
BNS Add Widget Security & Risk Analysis
wordpress.org/plugins/bns-add-widgetAdd a widget area to the footer of any theme.
Is BNS Add Widget Safe to Use in 2026?
Generally Safe
Score 85/100BNS Add Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'bns-add-widget' v1.0 plugin exhibits a generally strong security posture in several key areas. Static analysis reveals no identified attack surface points, meaning there are no exposed AJAX handlers, REST API routes, shortcodes, or cron events that could be directly targeted. Furthermore, the code signals indicate a complete absence of dangerous functions and raw SQL queries, with all SQL operations utilizing prepared statements. This suggests a deliberate effort to prevent common injection vulnerabilities.
However, there are areas that warrant attention. The plugin has a 50% rate of improperly escaped output, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is rendered directly. The presence of an external HTTP request, while not inherently malicious, could be a vector for certain attacks if not handled securely. The complete lack of nonce checks and capability checks is a significant concern, as it implies that any function can be called by any user, potentially leading to privilege escalation or unauthorized actions if other vulnerabilities are present.
The plugin's vulnerability history is clean, with no known CVEs. This is a positive indicator, suggesting that the plugin has not been historically a source of significant security flaws. However, the lack of historical vulnerabilities does not negate the risks identified in the current code analysis. In conclusion, while the plugin has a solid foundation in preventing common injection attacks, the missing authentication and authorization checks, coupled with unescaped output, present notable security weaknesses that should be addressed.
Key Concerns
- Unescaped output detected (50%)
- No nonce checks implemented
- No capability checks implemented
- External HTTP request made
BNS Add Widget Security Vulnerabilities
BNS Add Widget Code Analysis
Output Escaping
BNS Add Widget Attack Surface
WordPress Hooks 4
Maintenance & Trust
BNS Add Widget Maintenance & Trust
Maintenance Signals
Community Trust
BNS Add Widget Alternatives
BNS Login
bns-login
This plugin provides a link, in the theme footer area, to the dashboard when logged in as well as a log out link. A shortcode is also available.
Tiny Widget Manager
tiny-widget-manager
Tiny Widget Manager enhances the WordPress widget system by letting you control the visibility of each widget based on various conditions.
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor
elementskit-lite
Join millions who empower their websites with ElementsKit Elementor Addons. Get templates, & 100+ widgets like header-footer, mega menu, custom widget
Ultimate Addons for Elementor
header-footer-elementor
Powerful Elementor addon with advanced Elementor widgets, templates, WooCommerce widgets & Header-Footer builder to build professional websites fa …
Royal Addons for Elementor – Addons and Templates Kit for Elementor
royal-elementor-addons
Elementor templates, Header footer builder, Elementor Post Grid, Woocommerce Grid builder, Slider, Forms, Gallery, Nav menu addons, Elementor widgets.
BNS Add Widget Developer Profile
18 plugins · 2K total installs
How We Detect BNS Add Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bns-add-widget/bnsaw-style.cssbns-add-widget/bnsaw-style.css?ver=HTML / DOM Fingerprints
bns-add-widgetbns-add-widget-titlebnsaw-creditbnsaw-credit-text<!-- #%1$s .widget .%2$s --><!-- .bns-add-widget -->