-content/plugins/testimonial-add/owl-carousel/owl.carousel.js

HTML / DOM Fingerprints

CSS Classes
lpp_formlpp_inputlpp_label
Data Attributes
data-plugin-name="testimonial-add"
JS Globals
window.tss_slider_script
Shortcode Output
[tss_slider id=null]
FAQ

Frequently Asked Questions about Testimonial Slider – Free Testimonials Slider Plugin