
Review & testimonial widgets Security & Risk Analysis
wordpress.org/plugins/trustmaryAdd reviews to your website with Trustmary’s review and testimonial widgets: Google Review Widget, Facebook Review Widget, Tripadvisor Review Widget, …
Is Review & testimonial widgets Safe to Use in 2026?
Generally Safe
Score 91/100Review & testimonial widgets has a strong security track record. Known vulnerabilities have been patched promptly.
The Trustmary plugin, version 1.0.10, exhibits a mixed security posture. On the positive side, the code analysis reveals no dangerous functions, no raw SQL queries (all use prepared statements), no file operations, and no unhandled taint flows. The plugin also makes no external HTTP requests without proper handling, which is a good practice. However, there are significant areas of concern, particularly regarding output escaping and the absence of capability checks and nonce checks on entry points. While the static analysis reports no directly exploitable vulnerabilities at this moment, the high percentage of improperly escaped output indicates a potential for Cross-Site Scripting (XSS) vulnerabilities. The plugin's vulnerability history, while currently showing no unpatched issues, includes a past medium severity XSS vulnerability, which aligns with the concerns raised by the output escaping findings. The lack of capability and nonce checks on its entry points (shortcodes in this case) is a significant oversight that could allow unauthorized actions or information leakage, especially if these shortcodes handle any sensitive data or functionality. Overall, the plugin has some strong security foundations but suffers from critical weaknesses in output sanitization and access control for its exposed functionalities.
Key Concerns
- Insufficient output escaping
- Missing capability checks on entry points
- Missing nonce checks on entry points
- Past medium vulnerability for XSS
Review & testimonial widgets Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Review & testimonial widgets <= 1.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
Review & testimonial widgets Code Analysis
Output Escaping
Review & testimonial widgets Attack Surface
Shortcodes 2
WordPress Hooks 7
Maintenance & Trust
Review & testimonial widgets Maintenance & Trust
Maintenance Signals
Community Trust
Review & testimonial widgets Alternatives
Ace Testimonials Slider
ace-testimonials-slider
A sleek, responsive, and highly customizable WordPress plugin to showcase client testimonials and customer reviews in a beautiful slider format.
Solid Testimonials – Testimonial Slider, Video Testimonials & Customer Reviews
gs-testimonial
Showcase and automate customer reviews with ease - sliders, grids, filters, and more to boost trust and sales.
Testimonial Customer Feedback
testimonial-maker
Display client testimonials with customizable layouts, slider effects, and responsive design. Simple setup with shortcode support.
Testimonial – Responsive Testimonials Showcase
testimonial-by-weblizar
Testimonial is the Responsive Testimonials Showcase Plugin for WordPress built to display testimonials, reviews or quotes in multiple ways on any page …
Reviewfic – The Ultimate Testimonial Slider, Carousel, Grid Plugin
reviewfic
Showcase testimonials, customer reviews, or quotes on your website. Easily display reviews across posts, pages, custom templates, widgets, and more.
Review & testimonial widgets Developer Profile
1 plugin · 1K total installs
How We Detect Review & testimonial widgets
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/trustmary/assets/css/admin.css/wp-content/plugins/trustmary/assets/js/admin.jshttps://embed.trustmary.com/embed.jsHTML / DOM Fingerprints
data-trustmary-widgetdata-trustmary-experimentwindow.tmary<div data-trustmary-widget="<div data-trustmary-experiment="