PR Splash Security & Risk Analysis

wordpress.org/plugins/pr-splash

Plugin para exibição de mensagens ou imagens em forma de splash.

30 active installs v1.0.4 PHP + WP 3.3.1+ Updated Apr 12, 2014
modalpop-uppopupsplash
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is PR Splash Safe to Use in 2026?

Generally Safe

Score 85/100

PR Splash has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

Based on the static analysis, the pr-splash plugin v1.0.4 exhibits a seemingly robust security posture with no identified dangerous functions, file operations, external requests, or SQL injection vulnerabilities. The absence of any recorded CVEs further contributes to this positive initial impression. However, a critical concern arises from the complete lack of output escaping, meaning that any data processed and displayed by the plugin is vulnerable to cross-site scripting (XSS) attacks. This oversight significantly undermines the otherwise clean code signals. The plugin also has no capability checks or nonce checks, which, while not directly identified as an immediate vulnerability in this specific analysis (due to the lack of entry points), leaves it exposed should any new entry points be introduced without proper authorization. The lack of any historical vulnerabilities is a positive indicator, but the critical flaw in output escaping presents a clear and present danger that must be addressed.

Key Concerns

  • All outputs are unescaped
  • No capability checks
  • No nonce checks
Vulnerabilities
None known

PR Splash Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

PR Splash Release Timeline

v1.0.4Current
v1.0.3
v1.0.2
v1.0.1
v1.0
Code Analysis
Analyzed Mar 16, 2026

PR Splash Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped4 total outputs
Attack Surface

PR Splash Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_initpr-admin-functions.php:2
filtermce_buttons_3pr-admin-functions.php:4
actioninitpr-admin-functions.php:5
actionwp_footerpr-front-functions.php:94
actionadmin_menupr-splash.php:21
Maintenance & Trust

PR Splash Maintenance & Trust

Maintenance Signals

WordPress version tested3.7.41
Last updatedApr 12, 2014
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings2
Active installs30
Developer Profile

PR Splash Developer Profile

Paulo Iankoski

3 plugins · 50 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect PR Splash

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/pr-splash/pr-splash.php

HTML / DOM Fingerprints

CSS Classes
prSplash_overlayprSplashhide_prSplashprSplash_imageprSplash_content
Data Attributes
id="prSplash"class="hide_prSplash"class="prSplash_image"class="prSplash_content"
JS Globals
prSplashprSplash_imagewindow_heightprSplash_heightprSplash_width
FAQ

Frequently Asked Questions about PR Splash