Paris Attacks Ribbon MC Security & Risk Analysis

wordpress.org/plugins/paris-attacks-mc

Show support to Parisian and French people with a selected ribbon in your website corner. Configure the display via the Settings panel.

10 active installs v1.00a PHP + WP 3.0.1+ Updated Unknown
13-november-2015mourningparisparisattacksribbon
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Paris Attacks Ribbon MC Safe to Use in 2026?

Generally Safe

Score 100/100

Paris Attacks Ribbon MC has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The plugin 'paris-attacks-mc' v1.00a exhibits a concerning security posture due to a complete lack of output escaping. While the static analysis shows no apparent SQL injection vulnerabilities, dangerous functions, file operations, or external requests, the fact that 100% of its outputs are unescaped is a significant risk. This indicates a high likelihood of Cross-Site Scripting (XSS) vulnerabilities, allowing malicious actors to inject arbitrary JavaScript code into the site, which could lead to session hijacking, defacement, or further compromise. The taint analysis, although limited, did reveal one flow with an unsanitized path, which, when combined with the unescaped outputs, amplifies the XSS risk.

The vulnerability history of this plugin is clean, with no recorded CVEs. This could suggest a well-developed plugin, or it could simply mean that the plugin has not been thoroughly audited for common web vulnerabilities, particularly XSS, given the static analysis findings. The absence of readily apparent vulnerabilities in the history should not overshadow the critical security flaw identified in the code analysis. The plugin's strength lies in its apparent lack of direct access to sensitive operations like SQL queries or file manipulation, and its small attack surface. However, the critical issue of unescaped output presents a substantial risk that needs immediate attention.

Key Concerns

  • All outputs are unescaped (XSS risk)
  • Taint flow with unsanitized path
  • No capability checks
  • No nonce checks
Vulnerabilities
None known

Paris Attacks Ribbon MC Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Paris Attacks Ribbon MC Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped6 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<admin_settings> (admin_settings.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Paris Attacks Ribbon MC Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionplugins_loadedmc-paris-attacks.php:46
actionwp_footermc-paris-attacks.php:172
actionadmin_menumc-paris-attacks.php:189
Maintenance & Trust

Paris Attacks Ribbon MC Maintenance & Trust

Maintenance Signals

WordPress version tested4.3.34
Last updatedUnknown
PHP min version
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Paris Attacks Ribbon MC Developer Profile

Laurent ROCHE - Mistral Consulting

2 plugins · 20 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Paris Attacks Ribbon MC

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/paris-attacks-mc/mc-blackL.png/wp-content/plugins/paris-attacks-mc/mc-blackR.png/wp-content/plugins/paris-attacks-mc/mc-marianneL.png/wp-content/plugins/paris-attacks-mc/mc-marianneR.png/wp-content/plugins/paris-attacks-mc/mc-eiffelL.png/wp-content/plugins/paris-attacks-mc/mc-eiffelR.png/wp-content/plugins/paris-attacks-mc/mc-cryingeyeL.png/wp-content/plugins/paris-attacks-mc/mc-cryingeyeR.png+2 more

HTML / DOM Fingerprints

CSS Classes
MCpaRibbon
FAQ

Frequently Asked Questions about Paris Attacks Ribbon MC