Davon’s Floating Admin Bar Security & Risk Analysis

wordpress.org/plugins/davons-floating-admin-bar

The Davon’s Floating Admin Bar floats at the top of your Website with minimal impact on the website’s appearance if you are logged in.

10 active installs v1.0.5 PHP 5.6+ WP 4.5+ Updated Jan 31, 2022
admin-bar
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Davon’s Floating Admin Bar Safe to Use in 2026?

Generally Safe

Score 85/100

Davon’s Floating Admin Bar has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The "davons-floating-admin-bar" v1.0.5 plugin exhibits a strong security posture based on the provided static analysis. The plugin demonstrates a complete absence of common attack vectors such as AJAX handlers, REST API routes, shortcodes, and cron events, significantly limiting its attack surface. Furthermore, the code shows no dangerous function usage, no raw SQL queries (all are prepared), no file operations, no external HTTP requests, and no bundled libraries. This suggests a well-developed and secure codebase with a focus on fundamental security practices like data sanitization and input validation. The lack of any recorded vulnerabilities or CVEs in its history further reinforces this positive assessment, indicating a consistent track record of security adherence.

Despite the overwhelmingly positive indicators, a single critical concern arises from the output escaping analysis. With 100% of outputs not properly escaped, there is a significant risk of Cross-Site Scripting (XSS) vulnerabilities. If any data that is displayed to users originates from untrusted sources, it could be maliciously crafted to execute arbitrary JavaScript in the user's browser. While the absence of other attack vectors and vulnerability history are strong mitigating factors, this unescaped output represents a tangible and exploitable weakness that should be addressed promptly. The overall security is good due to strong foundational practices, but the lack of output escaping introduces a notable risk.

Key Concerns

  • Output escaping is not implemented (100%)
Vulnerabilities
None known

Davon’s Floating Admin Bar Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Davon’s Floating Admin Bar Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped2 total outputs
Attack Surface

Davon’s Floating Admin Bar Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actioninitclasses\class-plugin.php:26
actionget_headerclasses\package\class-stylechanges.php:9
actionwp_headclasses\package\class-stylechanges.php:10
actionadmin_noticesdavons-floating-admin-bar.php:72
Maintenance & Trust

Davon’s Floating Admin Bar Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.13
Last updatedJan 31, 2022
PHP min version5.6
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Davon’s Floating Admin Bar Developer Profile

joelmelon

3 plugins · 320 total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Davon’s Floating Admin Bar

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/davons-floating-admin-bar/classes/package/class-stylechanges.php

HTML / DOM Fingerprints

CSS Classes
wpadminbarab-top-secondarywp-toolbar
FAQ

Frequently Asked Questions about Davon’s Floating Admin Bar