
Whook Testimonials Security & Risk Analysis
wordpress.org/plugins/whook-testimonialWhook Testimonials is a plugin to use the feedback form on your WordPress website. It is a user friendly and feature rich plugin to add a responsive T …
Is Whook Testimonials Safe to Use in 2026?
Generally Safe
Score 100/100Whook Testimonials has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The whook-testimonial plugin v1.2 presents a concerning security posture due to a significant number of unprotected AJAX handlers and a high rate of unsanitized data flows. With 13 out of 15 entry points lacking authentication checks, attackers have a broad surface to potentially exploit. The presence of the 'unserialize' function, a known vector for object injection vulnerabilities, further amplifies the risk, especially when combined with unsanitized input. The taint analysis revealing 8 high-severity flows with unsanitized paths strongly suggests that user-supplied data is not being properly validated or escaped before being used in potentially dangerous operations.
While the plugin has no recorded vulnerability history, this is not an indicator of current security. The lack of nonces, capability checks, and proper output escaping on most outputs means that even without direct evidence of past exploits, the potential for new vulnerabilities to emerge is substantial. The reliance on prepared statements for SQL queries is a positive aspect, but it doesn't mitigate the risks posed by the other identified weaknesses. Overall, this plugin requires immediate attention to address the critical gaps in its security implementation.
Key Concerns
- Unprotected AJAX handlers
- Unsanitized paths in taint analysis (high severity)
- Use of 'unserialize' function
- Low rate of properly escaped output
- Missing nonce checks
- Missing capability checks
Whook Testimonials Security Vulnerabilities
Whook Testimonials Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Whook Testimonials Attack Surface
AJAX Handlers 13
Shortcodes 2
WordPress Hooks 5
Maintenance & Trust
Whook Testimonials Maintenance & Trust
Maintenance Signals
Community Trust
Whook Testimonials Alternatives
Five Star Restaurant Reviews
good-reviews-wp
Restaurant reviews made easy. Add and display reviews on your restaurant site using SEO friendly schema markup.
GlowReviews – Smart Feedback & Testimonials
glowreviews
Collect and display customer feedback with star ratings, image uploads, and WordPress user integration.
Scorpiotek Testimonials
scorpiotek-testimonials
A modern WordPress testimonials plugin with slider and star rating.
Site Reviews
site-reviews
Site Reviews is a complete review management solution that integrates with WooCommerce and SureCart and works similarly to reviews on Amazon, Tripadvi …
WP Testimonials
testimonial-widgets
Display your Testimonials on your website fast and easily. 21 widget types, 25 widget styles available. (Free Plugin)
Whook Testimonials Developer Profile
3 plugins · 20 total installs
How We Detect Whook Testimonials
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/whook-testimonial/bootstrap/css/bootstrap.min.css/wp-content/plugins/whook-testimonial/css/dataTables.bootstrap.min.css/wp-content/plugins/whook-testimonial/css/jquery.dataTables.min.css/wp-content/plugins/whook-testimonial/css/admin-css.css/wp-content/plugins/whook-testimonial/icons/css/open-iconic-bootstrap.css/wp-content/plugins/whook-testimonial/sweet-alert/css/sweetalert.css/wp-content/plugins/whook-testimonial/bootstrap/js/bootstrap.js/wp-content/plugins/whook-testimonial/js/jquery.dataTables.min.js+9 morehttps://www.google.com/recaptcha/api.jsHTML / DOM Fingerprints
logo-arealogo-imgwhook_test_site_urlwhook_test_timestampwhook_test_unique_salt