ShowTrust
A shareable link that collects testimonials, and a widget an agent can install for you
A submission form, an approval queue, and a grid of cards you can embed elsewhere. There is no algorithm here and no network effect · an agent will produce a working version in one sitting, same as it will for the $25 and $29 tools in this category. The catch is the same one Eloqra has: the hosted version is free for a single site, with no cap on testimonials, so you'd be spending a weekend and a hosting bill to replace zero dollars. Worth building if you want the data on your own box or you enjoy the exercise. Not worth building to save money, because there isn't any to save.
Build verification: not recorded. How we judge buildability
What you give up
- a free tier · one site with uncapped testimonials costs nothing hosted, so the DIY build starts out behind on price
- the install itself · an agent can provision the account from your email alone, get working credentials in the same response, create the project and paste the snippet into your framework, with the human only clicking a claim link afterwards · your own build is something you have to go and deploy
- the design surface you'd otherwise hand-build · multiple layouts, eight card styles, colour palettes, and sliders for width, spacing and radius, all previewable instead of CSS-tweaked by hand
- did-it-work data · impression and CTA-click tracking with click-through rate and which domains your wall is actually being viewed on
- X-verified testimonials · an OAuth flow that reads X's own verified state, so the quote is provably tied to a real handle and avatar
Why people still pay
For one site, they don't · it's free, uncapped, and nothing is feature-gated, so the paid tier only exists to add a second project. What you actually trade away by self-hosting is smaller and more boring than money: the layout and styling controls are a real chunk of fiddly frontend work, and the impression tracking tells you whether the wall is doing anything at all, which a hand-rolled version silently won't. One honest mark against the hosted option · the collection page carries a 'Powered by ShowTrustTo' line on every tier, paid included, and there's no switch to remove it. If that badge on a page you send to customers bothers you, that alone is a legitimate reason to build your own.
Your build guide
The stack, security requirements, and agent rules for a focused replacement.
Before you start
- Node, SQLite and private upload storage on persistent disk, public HTTPS hosting and authenticated owner moderation. Obtain contributor publication consent.
- Implementation components: Node.js, TypeScript and Express with server-rendered HTML and small browser modules. SQLite through better-sqlite3 with migrations, prepared statements and a single background worker. Sharp for bounded avatar processing and a public server-rendered embed response.
- Scope boundary: a free tier · one site with uncapped testimonials costs nothing hosted, so the DIY build starts out behind on price; the install itself · an agent can provision the account from your email alone, get working credentials in the same response, create the project and paste the snippet into your framework, with the human only clicking a claim link afterwards · your own build is something you have to go and deploy
Use these project rules and optional skill references alongside the prompt. Review each skill before adding it to your agent; the AGENTS.md export includes the same guidance.
Optional external skill: web-design-guidelines — Review web interfaces for accessibility, keyboard focus, forms, navigation and interaction quality. Review its instructions and compatibility before use; it does not grant deployment, data-access or publication permission.
Optional external skill: sharp-edges — Review security-sensitive APIs and configuration for dangerous defaults and easy-to-misuse interfaces. Review its instructions and compatibility before use; it does not grant deployment, data-access or publication permission.
Project rule — data model: testimonial submissions, contributor consent, image assets, moderation decisions and published wall revisions
Project rule — preserve this invariant: Only actual submitted and approved quotes are displayed; edits must not change a contributor's meaning or fabricate ratings and endorsements.
Project rule — acceptance evidence: A pending submission is absent from the public embed; withdrawing consent removes the quote and photo from newly served wall data.
Implementation plan
Phase 1
Scope and fixtures. Implement this bounded workflow: Provide a public form for a name, optional photo, rating and quote, then require owner approval before showing it on an embeddable testimonial wall. Offer removal and consent-record controls. Record prerequisites, select representative user-owned fixtures and document the unsupported features: a free tier · one site with uncapped testimonials costs nothing hosted, so the DIY build starts out behind on price; the install itself · an agent can provision the account from your email alone, get working credentials in the same response, create the project and paste the snippet into your framework, with the human only clicking a claim link afterwards · your own build is something you have to go and deploy
Phase 2
Durable model. Model testimonial submissions, contributor consent, image assets, moderation decisions and published wall revisions Add migrations or a versioned document format, explicit validation, stable IDs and a visible import-error report. Preserve this rule: Only actual submitted and approved quotes are displayed; edits must not change a contributor's meaning or fabricate ratings and endorsements.
Phase 3
Complete the first useful path. Implement the workflow's input, review and output interface, with clear controls and explicit empty/error states. Use short SQLite transactions and persist job state before starting work. Give retries stable operation IDs; report incomplete or unknown results instead of silently repeating them.
Phase 4
Permissions and integration failure. Public routes accept only their documented inputs with rate/size limits. Protect every owner/customer action with authenticated authorization and CSRF checks; keep secrets outside exports and redact personal data from logs. Request integration credentials and permissions only for the enabled feature; show a disconnected state instead of mock results.
