Show Support Ribbon Security & Risk Analysis

wordpress.org/plugins/show-support-ribbon

Displays a customizable "show support" ribbon, banner, or badge on your site.

300 active installs v20260130 PHP 5.6.20+ WP 4.7+ Updated Jan 30, 2026
badgebannerbuttonribbonsupport
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Show Support Ribbon Safe to Use in 2026?

Generally Safe

Score 100/100

Show Support Ribbon has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The 'show-support-ribbon' plugin, version 20260130, exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, file operations, external HTTP requests, and raw SQL queries is commendable. The use of prepared statements for all SQL queries is a significant security strength. Furthermore, the plugin demonstrates good practice by including capability checks. The limited attack surface, with only one shortcode and no unprotected entry points, further reduces its potential for exploitation.

However, a key area of concern is the output escaping, where only 49% of outputs are properly escaped. This indicates a potential for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data or dynamic content is not adequately sanitized before being displayed to the user. The lack of nonce checks, though not directly tied to an attack vector in this analysis, is a standard security measure that is missing. The plugin's vulnerability history is clean, with no recorded CVEs, suggesting a proactive approach to security by its developers or a lack of past significant issues.

In conclusion, while the plugin has several robust security features and a clean vulnerability history, the low percentage of properly escaped output presents a notable risk. Addressing the output escaping issues should be a priority to enhance the plugin's overall security.

Key Concerns

  • Low percentage of properly escaped output
  • Missing nonce checks
Vulnerabilities
None known

Show Support Ribbon Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Show Support Ribbon Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
20
19 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

49% escaped39 total outputs
Attack Surface

Show Support Ribbon Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[show_support_ribbon] show-support-ribbon.php:222
WordPress Hooks 9
actioninitshow-support-ribbon.php:49
actionadmin_initshow-support-ribbon.php:65
filteradmin_footer_textshow-support-ribbon.php:86
actionwp_headshow-support-ribbon.php:170
actionwp_footershow-support-ribbon.php:217
filterplugin_action_linksshow-support-ribbon.php:236
filterplugin_row_metashow-support-ribbon.php:257
actionadmin_initshow-support-ribbon.php:324
actionadmin_menushow-support-ribbon.php:361
Maintenance & Trust

Show Support Ribbon Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 30, 2026
PHP min version5.6.20
Downloads25K

Community Trust

Rating100/100
Number of ratings12
Active installs300
Developer Profile

Show Support Ribbon Developer Profile

Jeff Starr

30 plugins · 1.2M total installs

78
trust score
Avg Security Score
98/100
Avg Patch Time
345 days
View full developer profile
Detection Fingerprints

How We Detect Show Support Ribbon

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
show-support-ribbon
Data Attributes
id="show-support-ribbon"
FAQ

Frequently Asked Questions about Show Support Ribbon