
wpCJ Testimonials Security & Risk Analysis
wordpress.org/plugins/wpcj-testimonialsThis plugin helps you manage a list of testimonials that you can place anywhere in your blog using shortcodes, php calls or widgets.
Is wpCJ Testimonials Safe to Use in 2026?
Generally Safe
Score 85/100wpCJ Testimonials has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wpcj-testimonials plugin v1.0.4 presents a mixed security posture. On the positive side, it has no known CVEs, a relatively small attack surface, and does not appear to perform external HTTP requests. However, significant concerns arise from the static analysis. The complete lack of output escaping for all 39 detected outputs is a critical vulnerability, potentially leading to cross-site scripting (XSS) attacks if user-supplied data is displayed without proper sanitization.
Furthermore, the taint analysis reveals 5 flows with unsanitized paths, with 3 classified as high severity. This indicates that user-controlled input might be processed in a way that could lead to unintended or malicious actions, such as directory traversal or code injection, depending on the context of these unsanitized paths. The absence of nonce checks and capability checks, combined with the lack of proper output escaping, creates a risky environment where unauthenticated or low-privileged users could potentially manipulate plugin functionality or inject malicious scripts.
Key Concerns
- No output escaping detected
- High severity unsanitized taint flows
- No nonce checks
- No capability checks
- SQL queries not always prepared
wpCJ Testimonials Security Vulnerabilities
wpCJ Testimonials Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
wpCJ Testimonials Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
wpCJ Testimonials Maintenance & Trust
Maintenance Signals
Community Trust
wpCJ Testimonials Alternatives
Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More
reviews-feed
No API key required. Display Yelp and Google reviews for any business in a clean, customizable feed on your site.
Rich Showcase for Google Reviews
widget-google-reviews
Display up to 10 Google reviews in less than a minute. Continue collecting new reviews. No limits on connected places, widgets, shortcodes and blocks.
Site Reviews
site-reviews
Site Reviews is a complete review management solution that integrates with WooCommerce and SureCart and works similarly to reviews on Amazon, Tripadvi …
WP Google Review Slider
wp-google-places-review-slider
Display Google reviews on your site and even show user images! No address, no problem! Also works with Service Area Businesses and Products! Lightwei …
WP Customer Reviews
wp-customer-reviews
Allows your visitors to leave business / product reviews. Testimonials are in Microdata / Microformat and may display star ratings in search results.
wpCJ Testimonials Developer Profile
3 plugins · 30 total installs
How We Detect wpCJ Testimonials
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpcj-testimonials/css/wpcjtestimonials.css/wp-content/plugins/wpcj-testimonials/js/wpcjtestimonials.js/wp-content/plugins/wpcj-testimonials/js/wpcjtestimonials.jswpcj-testimonials/css/wpcjtestimonials.css?ver=wpcj-testimonials/js/wpcjtestimonials.js?ver=HTML / DOM Fingerprints
wpcjt_picturedata-wpcjt-idwpcjt_ajax_object<div class="wpcj_testimonial_container"><div class="wpcj_testimonial_content"><div class="wpcj_testimonial_author"><div class="wpcj_testimonial_company">