
Testimonial Moving Security & Risk Analysis
wordpress.org/plugins/testimonial-movingEasily add and manage Testimonials to your site.
Is Testimonial Moving Safe to Use in 2026?
Generally Safe
Score 100/100Testimonial Moving has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "testimonial-moving" plugin version 1.0.0 exhibits a generally good security posture based on the provided static analysis. A significant strength is the complete absence of known vulnerabilities, indicating a history of stable and secure development. The plugin also demonstrates good practices by utilizing prepared statements for all SQL queries and implementing nonce and capability checks, although the latter are limited in number. The limited attack surface, with no unprotected AJAX handlers or REST API routes, is also a positive sign.
However, there are areas of concern. The most prominent is the significant proportion of improperly escaped output (50%). This could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is directly echoed into the output without proper sanitization. While no critical or high severity taint flows were detected, the potential for XSS due to poor output escaping is a notable risk that could be exploited in conjunction with other factors or if future code introduces more complex data handling.
In conclusion, while the "testimonial-moving" plugin has a clean vulnerability history and employs some fundamental security practices, the high rate of unescaped output presents a tangible risk. Addressing this output escaping issue should be a priority to significantly improve the plugin's overall security. The absence of known CVEs is a strong positive, but the unescaped output represents a weakness that could be leveraged by attackers.
Key Concerns
- 50% of output is not properly escaped
Testimonial Moving Security Vulnerabilities
Testimonial Moving Code Analysis
Output Escaping
Data Flow Analysis
Testimonial Moving Attack Surface
Shortcodes 5
WordPress Hooks 21
Maintenance & Trust
Testimonial Moving Maintenance & Trust
Maintenance Signals
Community Trust
Testimonial Moving Alternatives
Excited! Testimonials Showcase
excited-testimonials-showcase
With Excited! Testimonials Showcase you can easily create awesome testimonials for your WordPress website or blog.
Testimonial – Responsive Testimonials Showcase
testimonial-by-weblizar
Testimonial is the Responsive Testimonials Showcase Plugin for WordPress built to display testimonials, reviews or quotes in multiple ways on any page …
IG Testimonials
ig-testimonials
IG Testimonials is a clean and easy-to-use testimonials plugin for WordPress.
Fancy Testimonials
fancy-testimonials
Plugin for displaying testimonials via a shortcode for use on posts and pages.
Testimonial & Review
testimonial-review
Testimonial Review plugin is a simple tool to display your customer's feedback on your WordPress website.
Testimonial Moving Developer Profile
2 plugins · 10 total installs
How We Detect Testimonial Moving
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/testimonial-moving/admin/css/testimonial-moving-admin.css/wp-content/plugins/testimonial-moving/admin/js/testimonial-moving-admin.js/wp-content/plugins/testimonial-moving/public/css/testimonial-moving-public.css/wp-content/plugins/testimonial-moving/public/js/testimonial-moving-public.jstestimonial-moving-admin?ver=testimonial-moving-public?ver=HTML / DOM Fingerprints
tm_testimonial_wrappertm_testimonial_itemtm_testimonial_authortm_testimonial_contentdata-testimonial-iddata-transition-speeddata-autoplay-speeddata-navigationtestimonial_moving_objtestimonial_moving_notices[testimonial_moving]