Phase 5
Portable handoff. Use a consistent SQLite backup and an attachment manifest. Export portable JSON/CSV, then restore to a new directory without overwriting the original data. Include setup, operating limits, fixture walkthrough and shutdown/restart instructions in the README.
Phase 6
Acceptance scenarios. A pending submission is absent from the public embed; withdrawing consent removes the quote and photo from newly served wall data. Repeat the workflow after restart and with a denied permission or unavailable dependency; show recoverable failure rather than a success placeholder.
WORKING SLICE Provide a public form for a name, optional photo, rating and quote, then require owner approval before showing it on an embeddable testimonial wall. Offer removal and consent-record controls. Build this scoped ShowTrust-inspired workflow with a documented data model and visible failure states. Architecture - Node.js, TypeScript and Express with server-rendered HTML and small browser modules. - SQLite through better-sqlite3 with migrations, prepared statements and a single background worker. - Sharp for bounded avatar processing and a public server-rendered embed response. Prerequisites and limits Node, SQLite and private upload storage on persistent disk, public HTTPS hosting and authenticated owner moderation. Obtain contributor publication consent. Outside this release: a free tier · one site with uncapped testimonials costs nothing hosted, so the DIY build starts out behind on price; the install itself · an agent can provision the account from your email alone, get working credentials in the same response, create the project and paste the snippet into your framework, with the human only clicking a claim link afterwards · your own build is something you have to go and deploy Data model and correctness testimonial submissions, contributor consent, image assets, moderation decisions and published wall revisions Invariant: Only actual submitted and approved quotes are displayed; edits must not change a contributor's meaning or fabricate ratings and endorsements. Use short SQLite transactions and persist job state before starting work. Give retries stable operation IDs; report incomplete or unknown results instead of silently repeating them. Security and privacy Public routes accept only their documented inputs with rate/size limits. Protect every owner/customer action with authenticated authorization and CSRF checks; keep secrets outside exports and redact personal data from logs. Recovery and export Use a consistent SQLite backup and an attachment manifest. Export portable JSON/CSV, then restore to a new directory without overwriting the original data. Implementation order 1. Phase 1 — Scope and fixtures. Implement this bounded workflow: Provide a public form for a name, optional photo, rating and quote, then require owner approval before showing it on an embeddable testimonial wall. Offer removal and consent-record controls. Record prerequisites, select representative user-owned fixtures and document the unsupported features: a free tier · one site with uncapped testimonials costs nothing hosted, so the DIY build starts out behind on price; the install itself · an agent can provision the account from your email alone, get working credentials in the same response, create the project and paste the snippet into your framework, with the human only clicking a claim link afterwards · your own build is something you have to go and deploy 2. Phase 2 — Durable model. Model testimonial submissions, contributor consent, image assets, moderation decisions and published wall revisions Add migrations or a versioned document format, explicit validation, stable IDs and a visible import-error report. Preserve this rule: Only actual submitted and approved quotes are displayed; edits must not change a contributor's meaning or fabricate ratings and endorsements. 3. Phase 3 — Complete the first useful path. Implement the workflow's input, review and output interface, with clear controls and explicit empty/error states. Use short SQLite transactions and persist job state before starting work. Give retries stable operation IDs; report incomplete or unknown results instead of silently repeating them. 4. Phase 4 — Permissions and integration failure. Public routes accept only their documented inputs with rate/size limits. Protect every owner/customer action with authenticated authorization and CSRF checks; keep secrets outside exports and redact personal data from logs. Request integration credentials and permissions only for the enabled feature; show a disconnected state instead of mock results. 5. Phase 5 — Portable handoff. Use a consistent SQLite backup and an attachment manifest. Export portable JSON/CSV, then restore to a new directory without overwriting the original data. Include setup, operating limits, fixture walkthrough and shutdown/restart instructions in the README. 6. Phase 6 — Acceptance scenarios. A pending submission is absent from the public embed; withdrawing consent removes the quote and photo from newly served wall data. Repeat the workflow after restart and with a denied permission or unavailable dependency; show recoverable failure rather than a success placeholder. Acceptance A pending submission is absent from the public embed; withdrawing consent removes the quote and photo from newly served wall data. Use real source data or clearly labeled fixtures. Explain unsupported input and provider failures; do not fabricate analytics, delivery receipts, accuracy claims or security guarantees. Optional agent guidance Optional external skill: [web-design-guidelines](https://github.com/vercel-labs/agent-skills/blob/main/skills/web-design-guidelines/SKILL.md) — Review web interfaces for accessibility, keyboard focus, forms, navigation and interaction quality. Review its instructions and compatibility before use; it does not grant deployment, data-access or publication permission. Optional external skill: [sharp-edges](https://github.com/trailofbits/skills/blob/main/plugins/sharp-edges/skills/sharp-edges/SKILL.md) — Review security-sensitive APIs and configuration for dangerous defaults and easy-to-misuse interfaces. Review its instructions and compatibility before use; it does not grant deployment, data-access or publication permission. Project rule — data model: testimonial submissions, contributor consent, image assets, moderation decisions and published wall revisions Project rule — preserve this invariant: Only actual submitted and approved quotes are displayed; edits must not change a contributor's meaning or fabricate ratings and endorsements. Project rule — acceptance evidence: A pending submission is absent from the public embed; withdrawing consent removes the quote and photo from newly served wall data.
