
BS Banners Security & Risk Analysis
wordpress.org/plugins/bs-bannersCopyright (C) Albano Toska Tags: image hover effects for wpbakery page builder, image caption hover for wpbakery page builder, visual composer image h …
Is BS Banners Safe to Use in 2026?
Generally Safe
Score 85/100BS Banners has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "bs-banners" plugin v3.6.8 presents a mixed security posture. On the positive side, the plugin exhibits excellent security hygiene by avoiding dangerous functions, performing all SQL queries using prepared statements, and having no recorded vulnerabilities or CVEs. The absence of file operations and external HTTP requests is also a strength. However, a significant concern arises from the complete lack of output escaping, with 0% of 208 outputs being properly sanitized. This is a critical weakness that could lead to cross-site scripting (XSS) vulnerabilities if any user-supplied data is ever rendered directly to the browser.
While the attack surface is small (2 shortcodes) and there are no unauthenticated entry points or critical taint flows detected, the lack of output escaping overshadows these positives. The vulnerability history being clean suggests diligent maintenance or a lack of targeted attacks, but it does not negate the inherent risk posed by unescaped output. In conclusion, the plugin demonstrates good practices in critical areas like SQL and vulnerability management, but the failure to implement proper output escaping creates a substantial risk that needs immediate attention.
Key Concerns
- 0% properly escaped output
BS Banners Security Vulnerabilities
BS Banners Code Analysis
Output Escaping
BS Banners Attack Surface
Shortcodes 2
WordPress Hooks 9
Maintenance & Trust
BS Banners Maintenance & Trust
Maintenance Signals
Community Trust
BS Banners Alternatives
No alternatives data available yet.
BS Banners Developer Profile
2 plugins · 3K total installs
How We Detect BS Banners
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bs-banners/css/style.css/wp-content/plugins/bs-banners/js/main.jshttps://stackpath.bootstrapcdn.com/font-awesome/4.7.0/css/font-awesome.min.cssbs-banners/css/style.css?ver=HTML / DOM Fingerprints
bunny-image-classbunny-banners-shortcodes-containerwpb_element_titledata-vc-shortcode-param-name=\"style\"bs_banner_shortcodebtn[bs_banner