
Bottom Bar Security & Risk Analysis
wordpress.org/plugins/bottom-barBottom Bar is a WordPress plugin that includes a several features for creating interactive and user-friendly toolbar.
Is Bottom Bar Safe to Use in 2026?
Generally Safe
Score 100/100Bottom Bar has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "bottom-bar" plugin v0.1.7 exhibits a mixed security posture. On one hand, the absence of known vulnerabilities and CVEs in its history suggests a potentially well-maintained or less-targeted plugin. Furthermore, the static analysis reports a limited attack surface with no apparent AJAX handlers, REST API routes, shortcodes, or cron events exposed without authentication. This is a positive sign for overall security.
However, several significant concerns arise from the code analysis. The fact that 100% of output is not properly escaped is a major red flag, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. Additionally, 13% of SQL queries not using prepared statements, coupled with a taint analysis indicating a flow with unsanitized paths, suggests potential SQL injection risks. The complete lack of nonce checks and capability checks, especially concerning given the potential for XSS, further weakens its security defenses.
Key Concerns
- 0% output escaping
- Raw SQL queries
- Unsanitized paths in taint flow
- No nonce checks
- No capability checks
Bottom Bar Security Vulnerabilities
Bottom Bar Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Bottom Bar Attack Surface
WordPress Hooks 4
Maintenance & Trust
Bottom Bar Maintenance & Trust
Maintenance Signals
Community Trust
Bottom Bar Alternatives
Bottom Admin Toolbar
bottom-admin-toolbar
Stick the WordPress admin bar to the bottom of the screen. Hide it with SHIFT + Down Arrow keyboard shortcut.
Tambar – Bottom Admin Bar
tambar
The sticky header is a widely used feature on many websites, but it can conflict with the WordPress admin bar. Tambar effectively resolves this issue!
Shareboost
shareboost
Increase social engagement.
Show Current Template
show-current-template
A WordPress plugin which shows the current template file name, the current theme name and included template files' name in the tool bar.
WPFront Notification Bar
wpfront-notification-bar
Easily lets you create a bar on top or bottom to display a notification.
Bottom Bar Developer Profile
2 plugins · 20 total installs
How We Detect Bottom Bar
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bottom-bar/css/bottom-bar.css/wp-content/plugins/bottom-bar/controllers/jquery.min.js/wp-content/plugins/bottom-bar/controllers/bottom-bar.js/wp-content/plugins/bottom-bar/controllers/jquery.min.js/wp-content/plugins/bottom-bar/controllers/bottom-bar.jsHTML / DOM Fingerprints
random-postbb_lang