Welcome Bar Security & Risk Analysis

wordpress.org/plugins/intelly-welcome-bar

Increase engagement and drive specific offers to the visitors coming from a specific traffic source. As seen on BetaList and ProductHunt.

10 active installs v2.0.4 PHP + WP 2.7+ Updated Mar 30, 2023
barhello-barhellobarnotification-barproducthunt
62
C · Use Caution
CVEs total3
Unpatched1
Last CVEApr 4, 2025
Safety Verdict

Is Welcome Bar Safe to Use in 2026?

Use With Caution

Score 62/100

Welcome Bar has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

3 known CVEs 1 unpatched Last CVE: Apr 4, 2025Updated 3yr ago
Risk Assessment

The intelly-welcome-bar plugin exhibits a mixed security posture. While it appears to have a limited attack surface with no immediately apparent unprotected entry points for AJAX, REST API, or shortcodes, several concerning code signals suggest potential weaknesses. The low percentage of properly escaped output (29%) indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, especially given the plugin's history of such issues.

Taint analysis reveals flows with unsanitized paths, which, although not categorized as critical or high severity in this analysis, combined with the poor output escaping, warrants significant concern for potential code injection or manipulation. The presence of file operations and external HTTP requests also opens up avenues for exploitation if not handled with extreme care. The plugin's vulnerability history, featuring three medium-severity CVEs, including Cross-Site Request Forgery (CSRF) and Missing Authorization, strongly suggests recurring security flaws.

Most critically, there is one currently unpatched CVE. This, coupled with the past types of vulnerabilities, points to a pattern of security oversights. While the plugin demonstrates some good practices like using prepared statements for the majority of SQL queries and including a nonce check, these are overshadowed by the risks associated with unescaped output, unsanitized paths, and the unpatched vulnerability. The absence of capability checks on entry points is also a significant concern.

Key Concerns

  • Currently unpatched CVE
  • Low output escaping percentage
  • Unsanitized paths in taint flows
  • Missing capability checks
  • Vulnerability history with XSS, CSRF, auth issues
  • Bundled outdated library (Select2)
Vulnerabilities
3 published

Welcome Bar Security Vulnerabilities

CVEs by Year

2 CVEs in 2023
2023
1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
3

3 total CVEs

CVE-2025-32129medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Welcome Bar <= 2.0.4 - Authenticated (Administrator+) Stored Cross-Site Scripting

Apr 4, 2025Unpatched
WF-82a26836-44fc-47cf-ad09-bd3d264e8635-intelly-welcome-barmedium · 4.3Cross-Site Request Forgery (CSRF)

Welcome Bar <= 2.0.3 - Cross-Site Request Forgery

Mar 31, 2023 Patched in 2.0.4 (298d)

Welcome Bar <= 2.0.3 - Missing Authorization

Mar 31, 2023 Patched in 2.0.4 (298d)
Code Analysis
Analyzed Mar 16, 2026

Welcome Bar Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
14 prepared
Unescaped Output
178
72 escaped
Nonce Checks
1
Capability Checks
0
File Operations
7
External Requests
4
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

88% prepared16 total queries

Output Escaping

29% escaped250 total outputs
Data Flows · Security
3 unsanitized

Data Flow Analysis

3 flows3 with unsanitized paths
<Utils> (includes\classes\utils\Utils.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Welcome Bar Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 16
actionplugins_loadedincludes\classes\session\session.php:78
actionshutdownincludes\classes\session\session.php:109
actioniwb_session_garbage_collectionincludes\classes\session\session.php:152
actionwpincludes\classes\session\session.php:162
filterwp_enqueue_scriptsincludes\classes\ui\Tabs.php:8
actionadmin_menuincludes\classes\ui\Tabs.php:10
filterplugin_action_linksincludes\classes\ui\Tabs.php:11
actionadmin_enqueue_scriptsincludes\classes\ui\Tabs.php:13
filtercron_schedulesincludes\classes\utils\Cron.php:9
actioniwb_weekly_scheduled_eventsincludes\classes\utils\Tracking.php:6
filterwp_mail_content_typeincludes\classes\utils\Utils.php:2180
filterwp_headincludes\core.php:23
filterwp_footerincludes\core.php:28
filteradmin_footerincludes\core.php:36
actionadmin_initincludes\install.php:50
actionadmin_noticesindex.php:20

Scheduled Events 1

iwb_session_garbage_collection
Maintenance & Trust

Welcome Bar Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedMar 30, 2023
PHP min version
Downloads6K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Welcome Bar Developer Profile

Data443 Risk Mitigation, Inc.

11 plugins · 203K total installs

67
trust score
Avg Security Score
83/100
Avg Patch Time
411 days
View full developer profile
Detection Fingerprints

How We Detect Welcome Bar

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/intelly-welcome-bar/assets/css/theme.css/wp-content/plugins/intelly-welcome-bar/assets/css/admin-forms.css/wp-content/plugins/intelly-welcome-bar/assets/css/all-themes.css/wp-content/plugins/intelly-welcome-bar/assets/css/style.css/wp-content/plugins/intelly-welcome-bar/assets/deps/starrr/starrr.js/wp-content/plugins/intelly-welcome-bar/assets/deps/select2/css/core.css/wp-content/plugins/intelly-welcome-bar/assets/deps/select2/select2.min.js/wp-content/plugins/intelly-welcome-bar/assets/deps/qtip/jquery.qtip.min.js+10 more
Script Paths
/wp-content/plugins/intelly-welcome-bar/assets/js/library.js/wp-content/plugins/intelly-welcome-bar/assets/js/utility.js/wp-content/plugins/intelly-welcome-bar/assets/js/library.js/wp-content/plugins/intelly-welcome-bar/assets/js/plugin.js
Version Parameters
?v=2.0.4

HTML / DOM Fingerprints

CSS Classes
iwp
JS Globals
IWB_PLUGIN_PREFIXIWB_PLUGIN_FILEIWB_PLUGIN_SLUGIWB_PLUGIN_NAMEIWB_PLUGIN_VERSIONIWB_PLUGIN_AUTHOR+36 more
FAQ

Frequently Asked Questions about Welcome Bar