Bicycles by falbar Security & Risk Analysis

wordpress.org/plugins/bicycles-by-falbar

Collection of ready-made solutions for WordPress customization.

700 active installs v2.1 PHP 5.2+ WP 4.4.2+ Updated Jan 4, 2018
meta-generatorremove-meta-generatorrsdseo
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Bicycles by falbar Safe to Use in 2026?

Generally Safe

Score 85/100

Bicycles by falbar has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The plugin 'bicycles-by-falbar' v2.1 exhibits a concerning lack of security best practices despite having no recorded vulnerabilities. The static analysis reveals a complete absence of any attack surface checks, including AJAX handlers, REST API routes, shortcodes, and cron events. Furthermore, there are no nonce or capability checks implemented, which are critical for preventing various attacks. This indicates a significant oversight in securing potential entry points into the plugin.

While the plugin demonstrates good practices by using prepared statements for its SQL queries, the output escaping is alarmingly low, with only 2% of outputs being properly escaped. This creates a high risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data is likely being rendered without proper sanitization. The taint analysis also highlights a concerning pattern: all 6 analyzed flows have unsanitized paths, meaning data could be flowing through the application without being validated or cleaned, potentially leading to unexpected behavior or security issues.

The plugin's vulnerability history is clean, with zero recorded CVEs. This could indicate either genuine robust security over time or simply a lack of discovery due to the limited attack surface and perhaps limited user adoption, making it a less attractive target. However, the significant weaknesses identified in the static and taint analysis, particularly the low output escaping and unsanitized flows, far outweigh the absence of known vulnerabilities. The plugin needs immediate attention to implement proper output escaping and address the unsanitized data flows to mitigate the high risk of XSS and other injection attacks.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • Low output escaping (2%)
  • All taint flows have unsanitized paths
  • No authorization checks on entry points
Vulnerabilities
None known

Bicycles by falbar Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Bicycles by falbar Release Timeline

v2.1Current
v2.0.1
v2.0
v1.11
v1.1
v1.0.4
v1.0.3
v1.0.2
v1.0.1
v1.0
Code Analysis
Analyzed Mar 16, 2026

Bicycles by falbar Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
204
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
3
External Requests
0
Bundled Libraries
0

