DH – Notification Bar Security & Risk Analysis

wordpress.org/plugins/dh-notification-bar

Simple Top Notification Bar.

10 active installs v7 PHP + WP 4.0+ Updated Sep 9, 2020
bardhnotificationnotification-barnotificationbar
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is DH – Notification Bar Safe to Use in 2026?

Generally Safe

Score 85/100

DH – Notification Bar has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "dh-notification-bar" v7 plugin presents a generally positive security posture based on the provided static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points is a significant strength, minimizing the plugin's direct attack surface. Furthermore, the code signals show no dangerous functions, external HTTP requests, or file operations, which are common vectors for exploits. All SQL queries utilize prepared statements, and there are no known vulnerabilities (CVEs) associated with this plugin, indicating a history of stable and secure development.

However, a notable concern arises from the output escaping. With 36 total outputs, only 28% are properly escaped, leaving a substantial portion potentially vulnerable to cross-site scripting (XSS) attacks. This is a critical weakness that could be exploited if any user-controlled data is reflected in the output without adequate sanitization. While the plugin boasts no known vulnerabilities, the lack of comprehensive output escaping is a significant security gap that needs immediate attention, as it could be a precursor to future, undiscovered vulnerabilities.

In conclusion, the plugin has excellent foundational security practices, particularly in its limited attack surface and secure database interactions. The absence of known vulnerabilities is a testament to its history. The primary weakness lies in its insufficient output escaping, which creates a significant XSS risk. Addressing this specific issue should be the top priority to improve the overall security of "dh-notification-bar" v7.

Key Concerns

  • Insufficient output escaping (72% unescaped)
Vulnerabilities
None known

DH – Notification Bar Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

DH – Notification Bar Release Timeline

v7Current
v6
v5
v4
v3
v2
v1
Code Analysis
Analyzed Apr 16, 2026

DH – Notification Bar Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
26
10 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

28% escaped36 total outputs
Attack Surface

DH – Notification Bar Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionwp_enqueue_scriptsindex.php:37
actionadmin_menuindex.php:66
actionadmin_menuindex.php:79
actionadmin_headindex.php:116
actionadmin_enqueue_scriptsindex.php:118
actioninitindex.php:120
actionwp_headindex.php:406
actionwp_footerindex.php:407
Maintenance & Trust

DH – Notification Bar Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedSep 9, 2020
PHP min version
Downloads2K

Community Trust

Rating20/100
Number of ratings1
Active installs10
Developer Profile

DH – Notification Bar Developer Profile

Dannie Herdyawan

8 plugins · 80 total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect DH – Notification Bar

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/dh-notification-bar/assets/css/dhnotificationbar.css/wp-content/plugins/dh-notification-bar/assets/js/js.cookie.js/wp-content/plugins/dh-notification-bar/assets/js/dhnotificationbar-admin.js/wp-content/plugins/dh-notification-bar/assets/css/dhnotificationbar-admin.css/wp-content/plugins/dh-notification-bar/assets/js/spectrum.js/wp-content/plugins/dh-notification-bar/assets/css/spectrum.css
Script Paths
https://stackpath.bootstrapcdn.com/font-awesome/4.7.0/css/font-awesome.min.css

HTML / DOM Fingerprints

CSS Classes
dh-success-messagesdhnotificationbardh-plugins-admin__menudhnotificationbar-admin__menutitle
HTML Comments
<!-- Start of Donation Form --><!-- End of Donation Form --><!-- If using a Business or Company Logo Graphic, include the "cpp_header_image" variable in your View Cart code. --><!-- Replace "business" value with your PayPal Email Address or Account ID -->+2 more
Data Attributes
name="os0"name="myform"name="amount"name="item_number"name="cpp_header_image"name="on0"+14 more
JS Globals
CalculateOrderdhnotificationbar_admin_head
FAQ

Frequently Asked Questions about DH – Notification Bar