Banner Display Thumbnail Security & Risk Analysis

wordpress.org/plugins/banner-display-thumbnail

A quick, easy way to add an Responsive header Banner Display Thumbnail OR Responsive Banner Display Thumbnail inside wordpress page OR Template.

10 active installs v1.0 PHP + WP 3.5+ Updated Feb 3, 2016
banner-display-thumbnailimage-slidermobile-touch-banner-display-thumbnailresponsive-banner-display-thumbnailresponsive-header-gallery-slider
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Banner Display Thumbnail Safe to Use in 2026?

Generally Safe

Score 85/100

Banner Display Thumbnail has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The "banner-display-thumbnail" v1.0 plugin exhibits a generally good security posture based on this static analysis. It has a very small attack surface, with only one shortcode entry point, and no identified AJAX handlers or REST API routes that are unprotected. The code also demonstrates adherence to several security best practices, including the use of prepared statements for all SQL queries, a nonce check for its shortcode, and capability checks which likely protect its functionality. The absence of file operations and external HTTP requests further reduces potential attack vectors.

However, there are areas for improvement. The most significant concern is the low percentage of properly escaped output (22%). This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, where unescaped data, potentially originating from user input, could be rendered directly in the browser, allowing attackers to inject malicious scripts. While taint analysis did not reveal any specific flows, the lack of comprehensive output escaping creates a latent vulnerability.

The plugin's vulnerability history is clean, with no recorded CVEs. This, combined with the absence of critical or high-severity signals in the static analysis, suggests that the developers have likely followed good security practices. Despite the low output escaping, the overall security risk appears moderate, primarily due to the limited attack surface and the clean vulnerability history. Addressing the output escaping is the most critical next step to further harden this plugin.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

Banner Display Thumbnail Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Banner Display Thumbnail Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
2 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

22% escaped9 total outputs
Attack Surface

Banner Display Thumbnail Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[bdt_gallery.slider] banner-display-thumbnail.php:38
WordPress Hooks 10
actioninitbanner-display-thumbnail.php:22
actionwp_enqueue_scriptsbanner-display-thumbnail.php:25
actioninitbanner-display-thumbnail.php:28
actionadd_meta_boxesbanner-display-thumbnail.php:29
actionsave_postbanner-display-thumbnail.php:30
filtermanage_responsive_bdt_slider-category_custom_columnbanner-display-thumbnail.php:35
filtermanage_edit-responsive_bdt_slider-category_columnsbanner-display-thumbnail.php:36
actionplugins_loadedbanner-display-thumbnail.php:327
actionadmin_menubdt_gallery_admin_settings_center.php:2
actionadmin_headbdt_gallery_admin_settings_center.php:43
Maintenance & Trust

Banner Display Thumbnail Maintenance & Trust

Maintenance Signals

WordPress version tested4.4.34
Last updatedFeb 3, 2016
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Banner Display Thumbnail Developer Profile

smit jon

14 plugins · 140 total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Banner Display Thumbnail

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/banner-display-thumbnail/css/responsiveimgslider.css/wp-content/plugins/banner-display-thumbnail/css/sangarSlider.css/wp-content/plugins/banner-display-thumbnail/css/demo.css/wp-content/plugins/banner-display-thumbnail/themes/default-big/default-big.css/wp-content/plugins/banner-display-thumbnail/js/sangarSlider/sangarBaseClass.js/wp-content/plugins/banner-display-thumbnail/js/sangarSlider/sangarSetupLayout.js/wp-content/plugins/banner-display-thumbnail/js/sangarSlider/sangarSizeAndScale.js/wp-content/plugins/banner-display-thumbnail/js/sangarSlider/sangarShift.js+13 more
Script Paths
/wp-content/plugins/banner-display-thumbnail/js/sangarSlider/sangarBaseClass.js/wp-content/plugins/banner-display-thumbnail/js/sangarSlider/sangarSetupLayout.js/wp-content/plugins/banner-display-thumbnail/js/sangarSlider/sangarSizeAndScale.js/wp-content/plugins/banner-display-thumbnail/js/sangarSlider/sangarShift.js/wp-content/plugins/banner-display-thumbnail/js/sangarSlider/sangarSetupBulletNav.js/wp-content/plugins/banner-display-thumbnail/js/sangarSlider/sangarSetupNavigation.js+11 more

HTML / DOM Fingerprints

CSS Classes
bdt_gallery_slider
Data Attributes
gallery_bdt_shortcode
Shortcode Output
[bdt_gallery.slider]
FAQ

Frequently Asked Questions about Banner Display Thumbnail