
Wbcom Designs – WB Ad Manager Security & Risk Analysis
wordpress.org/plugins/wb-ads-rotator-with-split-testComprehensive ad management for WordPress with ad rotation, split testing, multiple placements, Google AdSense, BuddyPress, and bbPress integration.
Is Wbcom Designs – WB Ad Manager Safe to Use in 2026?
Generally Safe
Score 100/100Wbcom Designs – WB Ad Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wb-ads-rotator-with-split-test" v2.6.0 plugin exhibits a generally good security posture, with a strong emphasis on security best practices like nonce and capability checks. The static analysis reveals a comprehensive approach to input sanitization and output escaping, with a very high percentage of outputs being properly escaped and a significant portion of SQL queries utilizing prepared statements. The absence of known CVEs and a history free of recorded vulnerabilities further reinforce this positive impression.
However, the taint analysis highlights a significant area of concern. A large number of identified flows (9 out of 11) show unsanitized paths, with 9 of these being categorized as high severity. This suggests that while the plugin might be escaping output effectively, there are potential vulnerabilities in how user-supplied data is processed internally before reaching sensitive operations or being used in SQL queries. The presence of external HTTP requests, while not inherently a vulnerability, could be a vector if not handled securely. The large number of total SQL queries, even with a high percentage using prepared statements, warrants careful review of the remaining 27% that do not.
In conclusion, the plugin demonstrates strong defensive coding in many areas. The lack of historical vulnerabilities is a positive indicator. Nevertheless, the high number of high-severity unsanitized taint flows is a critical weakness that needs immediate attention. Addressing these specific taint flow issues should be the priority to ensure the plugin's security.
Key Concerns
- High severity unsanitized taint flows
- SQL queries without prepared statements
Wbcom Designs – WB Ad Manager Security Vulnerabilities
Wbcom Designs – WB Ad Manager Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Wbcom Designs – WB Ad Manager Attack Surface
AJAX Handlers 9
Shortcodes 6
WordPress Hooks 99
Maintenance & Trust
Wbcom Designs – WB Ad Manager Maintenance & Trust
Maintenance Signals
Community Trust
Wbcom Designs – WB Ad Manager Alternatives
Ad Inserter – Ad Manager & AdSense Ads
ad-inserter
Manage Google AdSense ads, banners, ad rotation, sticky widgets, AMP ads, ads.txt, tracking, header and footer code, PHP code, global custom fields
AD Publisher – Automatically insert post ads
ad-publisher
Automatically publishing ad code and increasing THE ad UNIT AdSense CTR
Auto Ad Inserter – Increase Google Adsense and Ad Manager Revenue
revenueflex-easy-ads
Auto Ad Inserter is an AI-assisted tool used to get the best revenue from ads placed on your site through Google Adsense and Ads manager.
Remove Yellow BGBOX
remove-yellow-bgbox
Fix the background color that sometimes AdSense ads have on websites/blog’s (Remove Yellow Background/Box From Google Adsense Ads).
Advanced Ads – Ad Manager & AdSense
advanced-ads
The only complete toolkit for all ad types. Grow your revenue with AdSense, Amazon—or any affiliate network. Get pinpoint targeting and best support!
Wbcom Designs – WB Ad Manager Developer Profile
5 plugins · 420 total installs
How We Detect Wbcom Designs – WB Ad Manager
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wb-ads-rotator-with-split-test/assets/css/admin.css/wp-content/plugins/wb-ads-rotator-with-split-test/assets/js/admin.js/wp-content/plugins/wb-ads-rotator-with-split-test/assets/js/admin.jswb-ads-rotator-with-split-test/assets/css/admin.css?ver=wb-ads-rotator-with-split-test/assets/js/admin.js?ver=HTML / DOM Fingerprints
wbam-ad-settingswbam-ad-placementswbam-ad-statusdata-wbam-ad-iddata-wbam-placement-idwbamAdminwbamCodeEditor[wbam_display_ad][wbam_get_ads]