
Push Down Banners Security & Risk Analysis
wordpress.org/plugins/push-down-bannersThe easiest way to create Push Down Banners for your site. Unlimited creativity! 9 Languages!
Is Push Down Banners Safe to Use in 2026?
Generally Safe
Score 85/100Push Down Banners has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The push-down-banners plugin v1.3 exhibits a significant security concern due to its extensive attack surface being entirely unprotected. All 8 identified AJAX handlers lack authentication checks, presenting a direct pathway for unauthorized actions. While the plugin demonstrates strong practices in SQL query handling and output escaping, the absence of nonces and capability checks on its AJAX endpoints is a critical oversight. The taint analysis further highlights this, revealing 6 high-severity flows with unsanitized paths, strongly suggesting potential for injection vulnerabilities or unintended data manipulation when these unprotected AJAX handlers are triggered. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive indicator of past development. However, this lack of history should not overshadow the immediate and substantial risks presented by the current code's lack of essential security controls on its entry points.
Key Concerns
- 8 AJAX handlers without auth checks
- 6 high severity taint flows
- 0 Nonce checks on AJAX handlers
- 0 Capability checks on AJAX handlers
Push Down Banners Security Vulnerabilities
Push Down Banners Release Timeline
Push Down Banners Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Push Down Banners Attack Surface
AJAX Handlers 8
WordPress Hooks 8
Maintenance & Trust
Push Down Banners Maintenance & Trust
Maintenance Signals
Community Trust
Push Down Banners Alternatives
No alternatives data available yet.
Push Down Banners Developer Profile
2 plugins · 20 total installs
How We Detect Push Down Banners
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/push-down-banners/pushdownbanners.js/wp-content/plugins/push-down-banners/swfobject/swfobject.jspush-down-banners/pushdownbanners.js?ver=push-down-banners/swfobject/swfobject.js?ver=HTML / DOM Fingerprints
PushdownAdshowid="PushdownAd2"id="PushdownAd1"id="outer"id="mainimg"adm_urlpanid_gPDBSpeed_gPDBTimecreateCookiereadCookie+4 more