Notification Bar, Sticky Notification Bar, Sticky Welcome Bar for any theme Security & Risk Analysis

wordpress.org/plugins/gp-notification-bar

Easily it allows you to create a bar on top or bottom to display a notification or promotion

40 active installs v1.1 PHP 5.4+ WP 3.1+ Updated Unknown
barbottom-barnotificationnotification-bartop-bar
79
B · Generally Safe
CVEs total1
Unpatched1
Last CVEMar 31, 2025
Download
Safety Verdict

Is Notification Bar, Sticky Notification Bar, Sticky Welcome Bar for any theme Safe to Use in 2026?

Mostly Safe

Score 79/100

Notification Bar, Sticky Notification Bar, Sticky Welcome Bar for any theme is generally safe to use. 1 past CVE were resolved. Keep it updated.

1 known CVE 1 unpatched Last CVE: Mar 31, 2025
Risk Assessment

The gp-notification-bar plugin version 1.1 exhibits a mixed security posture. On the positive side, the static analysis reveals a strong adherence to secure coding practices. There are no dangerous function calls, all SQL queries are prepared, and a high percentage of output is properly escaped. Furthermore, the plugin does not appear to bundle any external libraries, which can sometimes introduce vulnerabilities. The presence of numerous nonce checks and a complete absence of taint analysis findings suggest a proactive approach to preventing common web exploits.

However, the plugin is not without its risks. A significant concern is the existence of one known, unpatched medium-severity vulnerability, specifically a Cross-Site Scripting (XSS) vulnerability. The fact that this vulnerability was last reported in March 2025 suggests it might be a recent discovery or an ongoing issue. While the static analysis did not reveal any immediate XSS flaws in the analyzed code, the historical vulnerability indicates a potential blind spot or a past oversight that could be exploited if the underlying issue remains unresolved. The plugin also makes external HTTP requests, which, while not inherently insecure, can be a vector for certain types of attacks if not handled carefully and are not explicitly checked for sanitization in the provided data.

In conclusion, gp-notification-bar v1.1 shows commendable use of secure coding principles in its current codebase. The robust use of prepared statements and output escaping are strong points. The primary weakness lies in the single unpatched medium-severity XSS vulnerability. While the current code analysis doesn't flag this specific issue, its presence in the vulnerability history necessitates vigilance and prompt patching. The plugin's attack surface, while small with no unprotected entry points, is still present, and the external HTTP requests warrant careful monitoring.

Key Concerns

  • Unpatched medium severity CVE
Vulnerabilities
1

Notification Bar, Sticky Notification Bar, Sticky Welcome Bar for any theme Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-31610medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Notification Bar, Sticky Notification Bar, Sticky Welcome Bar for any theme <= 1.1 - Authenticated (Administrator+) Stored Cross-Site Scripting

Mar 31, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Notification Bar, Sticky Notification Bar, Sticky Welcome Bar for any theme Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
19
317 escaped
Nonce Checks
7
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

94% escaped336 total outputs
Attack Surface

Notification Bar, Sticky Notification Bar, Sticky Welcome Bar for any theme Attack Surface

Entry Points5
Unprotected0

AJAX Handlers 5

authwp_ajax_gp_nb_contact_ginger_formadmin\admin-common.php:46
authwp_ajax_gnb_buttons_create_widgetadmin\admin.php:25
authwp_ajax_save_gnb_settingsadmin\admin.php:27
authwp_ajax_gnb_buttons_change_statusadmin\admin.php:29
authwp_ajax_gnb_buttons_remove_widgetadmin\admin.php:31
WordPress Hooks 13
actionadmin_menuadmin\admin-common.php:42
actionadmin_enqueue_scriptsadmin\admin-common.php:44
actionadmin_footeradmin\admin-common.php:48
actioninitadmin\admin.php:9
actionadmin_initadmin\admin.php:11
actionupgrader_process_completeadmin\admin.php:13
actionplugins_loadedadmin\admin.php:15
actionclear_cache_for_gnb_pluginadmin\admin.php:17
actionadmin_menuadmin\admin.php:19
actionadmin_enqueue_scriptsadmin\admin.php:21
actiongp_form_fieldadmin\admin.php:23
actionwp_enqueue_scriptsincludes\front-end.php:8
actionactivated_pluginindex.php:45
Maintenance & Trust

Notification Bar, Sticky Notification Bar, Sticky Welcome Bar for any theme Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedUnknown
PHP min version5.4
Downloads4K

Community Trust

Rating100/100
Number of ratings1
Active installs40
Developer Profile

Notification Bar, Sticky Notification Bar, Sticky Welcome Bar for any theme Developer Profile

gingerplugins

3 plugins · 10K total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
28 days
View full developer profile
Detection Fingerprints

How We Detect Notification Bar, Sticky Notification Bar, Sticky Welcome Bar for any theme

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gp-notification-bar/public/css/pricing.css
Version Parameters
gp-notification-bar/public/css/pricing.css?ver=

HTML / DOM Fingerprints

CSS Classes
gp_nb_notification_bar_close_buttongp_nb_notification_bar_messagegp_nb_notification_bar_wrappergp_nb_notification_bar_content_wrapper
HTML Comments
<!-- Start: GP Notification Bar --><!-- End: GP Notification Bar -->
Data Attributes
data-gpnb-transitiondata-gpnb-close-button-text
JS Globals
gp_notification_bar
FAQ

Frequently Asked Questions about Notification Bar, Sticky Notification Bar, Sticky Welcome Bar for any theme