
Advanced WordPress Backgrounds Security & Risk Analysis
wordpress.org/plugins/advanced-backgroundsEasy to use advanced Parallax, Image and Video backgrounds block plugin with parallax and video support.
Is Advanced WordPress Backgrounds Safe to Use in 2026?
Generally Safe
Score 99/100Advanced WordPress Backgrounds has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The advanced-backgrounds plugin v1.12.8 exhibits a mixed security posture. On one hand, it demonstrates good practices by using prepared statements for all SQL queries, correctly escaping a majority of its outputs, and having a limited attack surface with no unprotected entry points. The absence of file operations and external HTTP requests further strengthens its security. However, the presence of the `create_function` dangerous function is a significant concern, as it can be a vector for arbitrary code execution if user-supplied input reaches it without proper sanitization. While the taint analysis reported no flows, this could be due to the complexity of the code or limitations of the static analysis tool, and the `create_function` usage remains a potential risk.
The plugin's vulnerability history, with one known medium-severity Cross-site Scripting (XSS) vulnerability, suggests a past weakness in input sanitization or output escaping. Although this vulnerability is currently patched, it highlights the importance of diligent security practices. The fact that the last vulnerability was recent (September 2024) reinforces this.
In conclusion, while the plugin has some strong security foundations, the `create_function` usage and the history of an XSS vulnerability are notable weaknesses that require attention. The lack of reported taint flows should not entirely alleviate concerns about code execution, especially given the presence of a dangerous function.
Key Concerns
- Presence of dangerous function 'create_function'
- Past medium severity XSS vulnerability
- Less than 100% output escaping
Advanced WordPress Backgrounds Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Advanced WordPress Backgrounds <= 1.12.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via imageTag Parameter
Advanced WordPress Backgrounds Release Timeline
Advanced WordPress Backgrounds Code Analysis
Dangerous Functions Found
Bundled Libraries
Output Escaping
Advanced WordPress Backgrounds Attack Surface
Shortcodes 1
WordPress Hooks 19
Maintenance & Trust
Advanced WordPress Backgrounds Maintenance & Trust
Maintenance Signals
Community Trust
Advanced WordPress Backgrounds Alternatives
Better YouTube Block – A better way to embed YouTube videos, shorts, playlists
better-youtube-embed-block
Embed YouTube videos without slowing down your site. Easily embed one or multiple videos, shorts, and playlists.
Parallax Section Block – Add Parallax Scrolling Effects to Sections.
parallax-section
Add Parallax scrolling effects in any section of your website.
Gosign – Background Container Block
gosign-background-container
This plugin creates a background container which holds all kinds of elements with 40+ background options in WordPress 5 (Codename: Gutenberg).
Hero Banner Ultimate
hero-banner-ultimate
Add hero banner with the help of background image OR background color OR background video. Also work with Gutenberg shortcode block.
mb.YTPlayer for background videos
wpmbytplayer
Play any Youtube video as background of your page or as custom player inside an element of the page.
Advanced WordPress Backgrounds Developer Profile
94 plugins · 2.1M total installs
How We Detect Advanced WordPress Backgrounds
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/advanced-backgrounds/assets/awb/awb.min.js/wp-content/plugins/advanced-backgrounds/assets/awb/awb.min.css/wp-content/plugins/advanced-backgrounds/assets/vendor/jarallax/dist/jarallax.min.js/wp-content/plugins/advanced-backgrounds/assets/vendor/jarallax/dist/jarallax-video.min.js/wp-content/plugins/advanced-backgrounds/assets/awb/awb.min.js/wp-content/plugins/advanced-backgrounds/assets/vendor/jarallax/dist/jarallax.min.js/wp-content/plugins/advanced-backgrounds/assets/vendor/jarallax/dist/jarallax-video.min.jsadvanced-backgrounds/assets/awb/awb.min.css?ver=1.12.8advanced-backgrounds/assets/awb/awb.min.js?ver=1.12.8advanced-backgrounds/assets/vendor/jarallax/dist/jarallax.min.js?ver=2.2.1advanced-backgrounds/assets/vendor/jarallax/dist/jarallax-video.min.js?ver=2.2.1HTML / DOM Fingerprints
AWB/wp-json/advanced-backgrounds/v1