Hide WP Admin Bar by WP ALL SUPPORT Security & Risk Analysis

wordpress.org/plugins/hide-admin-bar-by-wp-all-support

This plugin will allow you to hide the WordPress admin toolbar from the frontend for all users and based on the user roles.

0 active installs v1.0.3 PHP 5.2.4+ WP 4.0+ Updated Oct 23, 2021
admin-bardisable-admin-barhide-admin-barhide-admin-bar-by-roleswp-admin-bar-hide
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Hide WP Admin Bar by WP ALL SUPPORT Safe to Use in 2026?

Generally Safe

Score 85/100

Hide WP Admin Bar by WP ALL SUPPORT has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The plugin 'hide-admin-bar-by-wp-all-support' version 1.0.3 presents a concerning security posture due to its exposed attack surface. While it demonstrates good practices by avoiding dangerous functions, performing no file operations, and making no external HTTP requests, the complete lack of authentication or permission checks on its two AJAX handlers is a significant weakness. This creates direct entry points for malicious actors to potentially interact with the plugin's functionality without proper authorization. The limited output escaping also poses a risk, as improperly sanitized output can lead to cross-site scripting (XSS) vulnerabilities.

Despite the presence of these weaknesses, the plugin has no recorded vulnerabilities or CVEs, which suggests a history of responsible development or a lack of historical scrutiny. The absence of taint flows further indicates that, in its current state, it might not be easily exploitable for data exfiltration or code execution. However, the uncovered attack surface remains the primary concern. The plugin's strengths lie in its avoidance of common risky coding practices like raw SQL queries and file operations. The main weakness is the unprotected AJAX endpoints and the insufficient output escaping, which could be exploited in conjunction with other factors or through social engineering.

Key Concerns

  • AJAX handlers without authentication checks
  • Insufficient output escaping (24% proper)
Vulnerabilities
None known

Hide WP Admin Bar by WP ALL SUPPORT Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Hide WP Admin Bar by WP ALL SUPPORT Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
25
8 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

24% escaped33 total outputs
Attack Surface
2 unprotected

Hide WP Admin Bar by WP ALL SUPPORT Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_wpas_create_new_custom_ruleadmin\class-wpas-hide-admin-bar-admin.php:11
authwp_ajax_wpas_get_postsadmin\class-wpas-hide-admin-bar-admin.php:12
WordPress Hooks 7
actionadmin_initadmin\class-wpas-hide-admin-bar-admin.php:7
actionadmin_enqueue_scriptsadmin\class-wpas-hide-admin-bar-admin.php:8
actionadmin_menuadmin\class-wpas-hide-admin-bar-admin.php:9
actionadmin_post_wpas_admin_bar_settingsadmin\class-wpas-hide-admin-bar-admin.php:10
actionplugins_loadedincludes\class-wpas-hide-admin-bar.php:28
actionwpincludes\class-wpas-hide-admin-bar.php:29
actionplugins_loadedwpas-hide-admin-bar.php:46
Maintenance & Trust

Hide WP Admin Bar by WP ALL SUPPORT Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedOct 23, 2021
PHP min version5.2.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Hide WP Admin Bar by WP ALL SUPPORT Developer Profile

WP ALL SUPPORT

3 plugins · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Hide WP Admin Bar by WP ALL SUPPORT

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/hide-admin-bar-by-wp-all-support/assets/css/select2.min.css/wp-content/plugins/hide-admin-bar-by-wp-all-support/assets/css/font-awesome.min.css/wp-content/plugins/hide-admin-bar-by-wp-all-support/assets/css/wpas-hide-admin-bar-admin.css/wp-content/plugins/hide-admin-bar-by-wp-all-support/assets/js/select2.min.js/wp-content/plugins/hide-admin-bar-by-wp-all-support/assets/js/wpas-hide-admin-bar.js
Version Parameters
/wp-content/plugins/hide-admin-bar-by-wp-all-support/assets/css/select2.min.css?ver=/wp-content/plugins/hide-admin-bar-by-wp-all-support/assets/css/font-awesome.min.css?ver=/wp-content/plugins/hide-admin-bar-by-wp-all-support/assets/css/wpas-hide-admin-bar-admin.css?ver=/wp-content/plugins/hide-admin-bar-by-wp-all-support/assets/js/select2.min.js?ver=/wp-content/plugins/hide-admin-bar-by-wp-all-support/assets/js/wpas-hide-admin-bar.js?ver=

HTML / DOM Fingerprints

CSS Classes
wpas_admin_bar_settings_wrapis_hide_bar_using_usersrander-select2
Data Attributes
data-placeholder
JS Globals
wpas_hide_admin_bar
REST Endpoints
/wp-admin/admin-ajax.php?action=wpas_create_new_custom_rule/wp-admin/admin-ajax.php?action=wpas_get_posts
FAQ

Frequently Asked Questions about Hide WP Admin Bar by WP ALL SUPPORT