Dev Info Bar Security & Risk Analysis

wordpress.org/plugins/dev-info-bar

A simple WordPress extension which adds itself to the admin bar, providing system information such as PHP, MySQL version and details of the WordPress …

80 active installs v1.0.2 PHP 5.6+ WP 4.5+ Updated Jan 21, 2019
adminadmin-bardebuggingenvironmentserver
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Dev Info Bar Safe to Use in 2026?

Generally Safe

Score 85/100

Dev Info Bar has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The static analysis of dev-info-bar v1.0.2 reveals a generally strong security posture with no detected issues in critical areas. The absence of dangerous functions, SQL queries executed with prepared statements, properly escaped output, file operations, external HTTP requests, nonce checks, capability checks, and bundled libraries is commendable. The taint analysis also shows zero flows with unsanitized paths, indicating no readily apparent data leakage or injection vulnerabilities through common attack vectors. Furthermore, the plugin has no recorded history of vulnerabilities (CVEs), which suggests a history of good development practices and diligence in addressing potential security flaws. However, the analysis also indicates a complete lack of protection mechanisms like nonce checks and capability checks across all entry points. While the current version may not have exploitable flaws due to its limited attack surface, this absence of fundamental security measures represents a significant underlying risk. If new entry points are introduced or existing ones are exposed in future versions, the lack of these checks could lead to vulnerabilities.

Key Concerns

  • No nonce checks present
  • No capability checks present
Vulnerabilities
None known

Dev Info Bar Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Dev Info Bar Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Dev Info Bar Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionplugins_loadedincludes\class-bw-dev-info-bar.php:32
actionwp_enqueue_scriptsincludes\class-bw-dev-info-bar.php:49
actionadmin_enqueue_scriptsincludes\class-bw-dev-info-bar.php:50
actionadmin_bar_menuincludes\class-bw-dev-info-bar.php:61
Maintenance & Trust

Dev Info Bar Maintenance & Trust

Maintenance Signals

WordPress version tested5.0.25
Last updatedJan 21, 2019
PHP min version5.6
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs80
Developer Profile

Dev Info Bar Developer Profile

istvankrucsanyica

1 plugin · 80 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Dev Info Bar

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/dev-info-bar/public/css/bw_dev_info_bar.css
Version Parameters
bw_dev_info_bar.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Dev Info Bar