
EL Banners Security & Risk Analysis
wordpress.org/plugins/el-bannersThis plugin allow you to create widgets which will show banners, links or any other code from specified folder or file into sidebar automatically.
Is EL Banners Safe to Use in 2026?
Generally Safe
Score 85/100EL Banners has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'el-banners' plugin version 0.2 exhibits a mixed security posture. On the positive side, the absence of known CVEs and a history of vulnerabilities is a strong indicator of past security diligence. The static analysis also reveals a limited attack surface with no apparent AJAX handlers, REST API routes, shortcodes, or cron events that could be directly exploited without authentication. Furthermore, all SQL queries are properly prepared, and there are no external HTTP requests, reducing common web attack vectors.
However, significant concerns arise from the static analysis. The presence of the `create_function` dangerous function is a critical red flag, as it can be exploited for code injection if used with unsanitized input. The low percentage of properly escaped output (10%) suggests a high likelihood of cross-site scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the web pages. The lack of nonce checks on any entry points, combined with the single capability check, indicates that actions performed by the plugin might not be adequately protected against unauthorized execution or manipulation.
In conclusion, while the plugin has a clean vulnerability history and a small attack surface, the identified code signals, particularly the `create_function` usage and poor output escaping, present substantial security risks. These issues could lead to code execution and XSS vulnerabilities, undermining the overall security of a WordPress site. The plugin needs immediate attention to address these critical code-level weaknesses.
Key Concerns
- Use of dangerous function 'create_function'
- Low percentage of properly escaped output
- Missing nonce checks on entry points
EL Banners Security Vulnerabilities
EL Banners Code Analysis
Dangerous Functions Found
Output Escaping
EL Banners Attack Surface
WordPress Hooks 1
Maintenance & Trust
EL Banners Maintenance & Trust
Maintenance Signals
Community Trust
EL Banners Alternatives
Ownyourblog Banner Widget
ownyourblog-banner-widget
Simple, but powerful widget to show any banner you want in your sidebar. One-click solution!
Classic Widgets
classic-widgets
Enables the previous "classic" widgets settings screens in Appearance - Widgets and the Customizer. Disables the block editor from managing widgets.
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor
elementskit-lite
Join millions who empower their websites with ElementsKit Elementor Addons. Get templates, & 100+ widgets like header-footer, mega menu, custom widget
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Ultimate Addons for Elementor
header-footer-elementor
Powerful Elementor addon with advanced Elementor widgets, templates, WooCommerce widgets & Header-Footer builder to build professional websites fa …
EL Banners Developer Profile
1 plugin · 10 total installs
How We Detect EL Banners
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
elbanners