Hello Bar Popup Builder Security & Risk Analysis

wordpress.org/plugins/hellobar

Easily add a Popup to your WordPress site with the official HelloBar WordPress plugin.

3K active installs v1.5.3 PHP 7.4+ WP 5.0+ Updated Jun 4, 2026
conversionmarketingnewsletterpopup-builderwoocommerce
99
A · Safe
CVEs total1
Unpatched0
Last CVEFeb 18, 2026
Safety Verdict

Is Hello Bar Popup Builder Safe to Use in 2026?

Generally Safe

Score 99/100

Hello Bar Popup Builder has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Feb 18, 2026Updated 2mo ago
Risk Assessment

The "hellobar" plugin version 1.5.1 exhibits a strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly minimizes the plugin's attack surface. Furthermore, the code's adherence to secure coding practices, such as the use of prepared statements for all SQL queries and the presence of nonce and capability checks, indicates a proactive approach to security. The lack of any known vulnerabilities in its history is also a positive indicator.

While the overall security is commendable, a minor concern arises from the output escaping. With 60% of outputs properly escaped, there's a remaining 40% that could potentially lead to cross-site scripting (XSS) vulnerabilities if the unescaped data originates from untrusted sources. The absence of taint analysis results means we cannot definitively rule out complex, chained vulnerabilities, but the limited attack surface and adherence to basic security checks make this less probable.

In conclusion, "hellobar" v1.5.1 appears to be a secure plugin with a strong foundation in secure coding. The primary area for improvement lies in ensuring all output is consistently and properly escaped to mitigate any potential XSS risks. The plugin's clean history and minimal attack surface are significant strengths.

Key Concerns

  • Percentage of unescaped output is concerning
Vulnerabilities
1 published

Hello Bar Popup Builder Security Vulnerabilities

CVEs by Year

1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2026-39666medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Hello Bar Popup Builder <= 1.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

Feb 18, 2026 Patched in 1.5.2 (111d)
Version History

Hello Bar Popup Builder Release Timeline

v1.5.3Current
v1.5.2
v1.5.11 CVE
v1.51 CVE
v0.31 CVE
Code Analysis
Analyzed Mar 16, 2026

Hello Bar Popup Builder Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
9 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

60% escaped15 total outputs
Attack Surface

Hello Bar Popup Builder Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionadmin_menuhellobar.php:49
actionwp_headhellobar.php:53
actionwp_headhellobar.php:54
actionwp_print_footer_scriptshellobar.php:57
actionwp_print_footer_scriptshellobar.php:58
actionwp_footerhellobar.php:60
actionwp_footerhellobar.php:61
actionadmin_enqueue_scriptshellobar.php:67
actionadmin_enqueue_scriptshellobar.php:68
actionplugins_loadedhellobar.php:217
Maintenance & Trust

Hello Bar Popup Builder Maintenance & Trust

Maintenance Signals

WordPress version tested7.0.2
Last updatedJun 4, 2026
PHP min version7.4
Downloads208K

Community Trust

Rating32/100
Number of ratings7
Active installs3K
Developer Profile

Hello Bar Popup Builder Developer Profile

telepathy

5 plugins · 4K total installs

71
trust score
Avg Security Score
88/100
Avg Patch Time
111 days
View full developer profile
Detection Fingerprints

How We Detect Hello Bar Popup Builder

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/hellobar/assets/css/hellobar-admin.css/wp-content/plugins/hellobar/assets/js/jquery.qtip.min.js
Script Paths
https://my.hellobar.com/
Version Parameters
jquery.qtip.min.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-hellobar-api-keydata-hellobar-id
JS Globals
window._hellobar_wordpress_tags
FAQ

Frequently Asked Questions about Hello Bar Popup Builder