
Simple Website Banner Security & Risk Analysis
wordpress.org/plugins/corona-virus-covid-19-bannerThis is a very simple plugin with a sole purpose of allowing you to inform your visitors of an upcoming event, updated store hours, or other important …
Is Simple Website Banner Safe to Use in 2026?
Generally Safe
Score 90/100Simple Website Banner has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of the "corona-virus-covid-19-banner" plugin version 1.8.0.4 reveals a seemingly clean code base with no identified attack surface in terms of AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, the code shows a positive sign by using prepared statements for all SQL queries and avoiding dangerous functions, file operations, and external HTTP requests. However, a significant concern arises from the low percentage (20%) of properly escaped output, indicating a high likelihood of Cross-Site Scripting (XSS) vulnerabilities. Taint analysis also shows no reported issues, which, when combined with the output escaping findings, might suggest an incomplete taint analysis or an oversight in identifying potential XSS vectors.
The vulnerability history paints a more concerning picture. With two known CVEs, including a high and a medium severity vulnerability, and a recent history of XSS and CSRF issues, the plugin has a track record of security weaknesses. The fact that there are currently no unpatched vulnerabilities is a positive sign, but the pattern of past issues, particularly XSS, combined with the static analysis finding of poor output escaping, strongly suggests that XSS remains a significant potential risk. While the absence of an exploitable attack surface and proper SQL handling are good, the persistent output escaping problem and past vulnerability trends indicate a need for caution.
Key Concerns
- Low percentage of properly escaped output
- One unpatched medium severity vulnerability
- One unpatched high severity vulnerability
- History of XSS and CSRF vulnerabilities
Simple Website Banner Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Corona Virus (COVID-19) Banner & Live Data <= 1.8.0.3 - Authenticated (Administrator+) Stored Cross-Site Scripting
Corona Virus (COVID-19) Banner & Live Data <= 1.7.0.6 - Cross-Site Request Forgery
Simple Website Banner Code Analysis
Output Escaping
Simple Website Banner Attack Surface
WordPress Hooks 9
Maintenance & Trust
Simple Website Banner Maintenance & Trust
Maintenance Signals
Community Trust
Simple Website Banner Alternatives
Corona Virus Data
corona-virus-data
This plugin displays the Coronavirus case data through shortcodes [cov2019] [cov2019all] or [cov2019map] in your WordPress post or page.
South African COVID19 Banner
corona-virus-covid19-banner
Comply with new South African Covid-19 regulations requiring all websites ending in .ZA to show a link to the official government page.
COVID-19 Float Button
covid-19-float-button
Creates a floating button with a link to a read more page.
VirusWeather Covid-19 Coronavirus
virusweather
Personalized by IP address PNG banner shows local covid-19 A.I. calculated threat level and live coronavirus stats for 10000+ local areas world-wide
Corona Update
corona-update
Corona Update WordPress Plugin to show corona current cases and more information about COVID-19. You will be able to show the relevant information: ca …
Simple Website Banner Developer Profile
3 plugins · 700 total installs
How We Detect Simple Website Banner
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/corona-virus-covid-19-banner/assets/css/front.css/wp-content/plugins/corona-virus-covid-19-banner/assets/js/front.js/wp-content/plugins/corona-virus-covid-19-banner/assets/js/front.jscorona-virus-covid-19-banner/assets/css/front.css?ver=corona-virus-covid-19-banner/assets/js/front.js?ver=HTML / DOM Fingerprints
ocvb-enabledocvb-disabledocvb-display-type-bannerocvb-display-type-overlayocvb-display-type-leaderboardocvb-display-type-bannerocvb-display-type-overlayocvb-display-type-leaderboard+7 moredata-message-alignmentdata-allow-closeOrchestrated_Corona_Virus_Banner