Sliding Banner – News and Offers Security & Risk Analysis

wordpress.org/plugins/sliding-banner

Diferentes Banners con Slider

0 active installs v1.0 PHP 5.6+ WP 3.0+ Updated Jun 5, 2018
bannernoticesofferssliderwoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Sliding Banner – News and Offers Safe to Use in 2026?

Generally Safe

Score 85/100

Sliding Banner – News and Offers has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The sliding-banner v1.0 plugin exhibits a generally positive security posture based on the provided static analysis. The absence of entry points like AJAX handlers, REST API routes, shortcodes, and cron events significantly reduces its attack surface. Furthermore, the code's adherence to secure coding practices, such as using prepared statements for all SQL queries and the presence of nonce and capability checks, is commendable.

However, a notable concern arises from the output escaping. With 38% of outputs properly escaped, there's a significant risk of Cross-Site Scripting (XSS) vulnerabilities, particularly if user-supplied data is not adequately sanitized before being displayed. While the taint analysis shows no identified flows, this is based on the current analysis scope and doesn't negate the potential risk posed by unsanitized output. The plugin's clean vulnerability history is a strong positive indicator, suggesting a history of responsible development and maintenance.

In conclusion, the sliding-banner v1.0 plugin demonstrates strong foundations in secure coding practices, particularly concerning data handling and authentication mechanisms. The primary weakness lies in the incomplete output escaping, which could lead to XSS vulnerabilities. Addressing this specific area should be the immediate priority to further enhance its security.

Key Concerns

  • Insufficient output escaping (38% proper)
Vulnerabilities
None known

Sliding Banner – News and Offers Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Sliding Banner – News and Offers Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
3 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

38% escaped8 total outputs
Attack Surface

Sliding Banner – News and Offers Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionadmin_noticessliding-banner.php:31
actionplugins_loadedisliding-banner.php:42
actionwp_enqueue_scriptssliding-banner.php:51
actionwp_enqueue_scriptssliding-banner.php:57
actioninitsliding-banner.php:59
actiondo_meta_boxessliding-banner.php:97
actionadd_meta_boxessliding-banner.php:110
actionsave_postsliding-banner.php:171
actionwp_footersliding-banner.php:232
actionadmin_initsliding-banner.php:235
actionadmin_menusliding-banner.php:244
Maintenance & Trust

Sliding Banner – News and Offers Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedJun 5, 2018
PHP min version5.6
Downloads993

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Sliding Banner – News and Offers Developer Profile

José Sabater

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Sliding Banner – News and Offers

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sliding-banner/assets/js/sb-script.js/wp-content/plugins/sliding-banner/assets/css/sb-style.css
Script Paths
assets/js/sb-script.js
Version Parameters
sb-scriptsb-style

HTML / DOM Fingerprints

CSS Classes
sliding-bannermarqueebanner_info
Data Attributes
data-duration
Shortcode Output
<div class="sliding-banner"<div class="marquee banner_info
FAQ

Frequently Asked Questions about Sliding Banner – News and Offers