Color Your Bar Security & Risk Analysis

wordpress.org/plugins/color-your-bar

A ultimate plugin to colorise the Mobile Chrome address bar and enable full mode and give style to iOS status bar.

500 active installs v2.0 PHP + WP 3.5+ Updated Aug 20, 2023
address-bar-colorchorme-address-barchrome-androidchrome-bargoogle-chrome-mobile
63
C · Use Caution
CVEs total1
Unpatched1
Last CVEMay 7, 2025
Safety Verdict

Is Color Your Bar Safe to Use in 2026?

Use With Caution

Score 63/100

Color Your Bar has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: May 7, 2025Updated 2yr ago
Risk Assessment

The "color-your-bar" plugin v2.0 exhibits a generally positive security posture based on the static analysis. The absence of any identified dangerous functions, raw SQL queries, file operations, or external HTTP requests is commendable. The plugin also demonstrates good practices in output escaping, with a very high percentage of outputs being properly escaped, and the presence of both nonce and capability checks indicates an effort to protect against common WordPress vulnerabilities. The attack surface is also notably clean, with no apparent AJAX handlers, REST API routes, shortcodes, or cron events that are exposed without authentication.

However, the presence of a known, unpatched medium severity CVE, specifically related to Cross-site Scripting (XSS), is a significant concern. This single vulnerability history point overshadows the otherwise strong static analysis results. It suggests that despite good coding practices in other areas, a critical flaw remains unaddressed, potentially exposing users to attacks. The fact that this vulnerability was discovered relatively recently (May 2025) further emphasizes the need for immediate attention.

In conclusion, while "color-your-bar" v2.0 has a solid foundation in terms of secure coding practices and a limited attack surface, the single unpatched medium severity XSS vulnerability represents a clear and present danger. The plugin's strengths in static analysis are undermined by this historical issue, making it crucial for users to apply any available patches or consider alternatives until this vulnerability is resolved.

Key Concerns

  • Unpatched medium severity CVE
Vulnerabilities
1

Color Your Bar Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-47595medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Color Your Bar <= 2.0 - Authenticated (Administrator+) Stored Cross-Site Scripting

May 7, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Color Your Bar Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
26 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

96% escaped27 total outputs
Attack Surface

Color Your Bar Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_menucolor-your-bar.php:42
actionadmin_enqueue_scriptscolor-your-bar.php:52
actionwp_headcolor-your-bar.php:58
actionamp_post_template_headcolor-your-bar.php:61
actionadmin_initcolor-your-bar.php:264
actionadd_meta_boxescolor-your-bar.php:283
actionsave_postcolor-your-bar.php:335
Maintenance & Trust

Color Your Bar Maintenance & Trust

Maintenance Signals

WordPress version tested6.3.8
Last updatedAug 20, 2023
PHP min version
Downloads8K

Community Trust

Rating86/100
Number of ratings3
Active installs500
Developer Profile

Color Your Bar Developer Profile

Darshan Saroya

1 plugin · 500 total installs

68
trust score
Avg Security Score
63/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Color Your Bar

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/color-your-bar/color-picker.js
Script Paths
/wp-content/plugins/color-your-bar/color-picker.js

HTML / DOM Fingerprints

Data Attributes
name='cyb-color'id='cyb-color'name='cyb-switch'id='cyb-switch'name='cyb-ios-full-mode'id='cyb-ios-full-mode'+2 more
FAQ

Frequently Asked Questions about Color Your Bar