Simple banner – Lightweight Announcement Banner Without jQuery Security & Risk Analysis

wordpress.org/plugins/fsd-simple-banner

Simple banner a lightweight WordPress plugin without jQuery, allows adding a simple banner for announcements on your site. Perfect for notifications.

70 active installs v1.2.2 PHP 7.4+ WP 3.0.1+ Updated Feb 19, 2025
announcementbannerbarnoticenotification
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Simple banner – Lightweight Announcement Banner Without jQuery Safe to Use in 2026?

Generally Safe

Score 92/100

Simple banner – Lightweight Announcement Banner Without jQuery has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The `fsd-simple-banner` plugin version 1.2.2 exhibits a strong security posture based on the provided static analysis. A remarkably clean codebase with no dangerous functions, zero direct SQL queries without prepared statements, and a high percentage of properly escaped output are significant strengths. The absence of file operations and external HTTP requests further reduces the attack surface. The plugin also shows no history of reported vulnerabilities (CVEs), indicating a history of responsible development or a lack of past discoveries.

While the plugin appears secure on the surface, the complete lack of nonce checks and capability checks on its single shortcode entry point presents a potential concern. Although there are no unsanitized taint flows reported, a shortcode can still be a vector for Cross-Site Scripting (XSS) if user-supplied data is not meticulously sanitized before being displayed, even with overall high output escaping rates. The absence of any reported vulnerabilities might also be due to the plugin's obscurity or lack of rigorous security testing in the past, rather than guaranteed inherent security.

In conclusion, `fsd-simple-banner` v1.2.2 demonstrates excellent coding practices in many areas, particularly concerning SQL and output sanitation. However, the lack of authentication/authorization mechanisms on its sole entry point, the shortcode, is a notable weakness that could be exploited if user input is involved in its functionality. This oversight warrants attention despite the otherwise clean code and vulnerability history.

Key Concerns

  • Missing nonce checks on shortcode
  • Missing capability checks on shortcode
Vulnerabilities
None known

Simple banner – Lightweight Announcement Banner Without jQuery Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Simple banner – Lightweight Announcement Banner Without jQuery Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
22 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

96% escaped23 total outputs
Attack Surface

Simple banner – Lightweight Announcement Banner Without jQuery Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[fsdsb_simple_banner] fsd-simple-banner.php:110
WordPress Hooks 9
actionafter_setup_themeadmin\class-fsd-simple-banner-admin.php:54
actioncarbon_fields_register_fieldsadmin\class-fsd-simple-banner-admin.php:55
actioncrb_attach_theme_optionsadmin\class-fsd-simple-banner-admin.php:90
actionwp_footerfsd-simple-banner.php:103
actionplugins_loadedincludes\class-fsd-simple-banner.php:142
actionadmin_enqueue_scriptsincludes\class-fsd-simple-banner.php:157
actionadmin_enqueue_scriptsincludes\class-fsd-simple-banner.php:158
actionwp_enqueue_scriptsincludes\class-fsd-simple-banner.php:173
actionwp_enqueue_scriptsincludes\class-fsd-simple-banner.php:174
Maintenance & Trust

Simple banner – Lightweight Announcement Banner Without jQuery Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedFeb 19, 2025
PHP min version7.4
Downloads1K

Community Trust

Rating60/100
Number of ratings2
Active installs70
Developer Profile

Simple banner – Lightweight Announcement Banner Without jQuery Developer Profile

56 Degrees

4 plugins · 2K total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Simple banner – Lightweight Announcement Banner Without jQuery

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/fsd-simple-banner/public/css/fsd-simple-banner-public.css
Version Parameters
fsd-simple-banner/public/css/fsd-simple-banner-public.css?ver=

HTML / DOM Fingerprints

CSS Classes
fsd-sb-banner-wrapperfsd-sb-banner-contentfsd-sb-banner-close-button
Data Attributes
data-fsd-sb-dismiss
Shortcode Output
[fsdsb_simple_banner]
FAQ

Frequently Asked Questions about Simple banner – Lightweight Announcement Banner Without jQuery