
LeadSquared Website Topbar Security & Risk Analysis
wordpress.org/plugins/leadsquared-website-topbarWebsite Topbar helps you direct your website visitors to a web page that matters to you. You can use it to direct your visitors to your product purcha …
Is LeadSquared Website Topbar Safe to Use in 2026?
Generally Safe
Score 85/100LeadSquared Website Topbar has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'leadsquared-website-topbar' v1.5 exhibits a mixed security posture. On one hand, the absence of known CVEs and a clean vulnerability history is a positive sign, suggesting a generally well-maintained codebase. The static analysis also indicates no direct use of dangerous functions, no file operations, and no external HTTP requests, which reduces common attack vectors. Furthermore, all SQL queries are utilizing prepared statements, a crucial practice for preventing SQL injection vulnerabilities. However, a significant concern arises from the output escaping, with 0% of 41 total outputs being properly escaped. This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected into the website through the plugin's output. The taint analysis also revealed one flow with unsanitized paths, which, although not classified as critical or high severity, warrants attention. The complete lack of nonce and capability checks on entry points, coupled with no documented security checks on AJAX handlers or REST API routes, further exacerbates the XSS risk and opens the door to potential unauthorized actions if an attacker can find a way to bypass these missing checks.
Key Concerns
- Unescaped output
- Flows with unsanitized paths
- No nonce checks
- No capability checks
LeadSquared Website Topbar Security Vulnerabilities
LeadSquared Website Topbar Code Analysis
Output Escaping
Data Flow Analysis
LeadSquared Website Topbar Attack Surface
WordPress Hooks 5
Maintenance & Trust
LeadSquared Website Topbar Maintenance & Trust
Maintenance Signals
Community Trust
LeadSquared Website Topbar Alternatives
Mobile Contact Bar
mobile-contact-bar
Allow your visitors to contact you via mobile phones, or access your site's pages instantly.
MC4WP: Mailchimp Top Bar
mailchimp-top-bar
Adds a Mailchimp opt-in form to the top or bottom of your WordPress site.
WP CTA – Sticky CTA Builder, Generate Leads, Promote Sales
easy-sticky-sidebar
WordPress Call To Action plugin to promote content, increase sales and leads. Easy to use and includes 3 professional, flexible templates.
TopBar Call To Action
topbar-call-to-action
Allow user to add upsales or any call to actions with TopBar Call To Action.
Call to Action Block by WPPOOL
call-to-action-block-wppool
Add a stunning call to action (CTA) block to your WordPress post or page using 10+ prebuilt call to action layouts for Gutenberg.
LeadSquared Website Topbar Developer Profile
1 plugin · 10 total installs
How We Detect LeadSquared Website Topbar
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/leadsquared-website-topbar/css/jquery-ui-timepicker-addon.css/wp-content/plugins/leadsquared-website-topbar/css/innerstyle.css/wp-content/plugins/leadsquared-website-topbar/js/datetimepicker/jquery-ui-timepicker-addon.js/wp-content/plugins/leadsquared-website-topbar/js/jscolor/jscolor.js/wp-content/plugins/leadsquared-website-topbar/js/admin_script.js/wp-content/plugins/leadsquared-website-topbar/js/lscookie.js/wp-content/plugins/leadsquared-website-topbar/js/our_script.js/wp-content/plugins/leadsquared-website-topbar/css/nav_bar_style.css+1 morehttp://code.jquery.com/ui/1.10.3/themes/smoothness/jquery-ui.csshttp://code.jquery.com/ui/1.10.3/jquery-ui.jsleadsquared-website-topbar/css/jquery-ui-timepicker-addon.css?ver=leadsquared-website-topbar/css/innerstyle.css?ver=leadsquared-website-topbar/js/datetimepicker/jquery-ui-timepicker-addon.js?ver=leadsquared-website-topbar/js/jscolor/jscolor.js?ver=leadsquared-website-topbar/js/admin_script.js?ver=leadsquared-website-topbar/js/lscookie.js?ver=leadsquared-website-topbar/js/our_script.js?ver=leadsquared-website-topbar/css/nav_bar_style.css?ver=leadsquared-website-topbar/css/style.css?ver=HTML / DOM Fingerprints
ls-sticky-bar<!--LeadSquared Website Top Bar Starts Here--><!--LeadSquared Website Top Bar Ends Here-->data-ls-iddata-ls-expiryLeadSquaredlsq_global_cookie_duration