Genesis Promotion Box Security & Risk Analysis

wordpress.org/plugins/genesis-promotion-box

This plugin allows you to add a promotion box after a single post in Genesis.

10 active installs v0.1 PHP + WP 3.1+ Updated Aug 10, 2015
custom-post-typegenesispromotion
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Genesis Promotion Box Safe to Use in 2026?

Generally Safe

Score 85/100

Genesis Promotion Box has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The 'genesis-promotion-box' plugin version 0.1 exhibits a very strong security posture based on the provided static analysis. The absence of any identified attack surface vectors like AJAX handlers, REST API routes, shortcodes, or cron events significantly reduces the potential for malicious exploitation. Furthermore, the code signals are overwhelmingly positive, with no dangerous functions, all SQL queries using prepared statements, and all output properly escaped. The lack of file operations, external HTTP requests, and the absence of critical security checks like nonce and capability checks are also indicators of a clean codebase in these areas, though their absence also contributes to the overall lack of defined entry points.

The taint analysis reveals no identified flows with unsanitized paths, further reinforcing the excellent security characteristics observed. The vulnerability history is completely clear, with no known CVEs, past or present. This lack of historical vulnerabilities, combined with the pristine static analysis, suggests a development process that prioritizes security. However, it's important to note that the version number 0.1 indicates this is a very early release, and the lack of entry points might be due to the plugin's limited functionality rather than a deliberate robust security design. Future versions with expanded features could introduce new attack vectors.

Key Concerns

  • No capability checks
  • No nonce checks
Vulnerabilities
None known

Genesis Promotion Box Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Genesis Promotion Box Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Genesis Promotion Box Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actioninitpromo-box.php:43
actiongenesis_after_postpromo-box.php:50
Maintenance & Trust

Genesis Promotion Box Maintenance & Trust

Maintenance Signals

WordPress version tested4.3.34
Last updatedAug 10, 2015
PHP min version
Downloads4K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Genesis Promotion Box Developer Profile

Ron Rennick

10 plugins · 1K total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Genesis Promotion Box

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/genesis-promotion-box/promo-box.php

HTML / DOM Fingerprints

CSS Classes
genesis-promo-boxaltthread-altclear
Shortcode Output
<div id="genesis-promo-box" class="alt thread-alt"><h3></h3></div>
FAQ

Frequently Asked Questions about Genesis Promotion Box