
Testimonial Slider – Free Testimonials Slider Plugin Security & Risk Analysis
wordpress.org/plugins/testimonial-addTestimonial Slider plugin is the only plugin you will need to display testimonials on your site, Create testimonial slider or list and design as per y …
Is Testimonial Slider – Free Testimonials Slider Plugin Safe to Use in 2026?
Use With Caution
Score 59/100Testimonial Slider – Free Testimonials Slider Plugin has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "testimonial-add" plugin v3.5.8.6 exhibits a mixed security posture. On the positive side, the static analysis reveals strong adherence to secure coding practices in several areas. There are no dangerous functions used, all SQL queries are prepared, and a very high percentage of output is properly escaped. The plugin also implements nonce and capability checks, limiting its direct attack surface. However, a significant concern arises from its vulnerability history, which includes two known CVEs, one of which remains unpatched. The nature of these past vulnerabilities, particularly 'PHP Remote File Inclusion' and 'Cross-site Scripting,' suggests potential risks related to input sanitization and file handling, despite the current static analysis not flagging direct issues in these categories. The presence of an unpatched high-severity vulnerability is a critical indicator of ongoing risk.
While the current code analysis doesn't reveal immediate exploitable flaws, the historical pattern of vulnerabilities cannot be ignored. The unpatched high-severity CVE points to a significant, known risk that requires immediate attention. The plugin's strengths in secure coding practices are commendable, but they are overshadowed by the existence of an unpatched vulnerability. Therefore, while the plugin demonstrates good development habits in some aspects, the unaddressed historical vulnerability significantly elevates its risk profile.
Key Concerns
- Unpatched high-severity CVE exists
- One past medium severity CVE
Testimonial Slider – Free Testimonials Slider Plugin Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Testimonial Slider <= 3.5.8.6 - Authenticated (Contributor+) Local File Inclusion
Testimonials Slider <= 3.5.8.3 - Authenticated (Editor+) Stored Cross-Site Scripting
Testimonial Slider – Free Testimonials Slider Plugin Code Analysis
Output Escaping
Testimonial Slider – Free Testimonials Slider Plugin Attack Surface
Shortcodes 1
WordPress Hooks 16
Maintenance & Trust
Testimonial Slider – Free Testimonials Slider Plugin Maintenance & Trust
Maintenance Signals
Community Trust
Testimonial Slider – Free Testimonials Slider Plugin Alternatives
WP Testimonial
wp-testimonial
Add Testimonials on Your Website.
Strong Testimonials
strong-testimonials
An easy-to-use testimonial plugin to collect and show customer feedback in WordPress
Real Testimonials – Testimonial Slider, Collect Customer Reviews and Video Testimonials
testimonial-free
A Customizable Testimonial plugin to Automate Collecting, Filtering, and Publishing Customer Reviews. Testimonial Slider, Grid & More to Grow Sales
WP Google Review Slider
wp-google-places-review-slider
Display Google reviews on your site and even show user images! No address, no problem! Also works with Service Area Businesses and Products! Lightwei …
Testimonial Grid and Testimonial Slider plus Carousel with Rotator Widget
wp-testimonial-with-widget
A quick, easy way to add and display responsive, clean client's testimonial on your website using a shortcode, widget or Gutenberg block.
Testimonial Slider – Free Testimonials Slider Plugin Developer Profile
11 plugins · 15K total installs
How We Detect Testimonial Slider – Free Testimonials Slider Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/testimonial-add/css/custom_style.css/wp-content/plugins/testimonial-add/owl-carousel/owl.carousel.css/wp-content/plugins/testimonial-add/owl-carousel/owl.theme.css/wp-content/plugins/testimonial-add/owl-carousel/owl.transitions.css/wp-content/plugins/testimonial-add/image-upload.js/wp-content/plugins/testimonial-add/lpp_color_picker.js/wp-content/plugins/testimonial-add/owl-carousel/owl.carousel.jsHTML / DOM Fingerprints
lpp_formlpp_inputlpp_labeldata-plugin-name="testimonial-add"window.tss_slider_script[tss_slider id=null]