Browser Address Bar Color Security & Risk Analysis

wordpress.org/plugins/browser-address-bar-color

Customize your mobile browsing experience by setting theme colors for the address bar of your pages on your WordPress site

300 active installs v4.1 PHP + WP 4.6+ Updated Dec 31, 2025
address-baraddress-bar-colormeta-tagtheme-colorurl-bar
99
A · Safe
CVEs total1
Unpatched0
Last CVEMar 24, 2025
Safety Verdict

Is Browser Address Bar Color Safe to Use in 2026?

Generally Safe

Score 99/100

Browser Address Bar Color has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Mar 24, 2025Updated 3mo ago
Risk Assessment

The browser-address-bar-color plugin, version 4.1, exhibits a generally good security posture based on the static analysis. The absence of dangerous functions, external HTTP requests, file operations, and SQL queries that are not properly prepared are strong indicators of secure coding practices. The presence of a nonce check and a high percentage of properly escaped output further bolster its security. However, the complete lack of capability checks across all entry points is a notable concern. While the attack surface appears to be zero, this could be misleading if any functionality were to be added without proper authorization checks in the future. The plugin's vulnerability history reveals a single medium-severity CVE, identified as Cross-Site Request Forgery (CSRF), which was patched. The fact that there are no currently unpatched vulnerabilities is positive. Overall, the plugin demonstrates good fundamental security but would benefit from the implementation of capability checks to safeguard against potential future authorization vulnerabilities.

Key Concerns

  • No capability checks found
  • One medium CVE history
Vulnerabilities
1

Browser Address Bar Color Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-30577medium · 6.1Cross-Site Request Forgery (CSRF)

Browser Address Bar Color <= 3.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting

Mar 24, 2025 Patched in 3.4.0 (54d)
Code Analysis
Analyzed Mar 16, 2026

Browser Address Bar Color Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
3
29 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

91% escaped32 total outputs
Attack Surface

Browser Address Bar Color Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_menubrowserAddressBarColor.php:30
actionwp_headbrowserAddressBarColor.php:128
actionsave_postbrowserAddressBarColor.php:137
actiondeleted_postbrowserAddressBarColor.php:138
Maintenance & Trust

Browser Address Bar Color Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 31, 2025
PHP min version
Downloads5K

Community Trust

Rating90/100
Number of ratings2
Active installs300
Developer Profile

Browser Address Bar Color Developer Profile

mendibass

1 plugin · 300 total installs

87
trust score
Avg Security Score
99/100
Avg Patch Time
54 days
View full developer profile
Detection Fingerprints

How We Detect Browser Address Bar Color

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/browser-address-bar-color/babcScript.js
Script Paths
wp-content/plugins/browser-address-bar-color/babcScript.js
Version Parameters
babc-script?ver=1.0.2

HTML / DOM Fingerprints

HTML Comments
Chrome mobile, Samsung internet
Data Attributes
name="theme-color"
FAQ

Frequently Asked Questions about Browser Address Bar Color