
Awesome Progress Bar Security & Risk Analysis
wordpress.org/plugins/awesome-progess-barAwesome Progress Bar is a lightweight plugin for WordPress that allows you to easily add customizable progress bars to your site.
Is Awesome Progress Bar Safe to Use in 2026?
Generally Safe
Score 99/100Awesome Progress Bar has a strong security track record. Known vulnerabilities have been patched promptly.
The 'awesome-progress-bar' plugin v1.1.0 demonstrates a mixed security posture. On the positive side, the static analysis shows no identified dangerous functions, all SQL queries utilize prepared statements, and all output is properly escaped. There are also no file operations or external HTTP requests, and no bundled libraries, which are generally good security practices. However, several concerns are raised. The absence of any nonce checks or capability checks across all entry points, especially the three shortcodes, is a significant weakness. This means that these shortcodes could be triggered by unauthenticated users or users with limited privileges, potentially leading to unintended actions if any logic within them is susceptible to manipulation.
The vulnerability history indicates one known CVE, which was a medium-severity Cross-Site Scripting (XSS) vulnerability. While this vulnerability is reported as currently unpatched, its historical nature and the fact that it's the only recorded CVE suggest that the developers have addressed past issues. However, the presence of an XSS vulnerability, even historically, highlights a potential area where input validation and output sanitization might have been previously insufficient, and continued vigilance is needed. The complete lack of taint analysis results is also notable; while this could mean no vulnerabilities were found, it might also indicate limitations in the analysis tool or scope.
In conclusion, while 'awesome-progress-bar' has strengths in its use of prepared statements and output escaping, the lack of authentication and authorization checks on its shortcodes presents a clear risk. The historical XSS vulnerability, though patched, warrants attention to ensure future code remains secure. The absence of taint analysis is a neutral factor but could be improved for more comprehensive testing.
Key Concerns
- Missing nonce checks on entry points (shortcodes)
- Missing capability checks on entry points (shortcodes)
- Historical medium severity XSS vulnerability
Awesome Progress Bar Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Awesome Progress Bar <= 1.0.13 - Authenticated (Contributor+) Stored Cross-Site Scripting
Awesome Progress Bar Code Analysis
Output Escaping
Awesome Progress Bar Attack Surface
Shortcodes 3
WordPress Hooks 1
Maintenance & Trust
Awesome Progress Bar Maintenance & Trust
Maintenance Signals
Community Trust
Awesome Progress Bar Alternatives
Sectionly
sectionly
Sectionly is a plugin as well as an add-on for the visual composer and elementor page builder.it contains the elements/widgets/shortcodes that are com …
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor
elementskit-lite
Join millions who empower their websites with ElementsKit Elementor Addons. Get templates, & 100+ widgets like header-footer, mega menu, custom widget
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Ultimate Addons for Elementor
header-footer-elementor
Powerful Elementor addon with advanced Elementor widgets, templates, WooCommerce widgets & Header-Footer builder to build professional websites fa …
Premium Addons for Elementor – Powerful Elementor Templates & Widgets
premium-addons-for-elementor
Elementor Carousel, Mega Menu, Posts List/Slider, Media Gallery, WooCommerce Widgets, Display Conditions, Premade Templates & more.
Awesome Progress Bar Developer Profile
12 plugins · 1K total installs
How We Detect Awesome Progress Bar
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/awesome-progess-bar/css/bootstrap.min.cssHTML / DOM Fingerprints
progressprogress-barprogress-bar-stripedprogress-bar-animatedaria-valuenowaria-valueminaria-valuemax[progressbar_basic[progressbar_stripped[progressbar_animated