Output Escaping

2% escaped208 total outputs
Data Flows · Security
6 unsanitized

Data Flow Analysis

6 flows6 with unsanitized paths
init_redirect_from_http_to_https (includes\static\class-falbar-bbf-option-additionally.php:192)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Bicycles by falbar Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 65
actionadmin_initincludes\class-falbar-bbf.php:38
actionplugins_loadedincludes\class-falbar-bbf.php:46
actionadmin_menuincludes\class-falbar-bbf.php:54
actionadmin_enqueue_scriptsincludes\class-falbar-bbf.php:62
actionadmin_noticesincludes\class-falbar-bbf.php:70
actionadmin_menuincludes\static\class-falbar-bbf-option-additionally.php:8
actiondo_feedincludes\static\class-falbar-bbf-option-additionally.php:24
actiondo_feed_rdfincludes\static\class-falbar-bbf-option-additionally.php:33
actiondo_feed_rssincludes\static\class-falbar-bbf-option-additionally.php:42
actiondo_feed_rss2includes\static\class-falbar-bbf-option-additionally.php:51
actiondo_feed_atomincludes\static\class-falbar-bbf-option-additionally.php:60
actionwp_before_admin_bar_renderincludes\static\class-falbar-bbf-option-additionally.php:74
filtersanitize_file_nameincludes\static\class-falbar-bbf-option-additionally.php:87
actioninitincludes\static\class-falbar-bbf-option-additionally.php:101
filterwp_revisions_to_keepincludes\static\class-falbar-bbf-option-additionally.php:125
actionwp_print_scriptsincludes\static\class-falbar-bbf-option-additionally.php:140
actionwidgets_initincludes\static\class-falbar-bbf-option-code.php:8
actioninitincludes\static\class-falbar-bbf-option-code.php:21
actioninitincludes\static\class-falbar-bbf-option-code.php:85
filterwp_default_scriptsincludes\static\class-falbar-bbf-option-code.php:98
actioninitincludes\static\class-falbar-bbf-option-code.php:113
actioninitincludes\static\class-falbar-bbf-option-code.php:129
filtertiny_mce_pluginsincludes\static\class-falbar-bbf-option-code.php:166
filterrest_enabledincludes\static\class-falbar-bbf-option-code.php:189
actiontemplate_redirectincludes\static\class-falbar-bbf-option-code.php:210
filtercomment_form_default_fieldsincludes\static\class-falbar-bbf-option-comments.php:11
actionwp_headincludes\static\class-falbar-bbf-option-comments.php:26
actionwp_footerincludes\static\class-falbar-bbf-option-comments.php:34
filtercomment_textincludes\static\class-falbar-bbf-option-comments.php:42
actionwp_headincludes\static\class-falbar-bbf-option-comments.php:57
actionwp_footerincludes\static\class-falbar-bbf-option-comments.php:65
filterget_comment_author_linkincludes\static\class-falbar-bbf-option-comments.php:73
actiontemplate_redirectincludes\static\class-falbar-bbf-option-doubles.php:8
actionwpincludes\static\class-falbar-bbf-option-doubles.php:22
actionwidgets_initincludes\static\class-falbar-bbf-option-doubles.php:30
actionwpincludes\static\class-falbar-bbf-option-doubles.php:43
actionwidgets_initincludes\static\class-falbar-bbf-option-doubles.php:51
actiontemplate_redirectincludes\static\class-falbar-bbf-option-doubles.php:64
actionwpincludes\static\class-falbar-bbf-option-doubles.php:77
actiontemplate_redirectincludes\static\class-falbar-bbf-option-doubles.php:90
filtercomment_reply_linkincludes\static\class-falbar-bbf-option-doubles.php:99
filterthe_generatorincludes\static\class-falbar-bbf-option-security.php:9
filterlogin_errorsincludes\static\class-falbar-bbf-option-security.php:34
filterxmlrpc_enabledincludes\static\class-falbar-bbf-option-security.php:47
filtertemplate_redirectincludes\static\class-falbar-bbf-option-security.php:52
filterwp_headersincludes\static\class-falbar-bbf-option-security.php:60
actionwpincludes\static\class-falbar-bbf-option-security.php:73
filterstyle_loader_srcincludes\static\class-falbar-bbf-option-security.php:86
filterscript_loader_srcincludes\static\class-falbar-bbf-option-security.php:101
filterthe_contentincludes\static\class-falbar-bbf-option-seo.php:10
actiontemplate_redirectincludes\static\class-falbar-bbf-option-seo.php:23
actioninitincludes\static\class-falbar-bbf-option-seo.php:38
filterrobots_txtincludes\static\class-falbar-bbf-option-seo.php:46
actionwidgets_initincludes\static\class-falbar-bbf-option-widgets.php:8
actionwidgets_initincludes\static\class-falbar-bbf-option-widgets.php:22
actionwidgets_initincludes\static\class-falbar-bbf-option-widgets.php:36
actionwidgets_initincludes\static\class-falbar-bbf-option-widgets.php:50
actionwidgets_initincludes\static\class-falbar-bbf-option-widgets.php:64
actionwidgets_initincludes\static\class-falbar-bbf-option-widgets.php:78
actionwidgets_initincludes\static\class-falbar-bbf-option-widgets.php:92
actionwidgets_initincludes\static\class-falbar-bbf-option-widgets.php:106
actionwidgets_initincludes\static\class-falbar-bbf-option-widgets.php:120
actionwidgets_initincludes\static\class-falbar-bbf-option-widgets.php:134
actionwidgets_initincludes\static\class-falbar-bbf-option-widgets.php:148
actionwidgets_initincludes\static\class-falbar-bbf-option-widgets.php:162
Maintenance & Trust

Bicycles by falbar Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedJan 4, 2018
PHP min version5.2
Downloads13K

Community Trust

Rating100/100
Number of ratings5
Active installs700
Developer Profile

Bicycles by falbar Developer Profile

Anton Kuliashou

3 plugins · 930 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Bicycles by falbar

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bicycles-by-falbar/assets/css/backend.css/wp-content/plugins/bicycles-by-falbar/assets/js/backend.js
Script Paths
/wp-content/plugins/bicycles-by-falbar/assets/js/backend.js
Version Parameters
bicycles-by-falbar/assets/css/backend.css?ver=bicycles-by-falbar/assets/js/backend.js?ver=

HTML / DOM Fingerprints

CSS Classes
bicycles-pagewrap-tabstabstabtab-contentfast-setupfast-setup-message
Data Attributes
data-tab
FAQ

Frequently Asked Questions about Bicycles by falbar