
HashBar – Announcement, Notification Bar & Popup Campaign Security & Risk Analysis
wordpress.org/plugins/hashbar-wp-notification-barCreate Announcement Bars, Notification Bars & Popup Campaigns with countdown timers, A/B testing, smart targeting & analytics.
Is HashBar – Announcement, Notification Bar & Popup Campaign Safe to Use in 2026?
Generally Safe
Score 99/100HashBar – Announcement, Notification Bar & Popup Campaign has a strong security track record. Known vulnerabilities have been patched promptly.
The hashbar-wp-notification-bar plugin exhibits a mixed security posture. While it demonstrates good practices such as a high percentage of prepared SQL statements and properly escaped outputs, several concerning areas require attention. The presence of a significant attack surface with a notable number of unprotected entry points, particularly AJAX handlers and REST API routes, is a primary concern. Additionally, the use of the `unserialize` function, even with good output escaping elsewhere, introduces a potential risk if user-controlled data is ever processed without strict validation and sanitization.
The vulnerability history, with two past medium-severity CVEs related to Cross-Site Scripting (XSS), suggests a recurring pattern of input sanitization weaknesses. Although there are no currently unpatched vulnerabilities, the historical context coupled with the static analysis findings of unsanitized paths in taint flows warrants caution. The presence of one high-severity taint flow, even if not classified as critical, indicates a potentially serious vulnerability that needs immediate investigation. The plugin has strengths in its handling of SQL and output, but the attack surface and historical XSS issues are significant weaknesses.
Key Concerns
- Unprotected AJAX handlers
- Unprotected REST API routes
- Dangerous function: unserialize
- High severity taint flow with unsanitized paths
- Past medium severity XSS vulnerabilities
- Limited nonce checks
HashBar – Announcement, Notification Bar & Popup Campaign Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
HashBar – WordPress Notification Bar <= 1.4.1 - Authenticated (Author+) Stored Cross-Site Scripting
HashBar – WordPress Notification Bar <= 1.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
HashBar – Announcement, Notification Bar & Popup Campaign Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
HashBar – Announcement, Notification Bar & Popup Campaign Attack Surface
AJAX Handlers 7
REST API Routes 52
Shortcodes 2
WordPress Hooks 78
Maintenance & Trust
HashBar – Announcement, Notification Bar & Popup Campaign Maintenance & Trust
Maintenance Signals
Community Trust
HashBar – Announcement, Notification Bar & Popup Campaign Alternatives
Icegram Engage – Popups, Optins, CTAs & lot more…
icegram
Create popups, opt-in forms, and call-to-action messages to capture leads and engage visitors on your WordPress site.
Lightweight High Performance Sticky Bar
lightweight-high-performance-sticky-bar
Add a customizable sticky notification bar with countdown functionality to your website with minimal performance impact.
MAU Top Bar
mau-top-bar
Short Description
Stella Announcement Bar
stella-announcement-bar
A lightweight, high-conversion announcement bar for WordPress. Perfectly designed for AI and SaaS startup landing pages but compatible with any theme.
Smart Popup by Supsystic
popup-by-supsystic
Create targeted popups for lead capture, event notifications, announcements, and promotions — shown at the right time without disrupting your visitors …
HashBar – Announcement, Notification Bar & Popup Campaign Developer Profile
13 plugins · 179K total installs
How We Detect HashBar – Announcement, Notification Bar & Popup Campaign
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/hashbar-wp-notification-bar/assets/images/logo.pngHTML / DOM Fingerprints
hashbar-review-notice-wraphashbar-rating-notice-logohashbar-review-notice-contenthashbar-review-notice-actionhashbar-review-noticehashbar-notice-closedata-already-did/wp-json/plugins/v1/register-routes