WP Branding Security & Risk Analysis

wordpress.org/plugins/wp-branding

Just a simple branding plugin

80 active installs v1.0 PHP + WP 3.5+ Updated Apr 1, 2013
brandbrandingcustom-logincustom-logologin
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Branding Safe to Use in 2026?

Generally Safe

Score 85/100

WP Branding has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 13yr ago
Risk Assessment

The wp-branding v1.0 plugin exhibits a generally good security posture based on the static analysis. It demonstrates a lack of dangerous functions, no raw SQL queries, and no file operations or external HTTP requests, which are common sources of vulnerabilities. The presence of a capability check is also a positive sign. However, a significant concern is the complete lack of output escaping for all identified output points. This means that any data rendered to the user interface, if it originates from an untrusted source or is manipulated by an attacker, could potentially lead to cross-site scripting (XSS) vulnerabilities. The absence of any recorded vulnerabilities in its history is a positive indicator, suggesting a history of secure development or a lack of prior significant issues.

Key Concerns

  • 0% output escaping
Vulnerabilities
None known

WP Branding Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP Branding Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped7 total outputs
Attack Surface

WP Branding Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionadmin_menubranding.php:65
filterplugin_action_linksbranding.php:93
actionadmin_print_scriptsbranding.php:114
actionadmin_print_stylesbranding.php:115
filteradmin_footer_textbranding.php:131
filterupdate_footerbranding.php:143
actionadmin_initbranding.php:154
actionlogin_headbranding.php:165
actionwp_dashboard_setupbranding.php:182
Maintenance & Trust

WP Branding Maintenance & Trust

Maintenance Signals

WordPress version tested3.5.2
Last updatedApr 1, 2013
PHP min version
Downloads6K

Community Trust

Rating100/100
Number of ratings3
Active installs80
Developer Profile

WP Branding Developer Profile

elsteno

3 plugins · 100 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP Branding

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-branding/mobisoft-upload.js
Script Paths
/wp-content/plugins/wp-branding/mobisoft-upload.js

HTML / DOM Fingerprints

HTML Comments
<!-- This file is part of wp-braning plugin. wp-branding plugin is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version. wp-branding plugin is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details. You should have received a copy of the GNU General Public License along with underConstruction. If not, see <http://www.gnu.org/licenses/>. --><!-- 1. Replace footer text --><!-- 2. Replace footer wordpress version tag --><!-- 3. Remove 'Upgrade Now' message for non-admin users -->+2 more
Data Attributes
id="footer-thankyou"
Shortcode Output
Hello World, I'm a great Dashboard Widget
FAQ

Frequently Asked Questions about WP Branding