
Announcement & Notification Banner – Bulletin Security & Risk Analysis
wordpress.org/plugins/bulletin-announcementsPublish a slick announcement banner notice across your website or Woocommerce shop. Extend with icons, countdowns, placement rules and more!
Is Announcement & Notification Banner – Bulletin Safe to Use in 2026?
Generally Safe
Score 96/100Announcement & Notification Banner – Bulletin has a strong security track record. Known vulnerabilities have been patched promptly.
The "bulletin-announcements" v3.14.0 plugin presents a mixed security posture. While the code demonstrates strong adherence to modern WordPress security practices, with a high percentage of SQL queries using prepared statements and an excellent rate of output escaping, there are significant concerns. The presence of a single AJAX handler without authentication checks represents a direct entry point for potential unauthorized actions. Furthermore, the use of the `unserialize` function is a critical red flag, as it can be exploited for Remote Code Execution (RCE) if not handled with extreme caution and strict input validation. The plugin's vulnerability history is also concerning, with a total of 5 known CVEs, including one high-severity vulnerability related to SQL Injection and others covering Cross-Site Scripting, CSRF, and Missing Authorization. The fact that there are no currently unpatched vulnerabilities is positive, but the recurring nature of these vulnerability types suggests potential weaknesses in the development process that could be re-introduced. Overall, the plugin has good foundational security practices but is marred by a critical code signal (`unserialize`) and a significant historical pattern of security flaws, making it a moderate to high risk.
Key Concerns
- AJAX handler without authentication
- Dangerous function: unserialize
- 1 High severity CVE history
- 4 Medium severity CVE history
- Bundled outdated library: Freemius v1.0
Announcement & Notification Banner – Bulletin Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
Bulletin Announcements <= 3.11.7 - Reflected Cross-Site Scripting
WordPress Announcement & Notification Banner Plugin – Bulletin <= 3.8.5 - Authenticated (Administrator+) SQL Injection
Announcement & Notification Banner – Bulletin <= 3.7.0 - Cross-Site Request Forgery
Announcement & Notification Banner – Bulletin <= 3.6.0 - Missing Authorization Checks
Announcement & Notification Banner – Bulletin <= 3.5.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting
Announcement & Notification Banner – Bulletin Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Announcement & Notification Banner – Bulletin Attack Surface
AJAX Handlers 1
WordPress Hooks 23
Maintenance & Trust
Announcement & Notification Banner – Bulletin Maintenance & Trust
Maintenance Signals
Community Trust
Announcement & Notification Banner – Bulletin Alternatives
wiseCampaign – WooCommerce Conversions Made Easy
wisecampaign
Turn visitors into buyers faster with banners, urgency timers, direct checkout, discounts, popups & mini-cart.
Disable Admin Notices – Hide Dashboard Notifications
disable-admin-notices
Disable admin notices and hide dashboard notifications from plugins, themes and core. Hide all notices, selected ones, or show them in a single line.
Hide Admin Notices
hide-admin-notices
Hide – or show – WordPress Dashboard Notices, Messages, Update Nags etc. ... for everything!
Hide Dashboard Notifications
wp-hide-backed-notices
Warnings and notices can be helpful for developers as they notify them for debugging issues with their code. Though these notices can be sometimes inf …
Disable WP Notification
disable-wp-notification
Best wordpress plugin to remove all the admin panel notifications in just one click. Including the theme and plugin update notification.
Announcement & Notification Banner – Bulletin Developer Profile
7 plugins · 17K total installs
How We Detect Announcement & Notification Banner – Bulletin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bulletin-announcements/admin/build/free.css/wp-content/plugins/bulletin-announcements/admin/build/free.js/wp-content/plugins/bulletin-announcements/admin/build/free.jsbulletin-announcements/admin/build/free.css?ver=bulletin-announcements/admin/build/free.js?ver=HTML / DOM Fingerprints
data-bulletinwp-plugin-slugBULLETINWP