Webiots Testimonial Showcase Security & Risk Analysis

wordpress.org/plugins/webiots-testimonials

Display responsive testimonials and reviews on any page or widget as list , slider or video. Best Testimonial Showcase Wordpress plugin.

0 active installs v1.0 PHP 5.6.31+ WP 3.6+ Updated Oct 1, 2017
reviewstestimonial-formtestimonial-gridtestimonial-liststestimonials
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Webiots Testimonial Showcase Safe to Use in 2026?

Generally Safe

Score 85/100

Webiots Testimonial Showcase has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The 'webiots-testimonials' plugin, version 1.0, exhibits a generally good security posture based on the provided static analysis. It lacks dangerous functions, uses prepared statements exclusively for SQL queries, and has no recorded vulnerabilities. The presence of nonce and capability checks on its entry points further enhances its security. However, a significant concern arises from the low percentage of properly escaped output. With 37% of 95 output operations being unescaped, this leaves a substantial potential for Cross-Site Scripting (XSS) vulnerabilities. The absence of taint analysis flows is positive but could also indicate the analysis may not have covered all potential paths or that the plugin is very simple. While the attack surface is small and protected, the unescaped output is a notable weakness that requires immediate attention.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

Webiots Testimonial Showcase Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Webiots Testimonial Showcase Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
60
35 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

37% escaped95 total outputs
Attack Surface

Webiots Testimonial Showcase Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[webiots-tm-form] index.php:46
[webiots-tm] index.php:53
WordPress Hooks 14
actionplugins_loadedincludes\functions.php:17
actioninitincludes\functions.php:19
actionadmin_headincludes\functions.php:25
actionadd_meta_boxesincludes\functions.php:26
actionsave_postincludes\functions.php:27
actioninitincludes\functions.php:664
actionrestrict_manage_postsincludes\functions.php:675
filterparse_queryincludes\functions.php:697
actionadmin_menuincludes\options.php:6
actionadmin_initincludes\options.php:12
actionwp_enqueue_scriptsindex.php:33
actioninitindex.php:48
actioninitindex.php:55
actionvc_before_initindex.php:56
Maintenance & Trust

Webiots Testimonial Showcase Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedOct 1, 2017
PHP min version5.6.31
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Webiots Testimonial Showcase Developer Profile

Webiots

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Webiots Testimonial Showcase

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/webiots-testimonials/assets/css/style.css/wp-content/plugins/webiots-testimonials/assets/js/testimonial.js
Version Parameters
webiots-testimonials/assets/css/style.css?ver=webiots-testimonials/assets/js/testimonial.js?ver=

HTML / DOM Fingerprints

CSS Classes
webiots-tm-form-wrapwebiots-testimonial-wrapper
Data Attributes
data-webiots-id
JS Globals
webiots_testimonials_ajax_object
Shortcode Output
[webiots-tm-form][webiots-tm]
FAQ

Frequently Asked Questions about Webiots Testimonial Showcase