
DoBar – A Beautiful Loading Bar for WordPress Security & Risk Analysis
wordpress.org/plugins/dobarSimply display a loading bar to your fontend and backend pages.
Is DoBar – A Beautiful Loading Bar for WordPress Safe to Use in 2026?
Generally Safe
Score 100/100DoBar – A Beautiful Loading Bar for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "dobar" v1.3 plugin exhibits a generally strong security posture based on the static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events with unprotected entry points is a significant positive. Furthermore, the plugin demonstrates good practices by exclusively using prepared statements for its SQL queries, indicating a low risk of SQL injection vulnerabilities. The presence of nonce and capability checks, while limited, also suggests an awareness of fundamental WordPress security principles.
However, there are notable areas of concern. The most significant is the very low percentage (4%) of properly escaped output, with 28 total outputs analyzed. This indicates a high likelihood of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data is likely being rendered without proper sanitization. The taint analysis revealing one flow with an unsanitized path, while not classified as critical or high severity, should still be investigated. Additionally, the 5 file operations and 1 external HTTP request represent potential avenues for attack if not handled with extreme care and proper validation, although the static analysis does not provide specifics on whether these are vulnerable.
The plugin's vulnerability history is clean, with no known CVEs. This is a positive sign, suggesting that the developers have either been diligent in their security practices or the plugin has not been a target of widespread exploitation. However, a clean history does not guarantee future security, especially given the identified output escaping issues. In conclusion, while "dobar" v1.3 has strengths in its limited attack surface and SQL handling, the prevalent lack of output escaping presents a substantial risk that needs immediate attention.
Key Concerns
- Low output escaping percentage
- Unsanitized path in taint flow
- File operations without specific checks
- External HTTP request without specific checks
DoBar – A Beautiful Loading Bar for WordPress Security Vulnerabilities
DoBar – A Beautiful Loading Bar for WordPress Release Timeline
DoBar – A Beautiful Loading Bar for WordPress Code Analysis
Output Escaping
Data Flow Analysis
DoBar – A Beautiful Loading Bar for WordPress Attack Surface
WordPress Hooks 10
Maintenance & Trust
DoBar – A Beautiful Loading Bar for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
DoBar – A Beautiful Loading Bar for WordPress Alternatives
Stylish Preloader
stylish-preloader
Stylish Preloader plugin use for loading your wrodpress page. Stylish Preloader is integrated in the WordPress Customizer, so you can change every set …
Preloader Awesome – Page Loading Animation with Spinner & Gif
preloader-awesome
Preloader Awesome help You to create page loading animation WordPress with spinner or You can upload Your own GIF.
PageLoader Lite – Loading Screen
pageloader-lite
Add a simple to use, lightweight loading screen to your WordPress site. Great for branding!
WP Page Loading
wp-page-loading
10+ layouts - Simple, light and great! Add preloader to your website easily, responsive and retina, full customization, compatible with all major brow …
DWL Preloader
dwl-preloader
A beautiful animated preloader plugin for WordPress. Choose from 10 stunning SVG preloader styles with a live preview admin panel.
DoBar – A Beautiful Loading Bar for WordPress Developer Profile
7 plugins · 8K total installs
How We Detect DoBar – A Beautiful Loading Bar for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/dobar/assets/dobar.css/wp-content/plugins/dobar/assets/dobar.js/wp-content/plugins/dobar/assets/pace/pace.min.js/wp-content/plugins/dobar/assets/pace/themes//wp-content/plugins/dobar/assets/pace/themes/.css/wp-content/plugins/dobar/assets/pace/pace.min.js/wp-content/plugins/dobar/assets/dobar.jsdobar.css?ver=dobar.js?ver=HTML / DOM Fingerprints
dobar-switchdata-dobar-iddobar