Attention Grabber (Hello Bar Alternative) Security & Risk Analysis

wordpress.org/plugins/attention-grabber-hello-bar-alternative

Grab your visitor's attention and get them to sign up for your email list, or tell them about a specific page they should visit.

30 active installs v1.4 PHP + WP 3.0.1+ Updated Jan 27, 2014
freehello-barhellobarnotification-bartoolbar
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Attention Grabber (Hello Bar Alternative) Safe to Use in 2026?

Generally Safe

Score 85/100

Attention Grabber (Hello Bar Alternative) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The "attention-grabber-hello-bar-alternative" plugin v1.4 exhibits a strong security posture based on the provided static analysis. The absence of any identified entry points like AJAX handlers, REST API routes, shortcodes, or cron events significantly reduces its attack surface. Furthermore, the code analysis reveals no dangerous functions, no direct SQL queries (all use prepared statements), no file operations, and no external HTTP requests. This indicates a well-contained and securely coded plugin.

However, a significant concern arises from the output escaping. With 186 total outputs and only 1% properly escaped, there is a high probability of Cross-Site Scripting (XSS) vulnerabilities. Although no taint flows were detected in this specific analysis, the lack of output escaping is a critical weakness that could be exploited if malicious data is ever introduced into the plugin's output.

The vulnerability history also appears clean, with no recorded CVEs. This, combined with the low number of detected code signals suggesting potential vulnerabilities, points to a plugin that has historically been secure. Nonetheless, the critical output escaping issue requires immediate attention, as it represents a significant, albeit undetected in the current flow, risk.

Key Concerns

  • Low output escaping rate
Vulnerabilities
None known

Attention Grabber (Hello Bar Alternative) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Attention Grabber (Hello Bar Alternative) Release Timeline

v1.202
v1.201
v1.41
v1.35
v1.34
v1.33
v1.32
v1.31
v1.4Current
v1.3
v1.2
v1.1
Code Analysis
Analyzed Mar 16, 2026

Attention Grabber (Hello Bar Alternative) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
185
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

1% escaped186 total outputs
Attack Surface

Attention Grabber (Hello Bar Alternative) Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actioninitclasses\sunrise.class.php:98
actionadmin_initclasses\sunrise.class.php:100
actionadmin_menuclasses\sunrise.class.php:102
actionadmin_menuclasses\sunrise.class.php:286
filterwp_footerinc\plugin-actions.php:3
Maintenance & Trust

Attention Grabber (Hello Bar Alternative) Maintenance & Trust

Maintenance Signals

WordPress version tested3.6.1
Last updatedJan 27, 2014
PHP min version
Downloads13K

Community Trust

Rating54/100
Number of ratings3
Active installs30
Developer Profile

Attention Grabber (Hello Bar Alternative) Developer Profile

conversioninsights

1 plugin · 30 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Attention Grabber (Hello Bar Alternative)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/attention-grabber-hello-bar-alternative/assets/css/sunrise.css/wp-content/plugins/attention-grabber-hello-bar-alternative/assets/js/form.js/wp-content/plugins/attention-grabber-hello-bar-alternative/assets/js/sunrise.js
Script Paths
/wp-content/plugins/attention-grabber-hello-bar-alternative/assets/js/form.js/wp-content/plugins/attention-grabber-hello-bar-alternative/assets/js/sunrise.js
Version Parameters
attention-grabber-hello-bar-alternative/assets/css/sunrise.css?ver=attention-grabber-hello-bar-alternative/assets/js/form.js?ver=attention-grabber-hello-bar-alternative/assets/js/sunrise.js?ver=

HTML / DOM Fingerprints

JS Globals
sunrise_plugin_framework
FAQ

Frequently Asked Questions about Attention Grabber (Hello Bar Alternative)