$ open in your agent (prompt prefilled, you press enter), copy the prompt or copy or download AGENTS.md
prompt copied. want to know what dies next week?
new verdicts + top votes, weekly. free. one-click out.
Alternatives to building your own
all 3 free alternatives to ShowTrust →· no votes, no pay-to-list · just what's real
ShowTrust pricing
| plan | monthly | annual (per mo) | what you get |
|---|---|---|---|
| free | $0/workspace | $0/workspace | Unlimited testimonials; 1 project; no visitor/page-view cap; no watermark. |
| pro | $4.99/workspace | $4.17/workspace | Unlimited testimonials and usage; paid project/features bundle.Annual total is $49.99. |
free tierUnlimited testimonials; 1 project; no visitor/page-view cap; no watermark.
billingMonthly + annual; annual total is $49.99.
pricing sources checked 2026-08-12 · pricing source ↗
Questions about ShowTrust
Can you build your own ShowTrust with AI?
The verdict is yes for the scoped workflow. A submission form, an approval queue, and a grid of cards you can embed elsewhere. There is no algorithm here and no network effect · an agent will produce a working version in one sitting, same as it will for the $25 and $29 tools in this category. The catch is the same one Eloqra has: the hosted version is free for a single site, with no cap on testimonials, so you'd be spending a weekend and a hosting bill to replace zero dollars. Worth building if you want the data on your own box or you enjoy the exercise. Not worth building to save money, because there isn't any to save.
What does the ShowTrust build prompt cover?
The prompt starts with this scope: Provide a public form for a name, optional photo, rating and quote, then require owner approval before showing it on an embeddable testimonial wall. Offer removal and consent-record controls. Full-product capabilities excluded from the comparison include: a free tier · one site with uncapped testimonials costs nothing hosted, so the DIY build starts out behind on price; the install itself · an agent can provision the account from your email alone, get working credentials in the same response, create the project and paste the snippet into your framework, with the human only clicking a claim link afterwards · your own build is something you have to go and deploy; the design surface you'd otherwise hand-build · multiple layouts, eight card styles, colour palettes, and sliders for width, spacing and radius, all previewable instead of CSS-tweaked by hand. Follow the implementation plan and its prerequisites before expanding the build.
How do I use the prompt, AGENTS.md and agent skills?
Start with the ShowTrust prerequisites and stack, then copy the prompt into your coding agent. Save the project rules as AGENTS.md in the project root. Linked skills are optional packages or source instructions for specific tasks; review their current contents and install only those matching the chosen stack. A skill does not supply API credentials or verify the finished app.
How long will this ShowTrust project take?
The catalogue estimate is one sitting for the limited scope. Setup, integration approvals, debugging, deployment and ongoing maintenance can add time. This is an estimate, not a delivery guarantee.
What would I give up by replacing ShowTrust?
a free tier · one site with uncapped testimonials costs nothing hosted, so the DIY build starts out behind on price; the install itself · an agent can provision the account from your email alone, get working credentials in the same response, create the project and paste the snippet into your framework, with the human only clicking a claim link afterwards · your own build is something you have to go and deploy; the design surface you'd otherwise hand-build · multiple layouts, eight card styles, colour palettes, and sliders for width, spacing and radius, all previewable instead of CSS-tweaked by hand; did-it-work data · impression and CTA-click tracking with click-through rate and which domains your wall is actually being viewed on; X-verified testimonials · an OAuth flow that reads X's own verified state, so the quote is provably tied to a real handle and avatar. For one site, they don't · it's free, uncapped, and nothing is feature-gated, so the paid tier only exists to add a second project. What you actually trade away by self-hosting is smaller and more boring than money: the layout and styling controls are a real chunk of fiddly frontend work, and the impression tracking tells you whether the wall is doing anything at all, which a hand-rolled version silently won't. One honest mark against the hosted option · the collection page carries a 'Powered by ShowTrustTo' line on every tier, paid included, and there's no switch to remove it. If that badge on a page you send to customers bothers you, that alone is a legitimate reason to build your own.
What price is this guide comparing against?
The recorded Pro plan is $4.99/mo (monthly per project), checked 2026-07-31. Check the linked pricing source before buying. Building your own also has hosting, API and maintenance costs; the recorded amount is not a guaranteed saving.
What can I use instead of building ShowTrust?
Real Testimonials: Another WordPress route: forms, moderation, grids and sliders are free; video and the clever automation live upstairs. Shosay: Unlimited text, video and audio proof, imports, walls and 25-plus widgets; the bill is zero, the tiny Powered by pill is not. Strong Testimonials: A WordPress-only form, moderation queue, grid, slider and widget; simple enough once you already own the WordPress problem. Compare all listed options at https://howtovibecodeit.dev/showtrust/alternatives. Check each option's license, hosting needs and feature limits.