LXB Staging Reminder Security & Risk Analysis

wordpress.org/plugins/lxb-staging-reminder

Give the user a visual reminder that he or she is on a wp-engine staging environment.

0 active installs v0.1.1 PHP + WP 4.8+ Updated Nov 3, 2017
stagingwp-engine
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is LXB Staging Reminder Safe to Use in 2026?

Generally Safe

Score 85/100

LXB Staging Reminder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The lxb-staging-reminder plugin version 0.1.1 exhibits a seemingly secure static analysis profile, with no identified entry points that are unprotected. The absence of dangerous functions, file operations, external HTTP requests, and the use of prepared statements for all SQL queries are positive indicators. However, a critical concern arises from the complete lack of output escaping, meaning that any data processed and displayed by the plugin is vulnerable to cross-site scripting (XSS) attacks. Additionally, the complete absence of nonce and capability checks across the board is a significant security weakness, suggesting a lack of authorization and potential for unauthorized actions, even if no immediate attack vectors were found in the static analysis. The plugin's vulnerability history is clean, with no recorded CVEs, which might imply a lack of previous scrutiny or a history of good security practices. Nevertheless, the identified weaknesses in output escaping and authorization mechanisms demand attention and mitigation.

Key Concerns

  • Unescaped output detected
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

LXB Staging Reminder Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

LXB Staging Reminder Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

LXB Staging Reminder Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionplugins_loadedinc\Bootstrap.php:16
actionwp_enqueue_scriptsinc\Enqueue.php:18
actionadmin_enqueue_scriptsinc\Enqueue.php:19
actionlogin_enqueue_scriptsinc\Enqueue.php:20
actionwp_enqueue_scriptsinc\Enqueue.php:24
actionadmin_enqueue_scriptsinc\Enqueue.php:25
actionlogin_enqueue_scriptsinc\Enqueue.php:26
actionwp_footerinc\Markup.php:17
actionadmin_footerinc\Markup.php:18
actionlogin_footerinc\Markup.php:19
Maintenance & Trust

LXB Staging Reminder Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedNov 3, 2017
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

LXB Staging Reminder Developer Profile

Scott Fennell

4 plugins · 120 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect LXB Staging Reminder

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/lxb-staging-reminder/js/script.js/wp-content/plugins/lxb-staging-reminder/css/style.css
Script Paths
/wp-content/plugins/lxb-staging-reminder/js/script.js
Version Parameters
lxb-staging-reminder/js/script.js?ver=lxb-staging-reminder/css/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
LXB_Staging_Reminder
Data Attributes
title='You are on staging.'
FAQ

Frequently Asked Questions about LXB Staging Reminder