
Wp Awesome Testimonial Security & Risk Analysis
wordpress.org/plugins/wp-awesome-testimonialWp Awesome Testimonial is the Best Testimonials Showcase Plugin for WordPress built to display testimonials.
Is Wp Awesome Testimonial Safe to Use in 2026?
Generally Safe
Score 85/100Wp Awesome Testimonial has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of wp-awesome-testimonial v1.0 reveals a generally strong security posture with several positive indicators. The absence of dangerous functions, file operations, and external HTTP requests is commendable. Notably, all SQL queries utilize prepared statements, and all identified outputs are properly escaped, mitigating common injection and XSS risks. The plugin also has no recorded vulnerabilities in its history, suggesting a history of secure development or thorough patching if any issues were found previously. However, there are significant areas of concern. The complete lack of nonce checks and capability checks, despite having a shortcode as an entry point, is a major weakness. This means that any user, regardless of their role or privileges, can potentially trigger the functionality associated with the shortcode, opening the door to unauthorized actions or information disclosure if the shortcode's processing involves sensitive operations. Furthermore, the absence of taint analysis results, while potentially meaning no issues were found, could also indicate that the analysis itself was not comprehensive enough to identify subtle vulnerabilities. In conclusion, while the plugin exhibits good practices in its handling of SQL and output, the critical deficiency in authentication and authorization checks for its sole entry point presents a substantial security risk.
Key Concerns
- No nonce checks on entry points
- No capability checks on entry points
- Shortcode exists with no auth checks
Wp Awesome Testimonial Security Vulnerabilities
Wp Awesome Testimonial Code Analysis
Wp Awesome Testimonial Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
Wp Awesome Testimonial Maintenance & Trust
Maintenance Signals
Community Trust
Wp Awesome Testimonial Alternatives
Creta Testimonial Showcase
creta-testimonial-showcase
Showcase client reviews with Creta Testimonial Showcase an easy, responsive WordPress testimonial plugin with free and premium templates.
Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More
reviews-feed
No API key required. Display Yelp and Google reviews for any business in a clean, customizable feed on your site.
Rich Showcase for Google Reviews
widget-google-reviews
Display up to 10 Google reviews in less than a minute. Continue collecting new reviews. No limits on connected places, widgets, shortcodes and blocks.
Strong Testimonials
strong-testimonials
An easy-to-use testimonial plugin to collect and show customer feedback in WordPress
Site Reviews
site-reviews
Site Reviews is a complete review management solution that integrates with WooCommerce and SureCart and works similarly to reviews on Amazon, Tripadvi …
Wp Awesome Testimonial Developer Profile
12 plugins · 820 total installs
How We Detect Wp Awesome Testimonial
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-awesome-testimonial/css/bootstrap.min.css/wp-content/plugins/wp-awesome-testimonial/css/font-awesome.min.css/wp-content/plugins/wp-awesome-testimonial/css/style.css/wp-content/plugins/wp-awesome-testimonial/js/bootstrap.min.js/wp-content/plugins/wp-awesome-testimonial/js/main.js/wp-content/plugins/wp-awesome-testimonial/js/bootstrap.min.js/wp-content/plugins/wp-awesome-testimonial/js/main.jsHTML / DOM Fingerprints
testimonial-showcaseteastimonial-item-04<!-- testimonial start--><div class="testimonial-showcase ">
<div class="container">
<div class="row">