Github Ribbon Security & Risk Analysis

wordpress.org/plugins/github-ribbon

Adds "Fork me on Github" ribbons to your WordPress posts

30 active installs v1.2.1 PHP + WP 3.8+ Updated Oct 13, 2021
gitgithubribbon
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Github Ribbon Safe to Use in 2026?

Generally Safe

Score 85/100

Github Ribbon has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The "github-ribbon" plugin exhibits a generally positive security posture with a minimal attack surface and no recorded vulnerabilities in its history. The static analysis shows no dangerous functions, SQL queries are properly prepared, and there are no file operations or external HTTP requests, all of which are good security practices. The presence of nonce and capability checks, while limited, also indicates some level of security awareness in the code.

Key Concerns

  • Low output escaping coverage
Vulnerabilities
None known

Github Ribbon Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Github Ribbon Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
15
4 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

21% escaped19 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<github-ribbon> (github-ribbon.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Github Ribbon Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_menugithub-ribbon.php:52
actionadmin_initgithub-ribbon.php:53
actionadmin_menugithub-ribbon.php:56
actionsave_postgithub-ribbon.php:59
actiontemplate_redirectgithub-ribbon.php:62
actionwp_footergithub-ribbon.php:65
actionin_admin_footergithub-ribbon.php:258
actioninitgithub-ribbon.php:421
Maintenance & Trust

Github Ribbon Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedOct 13, 2021
PHP min version
Downloads7K

Community Trust

Rating100/100
Number of ratings1
Active installs30
Developer Profile

Github Ribbon Developer Profile

Sudar Muthu

16 plugins · 21K total installs

84
trust score
Avg Security Score
86/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Github Ribbon

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/github-ribbon/github-ribbon.css/wp-content/plugins/github-ribbon/github-ribbon.js
Script Paths
/wp-content/plugins/github-ribbon/github-ribbon.js
Version Parameters
github-ribbon.css?ver=github-ribbon.js?ver=

HTML / DOM Fingerprints

CSS Classes
github-ribbongithub-ribbon-wrappergithub-ribbon-btn
HTML Comments
<!-- github-ribbon --><!-- github-ribbon-wrapper --><!-- github-ribbon-btn -->
Data Attributes
data-ribbon-typedata-ribbon-urldata-ribbon-textdata-ribbon-position
JS Globals
githubRibbon
FAQ

Frequently Asked Questions about Github Ribbon