Orbisius Simple Notice Security & Risk Analysis

wordpress.org/plugins/orbisius-simple-notice

This plugin allows you to show a simple notice to alert your users about server maintenance, new product launches etc.

100 active installs v1.1.4 PHP 5.6+ WP 3.6+ Updated Dec 11, 2024
alerthellobarnoticeorbisiuswp
91
A · Safe
CVEs total1
Unpatched0
Last CVEJan 24, 2025
Safety Verdict

Is Orbisius Simple Notice Safe to Use in 2026?

Generally Safe

Score 91/100

Orbisius Simple Notice has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jan 24, 2025Updated 1yr ago
Risk Assessment

The static analysis of orbisius-simple-notice v1.1.4 reveals a generally positive security posture, with no identified AJAX handlers, REST API routes, shortcodes, or cron events, resulting in a zero-point attack surface. Furthermore, no dangerous functions or critical taint flows were detected. However, a significant concern arises from the presence of an SQL query that does not utilize prepared statements, posing a potential risk of SQL injection if the input is not strictly validated and sanitized elsewhere. While the majority of output is properly escaped, the remaining percentage still represents a potential vector for cross-site scripting vulnerabilities.

The plugin's vulnerability history indicates a past medium-severity Cross-site Scripting (XSS) vulnerability. The fact that this vulnerability is listed as "currently unpatched" despite the "last vulnerability" date being in the future is a discrepancy that warrants further investigation or clarification. If the CVE is indeed unpatched, it represents a significant risk. The pattern of past XSS vulnerabilities suggests a recurring theme in how user-provided data is handled, even with a majority of outputs being escaped.

In conclusion, while the plugin has a commendable lack of direct attack surface and a good record of proper output escaping for most cases, the unescaped SQL query and the history of XSS vulnerabilities are areas of concern. Addressing the SQL query and ensuring robust sanitization for all user inputs, particularly in light of past XSS issues, would significantly improve the plugin's security.

Key Concerns

  • SQL query without prepared statement
  • Non-trivial percentage of unescaped output
  • Medium severity CVE in vulnerability history
Vulnerabilities
1

Orbisius Simple Notice Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-24634medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Orbisius Simple Notice <= 1.1.3 - Authenticated (Administrator+) Stored Cross-Site Scripting

Jan 24, 2025 Patched in 1.1.4 (5d)
Code Analysis
Analyzed Mar 16, 2026

Orbisius Simple Notice Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
10
24 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

71% escaped34 total outputs
Attack Surface

Orbisius Simple Notice Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actioninitorbisius-simple-notice.php:29
actionwp_footerorbisius-simple-notice.php:30
actionadmin_initorbisius-simple-notice.php:31
actionadmin_menuorbisius-simple-notice.php:32
filterplugin_action_linksorbisius-simple-notice.php:309
Maintenance & Trust

Orbisius Simple Notice Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedDec 11, 2024
PHP min version5.6
Downloads9K

Community Trust

Rating100/100
Number of ratings3
Active installs100
Developer Profile

Orbisius Simple Notice Developer Profile

Svetoslav Marinov

26 plugins · 12K total installs

71
trust score
Avg Security Score
88/100
Avg Patch Time
722 days
View full developer profile
Detection Fingerprints

How We Detect Orbisius Simple Notice

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/orbisius-simple-notice/assets/jquery.cookie.min.js/wp-content/plugins/orbisius-simple-notice/assets/jquery.cookie.js/wp-content/plugins/orbisius-simple-notice/assets/admin_main.js
Script Paths
/wp-content/plugins/orbisius-simple-notice/assets/jquery.cookie.min.js/wp-content/plugins/orbisius-simple-notice/assets/jquery.cookie.js/wp-content/plugins/orbisius-simple-notice/assets/admin_main.js
Version Parameters
orbisius-simple-notice/assets/jquery.cookie.min.js?ver=orbisius-simple-notice/assets/jquery.cookie.js?ver=orbisius-simple-notice/assets/admin_main.js?ver=

HTML / DOM Fingerprints

CSS Classes
orbisius_simple_notice_dismiss_containerdismiss_messageorbisius_simple_notice_powered_by_containerorbisius_simple_notice_powered_bylittle_info
HTML Comments
<!-- Orbisius Simple Notice | https://orbisius.com/products/wordpress-plugins/orbisius-simple-notice/ : is disabled or it's an ajax call. Skipping rendering. -->
Data Attributes
data-msg_id
JS Globals
orb_simp_ntc_dismiss_hash
FAQ

Frequently Asked Questions about Orbisius Simple Notice