Owner/Brand Info Widget Security & Risk Analysis

wordpress.org/plugins/owner-info-widget

This plugin enables the ability to display website brand/owner information on a widget.

0 active installs v1.0 PHP 5.2.4+ WP 4.1+ Updated Unknown
brand-infobrand-info-widgetbrand-information-widgetwidgetwordpress-widget
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Owner/Brand Info Widget Safe to Use in 2026?

Generally Safe

Score 100/100

Owner/Brand Info Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "owner-info-widget" v1.0 plugin exhibits a generally good security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits its attack surface. Furthermore, the code signals indicate no dangerous functions, no raw SQL queries (all use prepared statements), no file operations, and no external HTTP requests. This suggests a well-contained plugin with minimal external interactions and secure database handling.

However, a significant concern arises from the output escaping. With 72 total outputs and only 31% properly escaped, a substantial portion of the plugin's output could be vulnerable to Cross-Site Scripting (XSS) attacks. The lack of nonce checks and capability checks on its (non-existent) entry points, while not immediately exploitable due to the zero attack surface, would be a major concern if any entry points were introduced or discovered later. The plugin's vulnerability history is clean, with no recorded CVEs, which is positive, but this is often due to a lack of dedicated security research on less complex plugins or limited attack surface.

In conclusion, while the plugin has strong points in its limited attack surface and secure database operations, the poor output escaping presents a tangible risk of XSS vulnerabilities. The absence of known historical vulnerabilities is a good sign, but the static analysis highlights a critical area for improvement to ensure robust security.

Key Concerns

  • Insufficient output escaping
Vulnerabilities
None known

Owner/Brand Info Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Owner/Brand Info Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
50
22 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

31% escaped72 total outputs
Attack Surface

Owner/Brand Info Widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionwp_footerindex.php:192
actionwidgets_initindex.php:268
actionadmin_initindex.php:269
actionwp_enqueue_scriptsindex.php:270
Maintenance & Trust

Owner/Brand Info Widget Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedUnknown
PHP min version5.2.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Owner/Brand Info Widget Developer Profile

Pradip Debnath

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Owner/Brand Info Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
owner-photo-upload-buttonowner-photogoogle-partnersocial-linksfbtwitterlinkedingplus+2 more
Data Attributes
data-target="#hireMeModal"data-toggle="modal"
FAQ

Frequently Asked Questions about Owner/Brand Info Widget