
WP List Testimonials Security & Risk Analysis
wordpress.org/plugins/wp-list-testimonialsOutputs testimonials using information from your blogroll links.
Is WP List Testimonials Safe to Use in 2026?
Generally Safe
Score 85/100WP List Testimonials has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-list-testimonials plugin v1.2 exhibits a seemingly strong security posture based on the provided static analysis. The absence of identified AJAX handlers, REST API routes, shortcodes, and cron events with unprotected entry points is a positive indicator. Furthermore, the code signals show no dangerous functions, all SQL queries are using prepared statements, and there are no file operations or external HTTP requests. This suggests a minimal attack surface and a deliberate effort to avoid common vulnerability vectors.
However, a significant concern arises from the output escaping. With one total output identified and 0% properly escaped, this presents a clear risk of Cross-Site Scripting (XSS) vulnerabilities. Any data displayed by the plugin that is not sanitized could be manipulated by an attacker to inject malicious scripts. The lack of nonce checks and capability checks also means that even if entry points were to be discovered, their security could be compromised.
The plugin's vulnerability history is clean, with no recorded CVEs. This is a good sign, but it should not be solely relied upon, especially in conjunction with the identified output escaping issues. The conclusion is that while the plugin has avoided many common pitfalls and boasts a clean history, the unescaped output is a critical weakness that needs immediate attention.
Key Concerns
- Unescaped output detected
- Missing nonce checks
- Missing capability checks
WP List Testimonials Security Vulnerabilities
WP List Testimonials Code Analysis
Output Escaping
WP List Testimonials Attack Surface
Maintenance & Trust
WP List Testimonials Maintenance & Trust
Maintenance Signals
Community Trust
WP List Testimonials Alternatives
Link Manager
link-manager
Enables the Link Manager that existed in WordPress until version 3.5.
Eazy Enable Blogroll
eazy-enable-blogroll
Eazy Enable Blogroll brings back the one and only WordPress Blogroll Feature, with nearly one click!
Link View
link-view
Display a link-list or link-slider in a post or page by using a shortcode.
Easy Quotes
easy-quotes
Collect and show your favorite Quotes / Reviews / Testimonials or any other short snippet of Text.
Simple Testimonials Showcase
simple-testimonials-showcase
This plugin allows you to create and display testimonials in multiple ways.
WP List Testimonials Developer Profile
16 plugins · 21K total installs
How We Detect WP List Testimonials
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
testimonialtestimonial-testimonialdescriptiontestimonialnamewp-list-testimonials<div class="wp-list-testimonials"><blockquote class="testimonial<p><cite>