Hero Banner Ultimate Security & Risk Analysis

wordpress.org/plugins/hero-banner-ultimate

Add hero banner with the help of background image OR background color OR background video. Also work with Gutenberg shortcode block.

1K active installs v1.4.6 PHP + WP 4.0+ Updated Feb 20, 2026
hero-banner-imagehero-header-videohero-video-backgroundvimeo-video-backgroundyoutube-video-background
98
A · Safe
CVEs total2
Unpatched0
Last CVEJan 6, 2025
Safety Verdict

Is Hero Banner Ultimate Safe to Use in 2026?

Generally Safe

Score 98/100

Hero Banner Ultimate has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Jan 6, 2025Updated 1mo ago
Risk Assessment

The 'hero-banner-ultimate' plugin version 1.4.6 presents a mixed security profile. The static analysis indicates generally good coding practices, with a large percentage of outputs being properly escaped and all SQL queries utilizing prepared statements. The absence of dangerous functions, file operations, and external HTTP requests is also a positive sign. However, the low number of identified entry points (only one shortcode) and the lack of any detected taint flows might be misleading, as zero taint flows doesn't inherently guarantee security, especially if the analyzed code paths were limited or the plugin's functionality is minimal.

The plugin's vulnerability history is a significant concern. With two known CVEs, one high and one medium severity, and past vulnerabilities involving critical types like PHP Remote File Inclusion and Cross-Site Scripting, there is a clear pattern of past exploitable weaknesses. The fact that none are currently unpatched is a relief, but it highlights a history of exploitable flaws that require careful monitoring for future versions. The lack of nonce checks and capability checks on the single identified shortcode, while not explicitly flagged as an issue in the static analysis (likely due to limited entry points or analysis depth), could be a potential oversight if the shortcode handles sensitive data or performs actions that require authorization.

In conclusion, while the current version shows improvements in secure coding practices like output escaping and prepared statements, the historical prevalence of severe vulnerabilities warrants caution. The plugin has demonstrated a history of significant security flaws, suggesting that past development may have had gaps in secure coding. Users should remain vigilant, ensure the plugin is always updated to the latest version, and consider the historical risk profile when evaluating its use.

Key Concerns

  • High and Medium severity CVEs in vulnerability history
  • History of critical vulnerability types (RFI, XSS)
  • No nonce checks identified
  • Limited capability checks identified
Vulnerabilities
2

Hero Banner Ultimate Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

High
1
Medium
1

2 total CVEs

CVE-2025-22305high · 8.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

Hero Banner Ultimate <= 1.4.4 - Authenticated (Author+) Local File Inclusion

Jan 6, 2025 Patched in 1.4.5 (171d)
CVE-2022-45818medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Hero Banner Ultimate <= 1.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodes

Feb 22, 2023 Patched in 1.4 (335d)
Code Analysis
Analyzed Mar 16, 2026

Hero Banner Ultimate Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
27
295 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

92% escaped322 total outputs
Attack Surface

Hero Banner Ultimate Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[hbupro_banner] includes\shortcode\hbu-banner-shortcode.php:190
WordPress Hooks 11
actionplugins_loadedhero-banner-ultimate.php:81
actionupdate_option_active_pluginshero-banner-ultimate.php:114
actionadmin_noticeshero-banner-ultimate.php:176
actionadmin_menuincludes\admin\class-hbu-admin.php:20
actionadd_meta_boxesincludes\admin\class-hbu-admin.php:23
actionadmin_initincludes\admin\class-hbu-admin.php:29
actionwp_enqueue_scriptsincludes\class-hbu-script.php:19
actionwp_enqueue_scriptsincludes\class-hbu-script.php:22
actionadmin_enqueue_scriptsincludes\class-hbu-script.php:25
actionadmin_enqueue_scriptsincludes\class-hbu-script.php:28
actioninitincludes\hbu-post-types.php:51
Maintenance & Trust

Hero Banner Ultimate Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 20, 2026
PHP min version
Downloads53K

Community Trust

Rating100/100
Number of ratings2
Active installs1K
Alternatives

Hero Banner Ultimate Alternatives

No alternatives data available yet.

Developer Profile

Hero Banner Ultimate Developer Profile

Essential Plugin

33 plugins · 205K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
219 days
View full developer profile
Detection Fingerprints

How We Detect Hero Banner Ultimate

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/hero-banner-ultimate/assets/css/hbu-public-style.min.css/wp-content/plugins/hero-banner-ultimate/assets/js/hbu-ultimate-bg.min.js/wp-content/plugins/hero-banner-ultimate/assets/js/hbu-public-script.js/wp-content/plugins/hero-banner-ultimate/assets/css/hbu-admin-style.css
Version Parameters
hero-banner-ultimate/assets/css/hbu-public-style.min.css?ver=hero-banner-ultimate/assets/js/hbu-ultimate-bg.min.js?ver=hero-banner-ultimate/assets/js/hbu-public-script.js?ver=hero-banner-ultimate/assets/css/hbu-admin-style.css?ver=

HTML / DOM Fingerprints

CSS Classes
hbu-public-stylehbu-admin-style
JS Globals
HBU_VERSIONHBU_DIRHBU_URLHBU_POST_TYPEHBU_META_PREFIXHBU_PLUGIN_LINK_UNLOCK+1 more
FAQ

Frequently Asked Questions about Hero Banner Ultimate