Ultimate Testimonials Security & Risk Analysis

wordpress.org/plugins/ultimate-testimonials

The only testimonials plugin you'll ever need! Fully functional. Includes front-end submission, random testimonials, built-in ratings system.

10 active installs v0.2 PHP + WP 4.0+ Updated Feb 21, 2017
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Ultimate Testimonials Safe to Use in 2026?

Generally Safe

Score 85/100

Ultimate Testimonials has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the "ultimate-testimonials" plugin version 0.2 exhibits a strong security posture. The code analysis reveals no dangerous functions, file operations, or external HTTP requests. Crucially, all SQL queries are properly prepared, and all output is correctly escaped, indicating good coding practices against common web vulnerabilities. The absence of any taint analysis findings further reinforces this, suggesting no discernible paths for unsanitized user input to lead to vulnerabilities.

However, a significant concern arises from the complete lack of security mechanisms. There are zero AJAX handlers, REST API routes, shortcodes, or cron events that are protected by authentication or capability checks. This means that if any entry points were to be introduced in the future, they would be entirely unprotected by default. The absence of any recorded vulnerabilities in its history might suggest either a very limited usage, a lack of rigorous historical auditing, or that the current limited attack surface has simply not been targeted or exploited. This lack of historical issues, while positive, does not negate the inherent risk posed by a plugin with zero built-in security checks for any potential future features.

In conclusion, while the current codebase for "ultimate-testimonials" v0.2 appears clean and free from immediate exploitable flaws due to its minimal features and good sanitization practices, the complete absence of any authorization or nonce checks across its entry points presents a significant, albeit latent, risk. This plugin is essentially a blank slate for potential vulnerabilities should any functionality be added without proper security considerations. The strength lies in its current simplicity and clean code; its weakness is the complete lack of foundational security controls.

Key Concerns

  • No capability checks found
  • No nonce checks found
  • No AJAX handlers with auth checks
  • No REST API routes with permission callbacks
  • No shortcodes with auth checks
  • No cron events with auth checks
Vulnerabilities
None known

Ultimate Testimonials Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Ultimate Testimonials Release Timeline

v0.2Current
v0.1
Code Analysis
Analyzed Apr 16, 2026

Ultimate Testimonials Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Ultimate Testimonials Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionafter_setup_themewpgo-ultimate-testimonials.php:47
actionafter_setup_themewpgo-ultimate-testimonials.php:52
actionwidgets_initwpgo-ultimate-testimonials.php:61
actioncustomize_controls_enqueue_scriptswpgo-ultimate-testimonials.php:62
actionplugins_loadedwpgo-ultimate-testimonials.php:63
filterwidget_textwpgo-ultimate-testimonials.php:114
filterwidget_textwpgo-ultimate-testimonials.php:115
Maintenance & Trust

Ultimate Testimonials Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.33
Last updatedFeb 21, 2017
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Alternatives

Ultimate Testimonials Alternatives

No alternatives data available yet.

Developer Profile

Ultimate Testimonials Developer Profile

David Gwyer

12 plugins · 109K total installs

68
trust score
Avg Security Score
84/100
Avg Patch Time
156 days
View full developer profile
Detection Fingerprints

How We Detect Ultimate Testimonials

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ultimate-testimonials/lib/css/wpgo-tml-customizer.css

HTML / DOM Fingerprints

CSS Classes
wpgo-ultimate-testimonials
FAQ

Frequently Asked Questions about Ultimate Testimonials