LeadSquared Website Topbar Security & Risk Analysis

wordpress.org/plugins/leadsquared-website-topbar

Website Topbar helps you direct your website visitors to a web page that matters to you. You can use it to direct your visitors to your product purcha …

10 active installs v1.5 PHP + WP 3.0+ Updated Apr 11, 2014
call-to-actionctalead-bartool-bartop-bar
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is LeadSquared Website Topbar Safe to Use in 2026?

Generally Safe

Score 85/100

LeadSquared Website Topbar has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The plugin 'leadsquared-website-topbar' v1.5 exhibits a mixed security posture. On one hand, the absence of known CVEs and a clean vulnerability history is a positive sign, suggesting a generally well-maintained codebase. The static analysis also indicates no direct use of dangerous functions, no file operations, and no external HTTP requests, which reduces common attack vectors. Furthermore, all SQL queries are utilizing prepared statements, a crucial practice for preventing SQL injection vulnerabilities. However, a significant concern arises from the output escaping, with 0% of 41 total outputs being properly escaped. This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected into the website through the plugin's output. The taint analysis also revealed one flow with unsanitized paths, which, although not classified as critical or high severity, warrants attention. The complete lack of nonce and capability checks on entry points, coupled with no documented security checks on AJAX handlers or REST API routes, further exacerbates the XSS risk and opens the door to potential unauthorized actions if an attacker can find a way to bypass these missing checks.

Key Concerns

  • Unescaped output
  • Flows with unsanitized paths
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

LeadSquared Website Topbar Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

LeadSquared Website Topbar Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
41
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped41 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<top_nav_bar_admin_page_sttings> (inc\top_nav_bar_admin_page_sttings.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

LeadSquared Website Topbar Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_enqueue_scriptsindex.php:18
actioninitindex.php:19
actionwp_enqueue_scriptsindex.php:59
actionwp_headindex.php:80
actionadmin_menuindex.php:119
Maintenance & Trust

LeadSquared Website Topbar Maintenance & Trust

Maintenance Signals

WordPress version tested3.7.41
Last updatedApr 11, 2014
PHP min version
Downloads2K

Community Trust

Rating80/100
Number of ratings3
Active installs10
Developer Profile

LeadSquared Website Topbar Developer Profile

LeadSquared

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect LeadSquared Website Topbar

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/leadsquared-website-topbar/css/jquery-ui-timepicker-addon.css/wp-content/plugins/leadsquared-website-topbar/css/innerstyle.css/wp-content/plugins/leadsquared-website-topbar/js/datetimepicker/jquery-ui-timepicker-addon.js/wp-content/plugins/leadsquared-website-topbar/js/jscolor/jscolor.js/wp-content/plugins/leadsquared-website-topbar/js/admin_script.js/wp-content/plugins/leadsquared-website-topbar/js/lscookie.js/wp-content/plugins/leadsquared-website-topbar/js/our_script.js/wp-content/plugins/leadsquared-website-topbar/css/nav_bar_style.css+1 more
Script Paths
http://code.jquery.com/ui/1.10.3/themes/smoothness/jquery-ui.csshttp://code.jquery.com/ui/1.10.3/jquery-ui.js
Version Parameters
leadsquared-website-topbar/css/jquery-ui-timepicker-addon.css?ver=leadsquared-website-topbar/css/innerstyle.css?ver=leadsquared-website-topbar/js/datetimepicker/jquery-ui-timepicker-addon.js?ver=leadsquared-website-topbar/js/jscolor/jscolor.js?ver=leadsquared-website-topbar/js/admin_script.js?ver=leadsquared-website-topbar/js/lscookie.js?ver=leadsquared-website-topbar/js/our_script.js?ver=leadsquared-website-topbar/css/nav_bar_style.css?ver=leadsquared-website-topbar/css/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
ls-sticky-bar
HTML Comments
<!--LeadSquared Website Top Bar Starts Here--><!--LeadSquared Website Top Bar Ends Here-->
Data Attributes
data-ls-iddata-ls-expiry
JS Globals
LeadSquaredlsq_global_cookie_duration
FAQ

Frequently Asked Questions about LeadSquared Website Topbar