Easy Heads Up Bar Security & Risk Analysis

wordpress.org/plugins/easy-heads-up-bar

The Easy Heads Up Bar Plugin allows you to quickly add a customizable notification bar to your WordPress website.

100 active installs v2.1.7 PHP + WP 4.0+ Updated Aug 1, 2016
callout-barheads-upheads-up-bar
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Easy Heads Up Bar Safe to Use in 2026?

Generally Safe

Score 85/100

Easy Heads Up Bar has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "easy-heads-up-bar" v2.1.7 plugin exhibits a strong security posture based on the provided static analysis. The absence of any identified dangerous functions, SQL queries without prepared statements, unescaped output, file operations, external HTTP requests, or taint flows is highly commendable. Furthermore, the complete lack of any recorded vulnerabilities, including CVEs, suggests a well-maintained and secure codebase over time. This indicates that the developers are likely adhering to secure coding practices and have a proactive approach to security.

However, a notable area of concern arises from the complete absence of any observed capability checks or nonce checks. While the static analysis reports zero unprotected entry points, this could be an artifact of the analysis tool or the plugin's specific architecture. If the plugin relies solely on the absence of direct entry points rather than explicit authorization checks for its operations, it could present a theoretical risk. In the absence of any known vulnerabilities, this remains a theoretical concern, but a robust security model typically includes explicit authorization checks on all relevant operations, even if the attack surface appears limited.

In conclusion, the "easy-heads-up-bar" v2.1.7 plugin appears to be exceptionally secure with no active or historical vulnerabilities and excellent adherence to secure coding principles in most areas. The primary weakness, albeit theoretical given the current data, is the lack of explicit capability and nonce checks, which is a deviation from best practices for securing all plugin functionalities.

Key Concerns

  • No nonce checks found
  • No capability checks found
Vulnerabilities
None known

Easy Heads Up Bar Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Easy Heads Up Bar Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Easy Heads Up Bar Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

Easy Heads Up Bar Maintenance & Trust

Maintenance Signals

WordPress version tested4.6.30
Last updatedAug 1, 2016
PHP min version
Downloads31K

Community Trust

Rating90/100
Number of ratings17
Active installs100
Alternatives

Easy Heads Up Bar Alternatives

No alternatives data available yet.

Developer Profile

Easy Heads Up Bar Developer Profile

Greenweb

8 plugins · 330 total installs

90
trust score
Avg Security Score
94/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Easy Heads Up Bar

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/easy-heads-up-bar/css/ehb-frontend.css/wp-content/plugins/easy-heads-up-bar/js/ehb-frontend.js
Script Paths
/wp-content/plugins/easy-heads-up-bar/js/ehb-frontend.js
Version Parameters
easy-heads-up-bar/css/ehb-frontend.css?ver=easy-heads-up-bar/js/ehb-frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
ehb-wrapperehb-contentehb-closeehb-cta
HTML Comments
<!-- ehb-wrapper -->
Data Attributes
data-ehb-heightdata-ehb-bg-colordata-ehb-text-colordata-ehb-font-sizedata-ehb-cta-colordata-ehb-cta-text-color+1 more
JS Globals
ehb_front_end_obj
FAQ

Frequently Asked Questions about Easy Heads Up Bar