Wizhi banner images Security & Risk Analysis

wordpress.org/plugins/wizhi-banner-image

Display diffrent banner images in page and taxonomy terms,为每个页面或分类显示一个banner图片。

10 active installs v1.2 PHP + WP 3.4+ Updated Unknown
menuswidget
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Wizhi banner images Safe to Use in 2026?

Generally Safe

Score 100/100

Wizhi banner images has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

Based on the provided static analysis and vulnerability history, the wizhi-banner-image plugin version 1.2 exhibits a strong security posture. The code analysis reveals no identified dangerous functions, SQL queries are exclusively handled with prepared statements, and all output is properly escaped, indicating good coding practices for data sanitization and protection. Furthermore, the absence of file operations, external HTTP requests, and issues in taint analysis suggests that common attack vectors related to these areas are not present.

The vulnerability history further supports this positive assessment, with no recorded CVEs. This lack of past vulnerabilities, especially critical or high-severity ones, is a strong indicator that the plugin has either been consistently developed with security in mind or has not been a target for attackers. The complete absence of any entry points, including AJAX handlers, REST API routes, shortcodes, and cron events, means there are no exposed functionalities that could be directly exploited by external requests.

Overall, wizhi-banner-image v1.2 appears to be a very secure plugin. Its strengths lie in its lack of exploitable entry points and its adherence to secure coding principles for data handling. The primary weakness, if any can be inferred, is the complete absence of any checks for nonces or capabilities. While there are no exposed functionalities currently, if any were to be introduced in future versions without these checks, it could create a significant security risk. However, based solely on the current data, the risk is minimal.

Key Concerns

  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Wizhi banner images Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Wizhi banner images Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Wizhi banner images Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionplugins_loadedbanner-images.php:19
filterpiklist_add_partbanner-images.php:28
Maintenance & Trust

Wizhi banner images Maintenance & Trust

Maintenance Signals

WordPress version tested4.4.34
Last updatedUnknown
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Wizhi banner images Developer Profile

Amos Lee(一刀)

8 plugins · 5K total installs

88
trust score
Avg Security Score
91/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Wizhi banner images

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Wizhi banner images