
Dev Info Bar Security & Risk Analysis
wordpress.org/plugins/dev-info-barA simple WordPress extension which adds itself to the admin bar, providing system information such as PHP, MySQL version and details of the WordPress …
Is Dev Info Bar Safe to Use in 2026?
Generally Safe
Score 85/100Dev Info Bar has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of dev-info-bar v1.0.2 reveals a generally strong security posture with no detected issues in critical areas. The absence of dangerous functions, SQL queries executed with prepared statements, properly escaped output, file operations, external HTTP requests, nonce checks, capability checks, and bundled libraries is commendable. The taint analysis also shows zero flows with unsanitized paths, indicating no readily apparent data leakage or injection vulnerabilities through common attack vectors. Furthermore, the plugin has no recorded history of vulnerabilities (CVEs), which suggests a history of good development practices and diligence in addressing potential security flaws. However, the analysis also indicates a complete lack of protection mechanisms like nonce checks and capability checks across all entry points. While the current version may not have exploitable flaws due to its limited attack surface, this absence of fundamental security measures represents a significant underlying risk. If new entry points are introduced or existing ones are exposed in future versions, the lack of these checks could lead to vulnerabilities.
Key Concerns
- No nonce checks present
- No capability checks present
Dev Info Bar Security Vulnerabilities
Dev Info Bar Code Analysis
Dev Info Bar Attack Surface
WordPress Hooks 4
Maintenance & Trust
Dev Info Bar Maintenance & Trust
Maintenance Signals
Community Trust
Dev Info Bar Alternatives
Admin Bar Server Info
admin-bar-server-info
Lightweight plugin that displays essential server and environment information in a dropdown menu on the WordPress admin bar.
Don't Mess Up Prod
dont-mess-up-prod
Displays a colored environment indicator in the admin bar.
Heartbeat Control
heartbeat-control
Allows you to easily manage the frequency of the WordPress heartbeat API.
Display PHP Version
display-php-version
Displays the currently installed PHP/MySQL version in the "At a Glance" admin dashboard widget.
Hide Admin Bar
hide-admin-bar
Hide the Admin Bar in WordPress 3.1+.
Dev Info Bar Developer Profile
1 plugin · 80 total installs
How We Detect Dev Info Bar
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/dev-info-bar/public/css/bw_dev_info_bar.cssbw_dev_info_bar.css?ver=