
Orbisius Simple Notice Security & Risk Analysis
wordpress.org/plugins/orbisius-simple-noticeThis plugin allows you to show a simple notice to alert your users about server maintenance, new product launches etc.
Is Orbisius Simple Notice Safe to Use in 2026?
Generally Safe
Score 91/100Orbisius Simple Notice has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of orbisius-simple-notice v1.1.4 reveals a generally positive security posture, with no identified AJAX handlers, REST API routes, shortcodes, or cron events, resulting in a zero-point attack surface. Furthermore, no dangerous functions or critical taint flows were detected. However, a significant concern arises from the presence of an SQL query that does not utilize prepared statements, posing a potential risk of SQL injection if the input is not strictly validated and sanitized elsewhere. While the majority of output is properly escaped, the remaining percentage still represents a potential vector for cross-site scripting vulnerabilities.
The plugin's vulnerability history indicates a past medium-severity Cross-site Scripting (XSS) vulnerability. The fact that this vulnerability is listed as "currently unpatched" despite the "last vulnerability" date being in the future is a discrepancy that warrants further investigation or clarification. If the CVE is indeed unpatched, it represents a significant risk. The pattern of past XSS vulnerabilities suggests a recurring theme in how user-provided data is handled, even with a majority of outputs being escaped.
In conclusion, while the plugin has a commendable lack of direct attack surface and a good record of proper output escaping for most cases, the unescaped SQL query and the history of XSS vulnerabilities are areas of concern. Addressing the SQL query and ensuring robust sanitization for all user inputs, particularly in light of past XSS issues, would significantly improve the plugin's security.
Key Concerns
- SQL query without prepared statement
- Non-trivial percentage of unescaped output
- Medium severity CVE in vulnerability history
Orbisius Simple Notice Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Orbisius Simple Notice <= 1.1.3 - Authenticated (Administrator+) Stored Cross-Site Scripting
Orbisius Simple Notice Code Analysis
SQL Query Safety
Output Escaping
Orbisius Simple Notice Attack Surface
WordPress Hooks 5
Maintenance & Trust
Orbisius Simple Notice Maintenance & Trust
Maintenance Signals
Community Trust
Orbisius Simple Notice Alternatives
Cart Notices for WooCommerce
cart-notices-for-woocommerce
Display on cart page notices based on products and product categories in cart, cart cost, current day and time, customer referrer.
WP Post Disclaimer
wp-post-disclaimer
Add customizable disclaimers, terms, or warnings to the top, bottom, or within post, page, or custom post type content for WordPress
Log Deprecated Notices
log-deprecated-notices
Logs the usage of deprecated files, functions, and function arguments, and identifies where the deprecated functionality is being used.
WPC Smart Messages for WooCommerce
wpc-smart-messages
WPC Smart Messages help you display messages throughout your store through smart conditional logic settings.
Product Notices for WooCommerce
product-notices-for-woocommerce
Make the best of product announcements, promos, discounts, alerts, etc. on your eCommerce site with this one of its kind WooCommerce extension.
Orbisius Simple Notice Developer Profile
26 plugins · 12K total installs
How We Detect Orbisius Simple Notice
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/orbisius-simple-notice/assets/jquery.cookie.min.js/wp-content/plugins/orbisius-simple-notice/assets/jquery.cookie.js/wp-content/plugins/orbisius-simple-notice/assets/admin_main.js/wp-content/plugins/orbisius-simple-notice/assets/jquery.cookie.min.js/wp-content/plugins/orbisius-simple-notice/assets/jquery.cookie.js/wp-content/plugins/orbisius-simple-notice/assets/admin_main.jsorbisius-simple-notice/assets/jquery.cookie.min.js?ver=orbisius-simple-notice/assets/jquery.cookie.js?ver=orbisius-simple-notice/assets/admin_main.js?ver=HTML / DOM Fingerprints
orbisius_simple_notice_dismiss_containerdismiss_messageorbisius_simple_notice_powered_by_containerorbisius_simple_notice_powered_bylittle_info<!-- Orbisius Simple Notice | https://orbisius.com/products/wordpress-plugins/orbisius-simple-notice/ : is disabled or it's an ajax call. Skipping rendering. -->data-msg_idorb_simp_ntc_dismiss_hash