
WP Promoter Security & Risk Analysis
wordpress.org/plugins/wp-promoterPromote your Offers , Notify your users with eye catchy Promotional methods of wp-promoter. Manage your promotion effectively and by analysing from st …
Is WP Promoter Safe to Use in 2026?
Generally Safe
Score 85/100WP Promoter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the provided static analysis and vulnerability history, the "wp-promoter" v1.3 plugin exhibits a mixed security posture. The absence of any recorded CVEs, coupled with the lack of any identified dangerous functions, file operations, or external HTTP requests, suggests a generally well-behaved codebase concerning common vulnerability vectors. The plugin also demonstrates good practice by exclusively using prepared statements for its SQL queries.
However, a significant concern arises from the complete lack of output escaping. With 29 total outputs analyzed and 0% properly escaped, this represents a critical weakness. This could lead to Cross-Site Scripting (XSS) vulnerabilities, where malicious code could be injected into the user interface. Furthermore, the absence of nonce checks and capability checks, while not directly flagged as an issue due to the lack of entry points, means that if any entry points were to be introduced or discovered in future versions, they would be inherently unprotected. The zero taint flows and zero attack surface entries are positive but offer little reassurance given the output escaping issue.
In conclusion, while "wp-promoter" v1.3 avoids many common pitfalls and has a clean vulnerability history, the universal failure to escape output creates a substantial risk of XSS. This weakness overshadows the otherwise clean code analysis and necessitates immediate attention. The lack of built-in protection for potential entry points is also a latent concern.
Key Concerns
- No output escaping
WP Promoter Security Vulnerabilities
WP Promoter Code Analysis
Output Escaping
WP Promoter Attack Surface
WordPress Hooks 3
Maintenance & Trust
WP Promoter Maintenance & Trust
Maintenance Signals
Community Trust
WP Promoter Alternatives
Free Shipping Bar for WooCommerce – Progress Indicator, Popup & Alerts
free-shipping-notification-woocommerce
Free shipping bar will show a notification bar/popup on your website with a free shipping progress bar that will inform users how much they should buy …
Header Bar
responsive-welcome-bar
Header Bar to promote special offers, ebook download, free gifts. Responsive and fully customizable hello bar. 20+ onsite marketing tools included
Easy Announcement Bar
easy-announcement-bar
Easy Announcement Bar plugin adds a customizable, scrolling announcement bar to your WordPress site.
Holiday Notifications
holiday-notifications
The Holiday Notifications plugin allows you to easily set announcements for your website to let your customers know of upcoming holidays, events, and …
WP Social Proof
wp-social-proof
Get Social Proof for your WordPress website! Show recent purchases, latest products and user registrations, integrated with WooCommerce.
WP Promoter Developer Profile
5 plugins · 30 total installs
How We Detect WP Promoter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-promoter/minicolor/jquery.miniColors.css/wp-content/plugins/wp-promoter/minicolor/jquery.miniColors.min.js/wp-content/plugins/wp-promoter/css/custom.css/wp-content/plugins/wp-promoter/minicolor/jquery.miniColors.min.jsHTML / DOM Fingerprints
wp-promoter-popupwpp-promo-barwpp-linkwpp-closewpp-popupwpp_promoter<div class="wpp-promo-bar" id="wpp-wp_promoter"><span class="wpp-close" id="close_wp_promoter">X</span><div id="wpp-popup">