Testimonial – Testimonial Slider and Showcase Plugin Security & Risk Analysis

wordpress.org/plugins/testimonial-slider-and-showcase

Display customer testimonials beautifully with responsive slider and grid layouts. Build trust and boost conversions with this WordPress testimonial p …

30K active installs v2.4.1 PHP 7.0+ WP 5.0+ Updated Feb 16, 2026
customer-reviewstar-ratingstestimonialtestimonial-showcasetestimonial-slider
99
A · Safe
CVEs total2
Unpatched0
Last CVEMar 5, 2024
Safety Verdict

Is Testimonial – Testimonial Slider and Showcase Plugin Safe to Use in 2026?

Generally Safe

Score 99/100

Testimonial – Testimonial Slider and Showcase Plugin has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

2 known CVEsLast CVE: Mar 5, 2024Updated 3mo ago
Risk Assessment

The static analysis of 'testimonial-slider-and-showcase' v2.4.1 presents a generally positive security posture based on code signals. The plugin demonstrates good practices by having zero dangerous functions, no raw SQL queries (all use prepared statements), and all output appears to be properly escaped. Furthermore, there are no identified file operations or external HTTP requests, and the plugin does not appear to expose a broad attack surface through typical entry points like AJAX handlers, REST API routes, shortcodes, or cron events without proper checks.

However, the vulnerability history is a significant concern. With a total of two known CVEs, both categorized as medium severity and related to Missing Authorization and Cross-site Scripting, this indicates a past pattern of exploitable flaws. The fact that these vulnerabilities were addressed suggests the developers are responsive, but the existence of past issues, even if currently patched, warrants caution. The lack of current unpatched vulnerabilities is a positive sign, but the historical context cannot be ignored.

In conclusion, while the current version's code analysis shows strong adherence to secure coding practices, the plugin's history of security vulnerabilities, particularly those involving authorization and XSS, necessitates ongoing vigilance. The absence of an attack surface in the analyzed components is a significant strength, but the historical context means a medium-risk assessment is appropriate, leaning on the potential for future issues or overlooked areas given past discoveries.

Key Concerns

  • Total known CVEs (2 medium)
  • Bundled outdated library (Select2)
  • No capability checks detected
  • No nonce checks detected
Vulnerabilities
2 published

Testimonial – Testimonial Slider and Showcase Plugin Security Vulnerabilities

CVEs by Year

1 CVE in 2022
2022
1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2024-1745medium · 4.3Missing Authorization

Testimonial Slider <= 2.3.6 - Missing Authorization to Authenticated (Author+) Settings Update

Mar 5, 2024 Patched in 2.3.7 (14d)
WF-fc329aee-e777-41eb-8799-539c891bd03b-testimonial-slider-and-showcasemedium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Testimonial Slider <= 2.2.6 - Stored Cross-Site Scripting

Aug 5, 2022 Patched in 2.2.7 (536d)
Version History

Testimonial – Testimonial Slider and Showcase Plugin Release Timeline

v2.4.1Current
v2.4.0
v2.3.19
v2.3.18
v2.3.17
v2.3.16
v2.3.15
v2.3.14
v2.3.13
v2.3.12
v2.3.11
v2.3.10
v2.3.9
v2.3.8
v2.3.7
v2.3.61 CVE
v2.3.51 CVE
v2.3.41 CVE
v2.3.31 CVE
v2.3.21 CVE
Code Analysis
Analyzed Mar 16, 2026

Testimonial – Testimonial Slider and Showcase Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2
Attack Surface

Testimonial – Testimonial Slider and Showcase Plugin Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

Testimonial – Testimonial Slider and Showcase Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedFeb 16, 2026
PHP min version7.0
Downloads648K

Community Trust

Rating92/100
Number of ratings67
Active installs30K
Developer Profile

Testimonial – Testimonial Slider and Showcase Plugin Developer Profile

RadiusTheme

16 plugins · 214K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
94 days
View full developer profile
Detection Fingerprints

How We Detect Testimonial – Testimonial Slider and Showcase Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/testimonial-slider-and-showcase/assets/css/owl.carousel.min.css/wp-content/plugins/testimonial-slider-and-showcase/assets/css/slick.css/wp-content/plugins/testimonial-slider-and-showcase/assets/css/testimonial-slider-frontend.css/wp-content/plugins/testimonial-slider-and-showcase/assets/js/custom.js/wp-content/plugins/testimonial-slider-and-showcase/assets/js/frontend.js/wp-content/plugins/testimonial-slider-and-showcase/assets/js/isotope.pkgd.min.js/wp-content/plugins/testimonial-slider-and-showcase/assets/js/owl.carousel.min.js/wp-content/plugins/testimonial-slider-and-showcase/assets/js/slick.min.js
Script Paths
/wp-content/plugins/testimonial-slider-and-showcase/assets/js/custom.js/wp-content/plugins/testimonial-slider-and-showcase/assets/js/frontend.js/wp-content/plugins/testimonial-slider-and-showcase/assets/js/isotope.pkgd.min.js/wp-content/plugins/testimonial-slider-and-showcase/assets/js/owl.carousel.min.js/wp-content/plugins/testimonial-slider-and-showcase/assets/js/slick.min.js
Version Parameters
testimonial-slider-and-showcase/assets/css/owl.carousel.min.css?ver=testimonial-slider-and-showcase/assets/css/slick.css?ver=testimonial-slider-and-showcase/assets/css/testimonial-slider-frontend.css?ver=testimonial-slider-and-showcase/assets/js/custom.js?ver=testimonial-slider-and-showcase/assets/js/frontend.js?ver=testimonial-slider-and-showcase/assets/js/isotope.pkgd.min.js?ver=testimonial-slider-and-showcase/assets/js/owl.carousel.min.js?ver=testimonial-slider-and-showcase/assets/js/slick.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
rt-testimonial-slider-wrapperrt-testimonial-content-innerrt-testimonial-slider-activert-testimonial-slider-navrt-testimonial-grid-wrapperrt-testimonial-grid-itemrt-testimonial-slider-wraprt-testimonial-img-wrap+29 more
HTML Comments
<!-- RT Testimonial Slider And Showcase by RadiusTheme -->
Data Attributes
data-dotsdata-navdata-loopdata-autoplaydata-autoplay-timeoutdata-smart-speed+19 more
JS Globals
TSSFrontend
Shortcode Output
[testimonial_slider][testimonial_grid]
FAQ

Frequently Asked Questions about Testimonial – Testimonial Slider and Showcase Plugin