
Black Ribbon by Attawit Security & Risk Analysis
wordpress.org/plugins/black-ribbon-by-attawitDisplay mourning Black Ribbon at selected corner on every page of your website.
Is Black Ribbon by Attawit Safe to Use in 2026?
Generally Safe
Score 85/100Black Ribbon by Attawit has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the static analysis, the "black-ribbon-by-attawit" plugin version 1.1.3 presents a seemingly strong security posture with no identified vulnerabilities in its history and a clean code analysis. The absence of dangerous functions, file operations, external HTTP requests, and critical taint flows indicates good development practices for these areas. Furthermore, the plugin utilizes prepared statements for its SQL queries and exhibits a high percentage of properly escaped output, which are positive signs for preventing common injection and cross-site scripting (XSS) vulnerabilities.
However, there are some points of concern. The most significant is the complete lack of nonce checks and a single capability check without any explicit mention of its implementation or context. This raises questions about the protection of potentially sensitive actions within the plugin. While the attack surface appears to be zero, this could be due to the plugin's specific functionality or an incomplete analysis. The zero taint flows are also noteworthy; while generally positive, it could indicate a very limited scope of user input processing or a potential gap in the taint analysis itself if the plugin is expected to handle user-supplied data.
In conclusion, the plugin demonstrates good foundational security by avoiding common pitfalls like raw SQL and insecure output. The absence of historical vulnerabilities is a positive indicator of past security awareness. Nevertheless, the lack of detailed information on nonce and capability checks, coupled with the zero taint flows, warrants further investigation to ensure all potential attack vectors are adequately secured.
Key Concerns
- 0 Nonce checks found
- Only 1 capability check identified
- No taint flows analyzed
Black Ribbon by Attawit Security Vulnerabilities
Black Ribbon by Attawit Code Analysis
Output Escaping
Black Ribbon by Attawit Attack Surface
WordPress Hooks 4
Maintenance & Trust
Black Ribbon by Attawit Maintenance & Trust
Maintenance Signals
Community Trust
Black Ribbon by Attawit Alternatives
WP Simple Mourning
wp-simple-mouring
Simple implementation of mourning in your page. Grey out your website.
Paris Attacks Ribbon MC
paris-attacks-mc
Show support to Parisian and French people with a selected ribbon in your website corner. Configure the display via the Settings panel.
WP Black Ribbon
wp-black-ribbon
Put the black ribbon image to your wordpress website.
Mourning
mourning
Add black ribbon and grey out the website
WP Mourning
wp-mourning
A simple plugin to Gray out website showing the black ribbon to show mourning for your loved one.
Black Ribbon by Attawit Developer Profile
1 plugin · 10 total installs
How We Detect Black Ribbon by Attawit
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/black-ribbon-by-attawit/images/black_ribbon_bottom_left.png/wp-content/plugins/black-ribbon-by-attawit/images/black_ribbon_bottom_right.png/wp-content/plugins/black-ribbon-by-attawit/images/black_ribbon_top_left.png/wp-content/plugins/black-ribbon-by-attawit/images/black_ribbon_top_right.png/wp-content/plugins/black-ribbon-by-attawit/blackribbon.css/wp-content/plugins/black-ribbon-by-attawit/blackribbon.js/wp-content/plugins/black-ribbon-by-attawit/blackribbon.jsHTML / DOM Fingerprints
blackribbon-datepickerblackribbon-datepicker-outputblackribbon_rowname="blackribbon_options[blackribbon_location]"name="blackribbon_options[blackribbon_schedule_enable]"name="blackribbon_options[blackribbon_schedule_startdate_text]"name="blackribbon_options[blackribbon_schedule_enddate_text]"name="blackribbon_options[blackribbon_schedule_startdate]"name="blackribbon_options[blackribbon_schedule_enddate]"