You can quote me on that Security & Risk Analysis

wordpress.org/plugins/you-can-quote-me-on-that

The quickest and easiest way to create testimonial sliders.

500 active installs v1.0.12 PHP 5.3+ WP 4.0+ Updated Dec 11, 2024
responsive-sliderslidertestimonial-sliderwordpress-slider
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is You can quote me on that Safe to Use in 2026?

Generally Safe

Score 92/100

You can quote me on that has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "you-can-quote-me-on-that" v1.0.12 plugin exhibits a generally strong security posture based on the provided static analysis. It demonstrates good practices by incorporating nonce and capability checks for its identified entry points (shortcodes), and importantly, all SQL queries are executed using prepared statements, eliminating the risk of SQL injection through this vector. The absence of dangerous functions, file operations, and external HTTP requests further contributes to its security. The plugin also has no recorded vulnerability history, suggesting a stable and likely well-maintained codebase. However, a weakness lies in the output escaping. With 75% of outputs properly escaped, there's a remaining 25% that could potentially lead to cross-site scripting (XSS) vulnerabilities if not handled carefully in the unescaped portions. The limited attack surface (2 shortcodes) and zero unprotected entry points are positive indicators, but the escaping issue warrants attention.

Key Concerns

  • Output escaping is not fully implemented (25% unescaped)
Vulnerabilities
None known

You can quote me on that Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

You can quote me on that Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
28
86 escaped
Nonce Checks
2
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

75% escaped114 total outputs
Attack Surface

You can quote me on that Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[ycqmot] library\classes\class-you-can-quote-me-on-that-post-type.php:202
[you-can-quote-me-on-that] library\classes\class-you-can-quote-me-on-that-post-type.php:203
WordPress Hooks 16
actioninitlibrary\classes\class-you-can-quote-me-on-that-post-type.php:194
actionadmin_initlibrary\classes\class-you-can-quote-me-on-that-post-type.php:197
actionsave_post_ycqmotlibrary\classes\class-you-can-quote-me-on-that-post-type.php:198
actionsave_post_ycqmotlibrary\classes\class-you-can-quote-me-on-that-post-type.php:199
filtersingle_templatelibrary\classes\class-you-can-quote-me-on-that-post-type.php:206
filterpost_updated_messageslibrary\classes\class-you-can-quote-me-on-that-post-type.php:209
filterbulk_post_updated_messageslibrary\classes\class-you-can-quote-me-on-that-post-type.php:210
filterpostbox_classes_you-can-quote-me-on-that_you-can-quote-me-on-that-slide-settings-grouplibrary\classes\class-you-can-quote-me-on-that-post-type.php:272
filteradd_menu_classeslibrary\classes\class-you-can-quote-me-on-that.php:182
actionwp_enqueue_scriptslibrary\classes\class-you-can-quote-me-on-that.php:194
actionwp_enqueue_scriptslibrary\classes\class-you-can-quote-me-on-that.php:195
actionadmin_enqueue_scriptslibrary\classes\class-you-can-quote-me-on-that.php:198
actionadmin_enqueue_scriptslibrary\classes\class-you-can-quote-me-on-that.php:199
actioninitlibrary\classes\class-you-can-quote-me-on-that.php:203
actionwidgets_initlibrary\classes\class-you-can-quote-me-on-that.php:206
actionadmin_menulibrary\classes\class-you-can-quote-me-on-that.php:208
Maintenance & Trust

You can quote me on that Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedDec 11, 2024
PHP min version5.3
Downloads15K

Community Trust

Rating0/100
Number of ratings0
Active installs500
Developer Profile

You can quote me on that Developer Profile

Out the Box

10 plugins · 15K total installs

83
trust score
Avg Security Score
93/100
Avg Patch Time
58 days
View full developer profile
Detection Fingerprints

How We Detect You can quote me on that

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/you-can-quote-me-on-that/library/css//wp-content/plugins/you-can-quote-me-on-that/library/js/
Script Paths
/wp-content/plugins/you-can-quote-me-on-that/library/js/you-can-quote-me-on-that.js/wp-content/plugins/you-can-quote-me-on-that/library/js/you-can-quote-me-on-that.min.js
Version Parameters
you-can-quote-me-on-that/library/css/you-can-quote-me-on-that.css?ver=you-can-quote-me-on-that/library/js/you-can-quote-me-on-that.js?ver=

HTML / DOM Fingerprints

CSS Classes
ycqmot-slider-wrapper
Data Attributes
data-plugin-version
JS Globals
You_Can_Quote_Me_On_That_Params
REST Endpoints
/wp-json/you-can-quote-me-on-that/v1/settings
Shortcode Output
[you_can_quote_me_on_that]
FAQ

Frequently Asked Questions about You can quote me on that