
WP Announce Security & Risk Analysis
wordpress.org/plugins/wp-announceClean announcement plugin that reveals a neat popup when users visit your site. You can set who sees the announcement and when to display it.
Is WP Announce Safe to Use in 2026?
Generally Safe
Score 85/100WP Announce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-announce v3.0.0 plugin exhibits a generally good security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and a clean vulnerability history suggest a well-maintained and secure codebase. Furthermore, the limited attack surface, with zero AJAX handlers, REST API routes, shortcodes, and cron events, significantly reduces the potential for external exploitation. The presence of nonce checks and capability checks, along with the exclusive use of prepared statements for its single SQL query, are positive indicators of secure coding practices.
However, the static analysis reveals a significant concern regarding output escaping. A high percentage (83%) of the plugin's 58 output points are not properly escaped. This could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is displayed without adequate sanitization, allowing attackers to inject malicious scripts into the website. Additionally, two of the three analyzed taint flows have unsanitized paths, indicating potential risks of data being processed without proper validation, though no critical or high severity issues were identified in this area. The single file operation without further context also warrants attention.
In conclusion, while the plugin benefits from a low attack surface and a strong track record of security, the prevalent output escaping deficiencies and the identified unsanitized taint flows present notable risks. Addressing these specific coding issues would further strengthen the plugin's security. The plugin's strengths lie in its minimal entry points and robust historical security, while its primary weakness lies in the handling of output data.
Key Concerns
- Low percentage of properly escaped outputs
- Unsanitized paths in taint flows
WP Announce Security Vulnerabilities
WP Announce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Announce Attack Surface
WordPress Hooks 14
Maintenance & Trust
WP Announce Maintenance & Trust
Maintenance Signals
Community Trust
WP Announce Alternatives
ITRO Popup Plugin
itro-popup
Display a popup to your WordPress site: age verification popup for adult-content site ★ multilanguage popup with qTransalte-X ★ very easy to use
Magic Popups
magic-popups
The most complete popup plugin. Create Magic Popups with multiple selections & styles to show up on the front end.
Popups – Submission Messages For Contact Form 7
cf7-popups
Display contact form 7 default messages in stylish popup as user submits the form.
Popup Message Notifier for Contact Form 7
popup-notifier-for-contact-form-7
This plugin will show confirmation and error messages of CF7 inside a popup made with sweetalert2.
Popup Like box – Page Plugin
ays-facebook-popup-likebox
With the help of this amazing plugin you can promote your Facebook page and add number of Likes , which is very important today.
WP Announce Developer Profile
2 plugins · 20 total installs
How We Detect WP Announce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-announce/src/css/style.css/wp-content/plugins/wp-announce/src/js/wp-announce.js/wp-content/plugins/wp-announce/src/js/colorbox/jquery.colorbox-min.js/wp-content/plugins/wp-announce/src/js/colorbox/colorbox.css/wp-content/plugins/wp-announce/src/js/wp-announce.js/wp-content/plugins/wp-announce/src/js/colorbox/jquery.colorbox-min.jswp-announce/src/css/style.css?ver=wp-announce/src/js/wp-announce.js?ver=HTML / DOM Fingerprints
wpa-announcement-bodywpa-announcement-headerdata-widthdata-heightdata-delaydata-frequencydata-accessdata-style-header+1 morewpa_announcement_options