
MHR-Banner [Show banner/advertisement on page footer] Security & Risk Analysis
wordpress.org/plugins/mhr-bannerFloating footer banner
Is MHR-Banner [Show banner/advertisement on page footer] Safe to Use in 2026?
Generally Safe
Score 85/100MHR-Banner [Show banner/advertisement on page footer] has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'mhr-banner' plugin v2.0 exhibits a seemingly strong security posture at first glance, with no reported vulnerabilities, CVEs, or obvious attack surface points like unprotected AJAX handlers, REST API routes, or shortcodes. The use of prepared statements for all SQL queries is a positive indicator of good practice in handling database interactions, mitigating risks of SQL injection.
However, a significant concern arises from the static analysis regarding output escaping. With 100% of outputs not being properly escaped, there is a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data that is displayed on the frontend without proper sanitization could be exploited. Additionally, the taint analysis reveals two flows with unsanitized paths, which, while not rated as critical or high, still indicate potential areas where data could be mishandled, possibly leading to unexpected behavior or further vulnerabilities if combined with other weaknesses.
The lack of reported vulnerabilities historically suggests either a well-developed plugin or, possibly, limited exposure or testing. While the absence of past issues is encouraging, it doesn't negate the present risks identified in the code. The plugin's strengths lie in its minimal attack surface and secure SQL handling, but the critical weakness in output escaping demands immediate attention to prevent XSS attacks.
Key Concerns
- Outputs not properly escaped
- Flows with unsanitized paths
MHR-Banner [Show banner/advertisement on page footer] Security Vulnerabilities
MHR-Banner [Show banner/advertisement on page footer] Code Analysis
Output Escaping
Data Flow Analysis
MHR-Banner [Show banner/advertisement on page footer] Attack Surface
WordPress Hooks 3
Maintenance & Trust
MHR-Banner [Show banner/advertisement on page footer] Maintenance & Trust
Maintenance Signals
Community Trust
MHR-Banner [Show banner/advertisement on page footer] Alternatives
VK All in One Expansion Unit
vk-all-in-one-expansion-unit
This plug-in is an integrated plug-in with a variety of features that make it powerful your web site.
Sitemap by BestWebSoft – WordPress XML Site Map Page Generator Plugin
google-sitemap-plugin
Generate and add XML sitemap to WordPress website. Help search engines index your blog.
Saitama Addon Pack
cc-addon-pack
This plug-in is an integrated plug-in with a variety of features that make it powerful your web site.
Insights
insights
Insights allows you to quickly access and insert information (links, images, videos, maps..) into your blog posts.
Keyword Statistics
keyword-statistics
This SEO plugin checks the content of posts/pages for the keyword density (single/phrases) while writing and is automatically setting the META-tags.
MHR-Banner [Show banner/advertisement on page footer] Developer Profile
1 plugin · 10 total installs
How We Detect MHR-Banner [Show banner/advertisement on page footer]
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mhr-banner/anim.js/wp-content/plugins/mhr-banner/close.png/wp-content/plugins/mhr-banner/anim.jsHTML / DOM Fingerprints
bannerimgmyclickbtn<!-- MHR Banner (http://www.mahadirlab.com/en/mhr-banner/)-->id="toppopin"id="backlink"id="closebtn"onClick=window.open("window.open(