Bannerspace Slideshow Security & Risk Analysis

wordpress.org/plugins/bannerspace

A banner plugin for WordPress powered by the jQuery Cycle Plugin.

100 active installs v1.3.5 PHP + WP 3.0+ Updated Dec 19, 2015
bannergalleryphotophotography
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Bannerspace Slideshow Safe to Use in 2026?

Generally Safe

Score 85/100

Bannerspace Slideshow has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The plugin "bannerspace" v1.3.5 exhibits a generally good security posture with no recorded vulnerabilities or critical code signals in static analysis. The absence of known CVEs and the plugin's limited attack surface are positive indicators. The code analysis reveals no dangerous functions, file operations, external HTTP requests, or raw SQL queries, which are all strong security practices. However, a significant concern arises from the complete lack of output escaping. With 24 total outputs and 0% properly escaped, this presents a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the website. The lack of nonce checks and capability checks also indicates potential authorization and integrity issues, particularly if the shortcode has any user-facing functionality that could be manipulated. While the plugin is clean in many areas, the unescaped output and potential authorization bypasses represent critical weaknesses that need immediate attention.

Key Concerns

  • 0% output escaping
  • 0 Nonce checks
  • 0 Capability checks
Vulnerabilities
None known

Bannerspace Slideshow Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Bannerspace Slideshow Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
24
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped24 total outputs
Attack Surface

Bannerspace Slideshow Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[bannerspace] bannerspace.php:514
WordPress Hooks 4
actionadmin_menubannerspace.php:316
actionwp_enqueue_scriptsbannerspace.php:331
actionwp_headbannerspace.php:512
actioninitbannerspace.php:586
Maintenance & Trust

Bannerspace Slideshow Maintenance & Trust

Maintenance Signals

WordPress version tested4.2.39
Last updatedDec 19, 2015
PHP min version
Downloads32K

Community Trust

Rating94/100
Number of ratings3
Active installs100
Developer Profile

Bannerspace Slideshow Developer Profile

THRIVE - Web Design Gold Coast

7 plugins · 12K total installs

71
trust score
Avg Security Score
88/100
Avg Patch Time
735 days
View full developer profile
Detection Fingerprints

How We Detect Bannerspace Slideshow

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bannerspace/bannerspace.js/wp-content/plugins/bannerspace/bannerspace.css
Script Paths
/wp-content/plugins/bannerspace/bannerspace.js
Version Parameters
bannerspace/bannerspace.js?ver=bannerspace/bannerspace.css?ver=

HTML / DOM Fingerprints

CSS Classes
bannerspace_container
Data Attributes
data-slide_effectdata-sync_effectdata-banner_widthdata-banner_heightdata-banner_paddingdata-content_width+13 more
JS Globals
bannerspace
Shortcode Output
[bannerspace]
FAQ

Frequently Asked Questions about Bannerspace Slideshow