
Welcome Bar Security & Risk Analysis
wordpress.org/plugins/intelly-welcome-barIncrease engagement and drive specific offers to the visitors coming from a specific traffic source. As seen on BetaList and ProductHunt.
Is Welcome Bar Safe to Use in 2026?
Use With Caution
Score 62/100Welcome Bar has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The intelly-welcome-bar plugin exhibits a mixed security posture. While it appears to have a limited attack surface with no immediately apparent unprotected entry points for AJAX, REST API, or shortcodes, several concerning code signals suggest potential weaknesses. The low percentage of properly escaped output (29%) indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, especially given the plugin's history of such issues.
Taint analysis reveals flows with unsanitized paths, which, although not categorized as critical or high severity in this analysis, combined with the poor output escaping, warrants significant concern for potential code injection or manipulation. The presence of file operations and external HTTP requests also opens up avenues for exploitation if not handled with extreme care. The plugin's vulnerability history, featuring three medium-severity CVEs, including Cross-Site Request Forgery (CSRF) and Missing Authorization, strongly suggests recurring security flaws.
Most critically, there is one currently unpatched CVE. This, coupled with the past types of vulnerabilities, points to a pattern of security oversights. While the plugin demonstrates some good practices like using prepared statements for the majority of SQL queries and including a nonce check, these are overshadowed by the risks associated with unescaped output, unsanitized paths, and the unpatched vulnerability. The absence of capability checks on entry points is also a significant concern.
Key Concerns
- Currently unpatched CVE
- Low output escaping percentage
- Unsanitized paths in taint flows
- Missing capability checks
- Vulnerability history with XSS, CSRF, auth issues
- Bundled outdated library (Select2)
Welcome Bar Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Welcome Bar <= 2.0.4 - Authenticated (Administrator+) Stored Cross-Site Scripting
Welcome Bar <= 2.0.3 - Cross-Site Request Forgery
Welcome Bar <= 2.0.3 - Missing Authorization
Welcome Bar Release Timeline
Welcome Bar Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Welcome Bar Attack Surface
WordPress Hooks 16
Scheduled Events 1
Maintenance & Trust
Welcome Bar Maintenance & Trust
Maintenance Signals
Community Trust
Welcome Bar Alternatives
Attention Grabber (Hello Bar Alternative)
attention-grabber-hello-bar-alternative
Grab your visitor's attention and get them to sign up for your email list, or tell them about a specific page they should visit.
Header Bar
responsive-welcome-bar
Header Bar to promote special offers, ebook download, free gifts. Responsive and fully customizable hello bar. 20+ onsite marketing tools included
Apollo Bar
apollo-bar
Apollo Bar is a simple announcements plugin that allows you to create colorful notification bars for your website.
Stella Announcement Bar
stella-announcement-bar
A lightweight, high-conversion announcement bar for WordPress. Perfectly designed for AI and SaaS startup landing pages but compatible with any theme.
My Sticky Bar – Floating Notification Bar & Sticky Header (formerly myStickymenu)
mystickymenu
Create a welcome notification bar for your website. Also, My Sticky Bar plugin can make your menu or header sticky to the top when scrolled 📌
Welcome Bar Developer Profile
11 plugins · 203K total installs
How We Detect Welcome Bar
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/intelly-welcome-bar/assets/css/theme.css/wp-content/plugins/intelly-welcome-bar/assets/css/admin-forms.css/wp-content/plugins/intelly-welcome-bar/assets/css/all-themes.css/wp-content/plugins/intelly-welcome-bar/assets/css/style.css/wp-content/plugins/intelly-welcome-bar/assets/deps/starrr/starrr.js/wp-content/plugins/intelly-welcome-bar/assets/deps/select2/css/core.css/wp-content/plugins/intelly-welcome-bar/assets/deps/select2/select2.min.js/wp-content/plugins/intelly-welcome-bar/assets/deps/qtip/jquery.qtip.min.js+10 more/wp-content/plugins/intelly-welcome-bar/assets/js/library.js/wp-content/plugins/intelly-welcome-bar/assets/js/utility.js/wp-content/plugins/intelly-welcome-bar/assets/js/library.js/wp-content/plugins/intelly-welcome-bar/assets/js/plugin.js?v=2.0.4HTML / DOM Fingerprints
iwpIWB_PLUGIN_PREFIXIWB_PLUGIN_FILEIWB_PLUGIN_SLUGIWB_PLUGIN_NAMEIWB_PLUGIN_VERSIONIWB_PLUGIN_AUTHOR+36 more