
Testimonial Slider Security & Risk Analysis
wordpress.org/plugins/testimonials-sliderTestimonial slider is very helpful to display client feeback and quote. You can create shortcode and use it. thats simple. It is mobile friednly.
Is Testimonial Slider Safe to Use in 2026?
Generally Safe
Score 85/100Testimonial Slider has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "testimonials-slider" plugin version 1.1 presents a generally good security posture, with several positive indicators. The absence of known CVEs and critical taint flows, along with the use of prepared statements for all SQL queries, are strong points. The presence of a nonce check is also a good practice. However, a significant concern is the low percentage of properly escaped output (32%). This indicates a potential for Cross-Site Scripting (XSS) vulnerabilities, especially in any user-supplied data that is displayed to other users. While there are no unauthenticated entry points directly exposed in the static analysis (AJAX, REST API), the shortcode acts as a potential entry point that is not explicitly detailed regarding its internal security checks beyond a single nonce check for the entire plugin. The vulnerability history being clean is reassuring, but the low output escaping rate remains a notable weakness that could lead to vulnerabilities if not addressed.
Key Concerns
- Low output escaping rate (32%)
- Potential for XSS via shortcode
Testimonial Slider Security Vulnerabilities
Testimonial Slider Release Timeline
Testimonial Slider Code Analysis
Output Escaping
Data Flow Analysis
Testimonial Slider Attack Surface
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
Testimonial Slider Maintenance & Trust
Maintenance Signals
Community Trust
Testimonial Slider Alternatives
Akismet Anti-spam: Spam Protection
akismet
The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam solution for WordPress and WooCommerce.
Disable Comments – Remove Comments & Stop Spam [Multi-Site Support]
disable-comments
Allows administrators to globally disable comments on their site. Comments can be disabled according to post type. Multisite friendly.
Antispam Bee
antispam-bee
Sophisticated antispam plugin for effective daily comment and trackback spam-fighting. Built with data protection and privacy in mind.
Spam protection, Honeypot, Anti-Spam by CleanTalk
cleantalk-spam-protect
Blocks spam comments, fake users, contact form spam and more. No impact on SEO. Privacy focused. CAPTCHA free, premium Antispam plugin.
Captcha Code
captcha-code-authentication
GDPR compatible captcha anti-spam protection for login form, comments form, registration form & lost password form. Eliminate spam with captcha.
Testimonial Slider Developer Profile
2 plugins · 10 total installs
How We Detect Testimonial Slider
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/testimonials-slider/css/style.css/wp-content/plugins/testimonials-slider/css/bootstrap.min.css/wp-content/plugins/testimonials-slider/js/bootstrap.min.js/wp-content/plugins/testimonials-slider/js/main.js/wp-content/plugins/testimonials-slider/include/styles.css/wp-content/plugins/testimonials-slider/include/carousels.js/wp-content/plugins/testimonials-slider/include/color-picker.js/wp-content/plugins/testimonials-slider/js/bootstrap.min.js/wp-content/plugins/testimonials-slider/js/main.js/wp-content/plugins/testimonials-slider/include/carousels.js/wp-content/plugins/testimonials-slider/include/color-picker.jstestimonials-slider/css/style.css?ver=testimonials-slider/css/bootstrap.min.css?ver=testimonials-slider/js/bootstrap.min.js?ver=testimonials-slider/js/main.js?ver=testimonials-slider/include/styles.css?ver=testimonials-slider/include/carousels.js?ver=testimonials-slider/include/color-picker.js?ver=HTML / DOM Fingerprints
rt-startestimonial_testimonial_meta_nametestimonial_testimonial_meta_destignationtestimonial_testimonial_meta_rating