Simple Banner – Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website Security & Risk Analysis

wordpress.org/plugins/simple-banner

Display a simple banner/bar at the top or bottom of your website. Now with multi-banner support.

50K active installs v3.2.1 PHP + WP 3.0.1+ Updated Jan 20, 2026
announcementbannerbarnoticenotification
95
A · Safe
CVEs total6
Unpatched0
Last CVEOct 21, 2025
Safety Verdict

Is Simple Banner – Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website Safe to Use in 2026?

Generally Safe

Score 95/100

Simple Banner – Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website has a strong security track record. Known vulnerabilities have been patched promptly.

6 known CVEsLast CVE: Oct 21, 2025Updated 2mo ago
Risk Assessment

The 'simple-banner' plugin version 3.2.1 presents a mixed security posture. On the positive side, the static analysis indicates a clean attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events that lack authentication or permission checks. Furthermore, all SQL queries are correctly prepared, and there are no file operations or bundled libraries to worry about. However, a significant concern arises from the output escaping, with only 30% of outputs being properly escaped, suggesting a potential for Cross-Site Scripting (XSS) vulnerabilities. While taint analysis shows no critical or high severity flows, this could be a limitation of the analysis method rather than a true absence of risk, especially given the poor output escaping.

The plugin's vulnerability history is a major red flag. With a total of 6 known CVEs, all of which are currently patched, and a history dominated by medium severity XSS vulnerabilities, this indicates a recurring pattern of insecure coding practices. The fact that the last vulnerability was as recent as October 2025 (assuming the year is a typo and should be in the past, e.g., 2023 or 2024) further emphasizes that the developers have a track record of introducing security flaws. While no current unpatched vulnerabilities exist, the historical data strongly suggests a high likelihood of future issues if the underlying coding habits do not improve.

In conclusion, while the 'simple-banner' plugin has a well-defined and seemingly controlled attack surface and uses prepared statements for its SQL queries, the extremely poor output escaping and the extensive history of XSS vulnerabilities are significant weaknesses. The lack of proper output escaping provides a clear pathway for attackers to inject malicious scripts, and the past vulnerabilities suggest a persistent insecurity in how the plugin handles user-supplied data. Users should exercise caution and consider alternative plugins with a stronger security track record.

Key Concerns

  • Poor output escaping (30% properly escaped)
  • Significant historical vulnerability count (6 CVEs)
  • Vulnerability history dominated by medium severity XSS
Vulnerabilities
6

Simple Banner – Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website Security Vulnerabilities

CVEs by Year

1 CVE in 2021
2021
2 CVEs in 2022
2022
3 CVEs in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
6

6 total CVEs

CVE-2025-12033medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Simple Banner <= 3.0.10 - Authenticated (Admin+) Stored Cross-Site Scripting

Oct 21, 2025 Patched in 3.1.0 (1d)
CVE-2024-13898medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Simple Banner <= 3.0.4 - Authenticated (Administrator+) Stored Cross-Site Scripting

Apr 3, 2025 Patched in 3.0.5 (1d)
CVE-2024-12769medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Simple Banner <= 3.0.3 - Authenticated (Administrator+) Stored Cross-Site Scripting

Mar 3, 2025 Patched in 3.0.4 (47d)
CVE-2022-0446medium · 5.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Simple Banner <= 2.11.0 - Authenticated (Administrator+) Stored Cross-Site Scripting

Jul 26, 2022 Patched in 2.12.0 (546d)
CVE-2022-2515medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Simple Banner <= 2.11.0 - Authenticated Stored Cross-Site Scripting

Jul 22, 2022 Patched in 2.12.0 (550d)
CVE-2021-24574medium · 5.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Simple Banner <= 2.10.3 - Authenticated (Admin+) Stored Cross-Site Scripting

Jul 26, 2021 Patched in 2.10.4 (911d)
Code Analysis
Analyzed Mar 16, 2026

Simple Banner – Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
128
54 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

30% escaped182 total outputs
Attack Surface

Simple Banner – Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionadmin_menusimple-banner.php:27
actionwp_enqueue_scriptssimple-banner.php:82
actionwp_body_opensimple-banner.php:154
actionwp_footersimple-banner.php:176
actionwp_headsimple-banner.php:182
actionadmin_menusimple-banner.php:281
actionadmin_initsimple-banner.php:328
filtertiny_mce_before_initsimple-banner.php:607
actionadd_option_simple_banner_clear_cachesimple-banner.php:1009
actionupdate_option_simple_banner_clear_cachesimple-banner.php:1010
Maintenance & Trust

Simple Banner – Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.0
Last updatedJan 20, 2026
PHP min version
Downloads1.9M

Community Trust

Rating96/100
Number of ratings45
Active installs50K
Developer Profile

Simple Banner – Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website Developer Profile

rpetersen29

1 plugin · 50K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
343 days
View full developer profile
Detection Fingerprints

How We Detect Simple Banner – Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/simple-banner/simple-banner.css
Script Paths
/wp-content/plugins/simple-banner/simple-banner.js
Version Parameters
simple-banner/style.css?ver=simple-banner.js?ver=

HTML / DOM Fingerprints

CSS Classes
simple-bannersimple-banner-buttonsimple-banner-text
Data Attributes
simpleBannerScriptParams
JS Globals
simpleBannerScriptParams
FAQ

Frequently Asked Questions about Simple Banner – Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website