
LCT Admin Bar on Bottom Security & Risk Analysis
wordpress.org/plugins/lct-admin-bar-on-bottomThis plugin sticks the Admin Bar to the bottom of your screen! You can choose to make this change on the front-end, back-end or both
Is LCT Admin Bar on Bottom Safe to Use in 2026?
Generally Safe
Score 85/100LCT Admin Bar on Bottom has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "lct-admin-bar-on-bottom" plugin version 4.2.2 exhibits a generally strong security posture based on the provided static analysis. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, significantly limiting the attack surface. Furthermore, the absence of dangerous functions, SQL queries not using prepared statements, file operations, and external HTTP requests are all positive indicators of secure coding practices. The vulnerability history being empty further reinforces this positive outlook.
However, a critical concern arises from the output escaping analysis. With 6 total outputs and 0% properly escaped, this indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any dynamic data displayed to users, particularly within the admin area, could be manipulated to inject malicious scripts. While there's a single capability check, the lack of nonce checks on potential entry points (though none are explicitly identified in the attack surface) could be a weakness if new entry points are introduced in future versions. The absence of taint analysis results might suggest a limited scope or that no flows were detected by the tool, but it doesn't negate the clear risk from unescaped output.
In conclusion, the plugin's limited attack surface and lack of known vulnerabilities are commendable. The primary and most significant weakness is the complete lack of output escaping, presenting a substantial risk of XSS. This issue needs immediate attention to ensure user data and site integrity are protected.
Key Concerns
- Unescaped output detected
LCT Admin Bar on Bottom Security Vulnerabilities
LCT Admin Bar on Bottom Code Analysis
Output Escaping
LCT Admin Bar on Bottom Attack Surface
WordPress Hooks 6
Maintenance & Trust
LCT Admin Bar on Bottom Maintenance & Trust
Maintenance Signals
Community Trust
LCT Admin Bar on Bottom Alternatives
Hide Admin Bar
hide-admin-bar
Hide the Admin Bar in WordPress 3.1+.
Hide Admin Bar Based on User Roles
hide-admin-bar-based-on-user-roles
Hide the WordPress Admin Bar for specific user roles, capabilities, devices, pages, or time windows. The ultimate toolbar control plugin for membershi …
Hide Admin Bar from Non-Admins
hide-admin-bar-from-non-admins
Hides the WordPress toolbar (admin bar) for all non-admin users. Simple plugin with no settings to configure.
Bricks Navigator
brickslabs-bricks-navigator
Adds quick links in the WordPress admin bar for users of Bricks theme.
Hide Admin Toolbar
hide-admin-toolbar
This plugin is used to hide admin toolbar from website. It will hide that bar when you are logged in and viewing the site.
LCT Admin Bar on Bottom Developer Profile
4 plugins · 120 total installs
How We Detect LCT Admin Bar on Bottom
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lct-admin-bar-on-bottom/assets/css/labob_back.css/wp-content/plugins/lct-admin-bar-on-bottom/assets/css/labob_profile.css/wp-content/plugins/lct-admin-bar-on-bottom/assets/css/labob_front.cssHTML / DOM Fingerprints
lct-admin-bar-on-bottomname="lct_admin_bar_on_bottom_front"name="lct_admin_bar_on_bottom_back"