
Courier Notices Security & Risk Analysis
wordpress.org/plugins/courier-noticesAdd dismissible and non-dismissible notices throughout your WordPress website with customizable colors, icons, and placement options.
Is Courier Notices Safe to Use in 2026?
Generally Safe
Score 100/100Courier Notices has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "courier-notices" v1.9.17 plugin exhibits a generally strong security posture with excellent adherence to many WordPress security best practices. The high percentage of prepared SQL statements and properly escaped output are commendable. Furthermore, the absence of any recorded vulnerabilities or CVEs suggests a history of stable and secure development. The plugin also demonstrates good use of nonces and capability checks across its entry points, which are all protected by authentication.
However, the static analysis does reveal some areas of concern that warrant attention. The presence of the `assert` dangerous function, while potentially used for debugging or assertions, can be a vector for code injection if not carefully controlled and is a specific code signal to note. The taint analysis identified two flows with unsanitized paths, one of which is flagged as high severity, indicating a potential for data leakage or injection if these paths are maliciously exploited. While no direct vulnerabilities are known historically, these taint flows represent a latent risk.
In conclusion, the plugin is well-developed with a strong foundation in security. The lack of known vulnerabilities and robust use of authentication, nonces, and prepared statements are significant strengths. Nevertheless, the identified `assert` function and the high-severity taint flow with unsanitized paths are weaknesses that should be addressed to further harden the plugin and mitigate potential future risks.
Key Concerns
- High severity taint flow with unsanitized paths
- Presence of dangerous function: assert
- Taint flows with unsanitized paths (x2)
Courier Notices Security Vulnerabilities
Courier Notices Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Courier Notices Attack Surface
AJAX Handlers 5
Shortcodes 2
WordPress Hooks 72
Scheduled Events 3
Maintenance & Trust
Courier Notices Maintenance & Trust
Maintenance Signals
Community Trust
Courier Notices Alternatives
Disable Admin Notices – Hide Dashboard Notifications
disable-admin-notices
Disable admin notices and hide dashboard notifications from plugins, themes and core. Hide all notices, selected ones, or show them in a single line.
Hide Admin Notices
hide-admin-notices
Hide – or show – WordPress Dashboard Notices, Messages, Update Nags etc. ... for everything!
Hide Dashboard Notifications
wp-hide-backed-notices
Warnings and notices can be helpful for developers as they notify them for debugging issues with their code. Though these notices can be sometimes inf …
Disable WP Notification
disable-wp-notification
Best wordpress plugin to remove all the admin panel notifications in just one click. Including the theme and plugin update notification.
Hide admin notices – Admin Notification Center
wp-admin-notification-center
Keep your dashboard clean by grouping all the WordPress notice and hide them in a notification center.
Courier Notices Developer Profile
17 plugins · 153K total installs
How We Detect Courier Notices
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/courier-notices/build/courier-notices.css/wp-content/plugins/courier-notices/build/courier-notices.js/wp-content/plugins/courier-notices/build/courier-notices.jscourier-notices/build/courier-notices.css?ver=courier-notices/build/courier-notices.js?ver=HTML / DOM Fingerprints
cn-notice-wrappercn-notice-contentcn-notice-iconcn-notice-closecourier-notices-admin-noticedata-cn-iddata-cn-noncedata-cn-actionCourierNoticescourierNoticesApiSettings/wp-json/courier-notices/v1/notices/display/(.*)[courier-notices]