
Notification Bar, Sticky Notification Bar, Sticky Welcome Bar for any theme Security & Risk Analysis
wordpress.org/plugins/gp-notification-barEasily it allows you to create a bar on top or bottom to display a notification or promotion
Is Notification Bar, Sticky Notification Bar, Sticky Welcome Bar for any theme Safe to Use in 2026?
Mostly Safe
Score 79/100Notification Bar, Sticky Notification Bar, Sticky Welcome Bar for any theme is generally safe to use. 1 past CVE were resolved. Keep it updated.
The gp-notification-bar plugin version 1.1 exhibits a mixed security posture. On the positive side, the static analysis reveals a strong adherence to secure coding practices. There are no dangerous function calls, all SQL queries are prepared, and a high percentage of output is properly escaped. Furthermore, the plugin does not appear to bundle any external libraries, which can sometimes introduce vulnerabilities. The presence of numerous nonce checks and a complete absence of taint analysis findings suggest a proactive approach to preventing common web exploits.
However, the plugin is not without its risks. A significant concern is the existence of one known, unpatched medium-severity vulnerability, specifically a Cross-Site Scripting (XSS) vulnerability. The fact that this vulnerability was last reported in March 2025 suggests it might be a recent discovery or an ongoing issue. While the static analysis did not reveal any immediate XSS flaws in the analyzed code, the historical vulnerability indicates a potential blind spot or a past oversight that could be exploited if the underlying issue remains unresolved. The plugin also makes external HTTP requests, which, while not inherently insecure, can be a vector for certain types of attacks if not handled carefully and are not explicitly checked for sanitization in the provided data.
In conclusion, gp-notification-bar v1.1 shows commendable use of secure coding principles in its current codebase. The robust use of prepared statements and output escaping are strong points. The primary weakness lies in the single unpatched medium-severity XSS vulnerability. While the current code analysis doesn't flag this specific issue, its presence in the vulnerability history necessitates vigilance and prompt patching. The plugin's attack surface, while small with no unprotected entry points, is still present, and the external HTTP requests warrant careful monitoring.
Key Concerns
- Unpatched medium severity CVE
Notification Bar, Sticky Notification Bar, Sticky Welcome Bar for any theme Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Notification Bar, Sticky Notification Bar, Sticky Welcome Bar for any theme <= 1.1 - Authenticated (Administrator+) Stored Cross-Site Scripting
Notification Bar, Sticky Notification Bar, Sticky Welcome Bar for any theme Code Analysis
Output Escaping
Notification Bar, Sticky Notification Bar, Sticky Welcome Bar for any theme Attack Surface
AJAX Handlers 5
WordPress Hooks 13
Maintenance & Trust
Notification Bar, Sticky Notification Bar, Sticky Welcome Bar for any theme Maintenance & Trust
Maintenance Signals
Community Trust
Notification Bar, Sticky Notification Bar, Sticky Welcome Bar for any theme Alternatives
WPFront Notification Bar
wpfront-notification-bar
Easily lets you create a bar on top or bottom to display a notification.
Dima Take Action
dima-take-action
Easily lets you add a Top/Buttom Banner to display a notification and promotion.
ConvBoost Sticky Notification Bar
convboost-sticky-notification-bar
Lightweight sticky top/bottom bar for promos & announcements. CTA, scheduling, exclusions, and live admin preview.
Top Bar
top-bar
Simply the easiest way to add a topbar to your website. Create a notification bar in no-time and show a message and a button to your visitors.
Easy Notification Bar
easy-notification-bar
A simple plugin for displaying a notice at the top of your website that can be closed by the visitor. Completely free and minimal without any upsells.
Notification Bar, Sticky Notification Bar, Sticky Welcome Bar for any theme Developer Profile
3 plugins · 10K total installs
How We Detect Notification Bar, Sticky Notification Bar, Sticky Welcome Bar for any theme
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gp-notification-bar/public/css/pricing.cssgp-notification-bar/public/css/pricing.css?ver=HTML / DOM Fingerprints
gp_nb_notification_bar_close_buttongp_nb_notification_bar_messagegp_nb_notification_bar_wrappergp_nb_notification_bar_content_wrapper<!-- Start: GP Notification Bar --><!-- End: GP Notification Bar -->data-gpnb-transitiondata-gpnb-close-button-textgp_notification_bar