Lightweight Loading Bar Security & Risk Analysis

wordpress.org/plugins/lightweight-loading-bar

Add a YouTube-style loading bar to your website easily! Extremely lightweight plugin that only adds 810 bytes to your page size.

10 active installs v1.4 PHP + WP 2.8.0+ Updated Nov 17, 2018
lightweight-loading-barloaderloadingloading-barlw-loading-bar
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Lightweight Loading Bar Safe to Use in 2026?

Generally Safe

Score 85/100

Lightweight Loading Bar has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The plugin 'lightweight-loading-bar' version 1.4 exhibits a generally positive security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface. Furthermore, all SQL queries utilize prepared statements, and there are no recorded critical or high-severity vulnerabilities in its history, suggesting diligent maintenance and secure coding practices in the past.

However, a notable concern arises from the output escaping. With 4 total outputs and 0% properly escaped, this indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data that is directly outputted to the browser without proper sanitization can be exploited by attackers. Additionally, the presence of file operations without further context warrants a closer look, as they could potentially be a vector for further attacks if not handled securely.

While the plugin benefits from a clean vulnerability history and a small attack surface, the critical lack of output escaping is a significant weakness that overshadows its strengths. The zero-percent output escaping is a direct and actionable security flaw that needs immediate attention. The plugin's strengths lie in its limited entry points and secure database interaction, but the output sanitization issue presents a clear and present danger.

Key Concerns

  • 0% output escaping
  • File operations present without context
Vulnerabilities
None known

Lightweight Loading Bar Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Lightweight Loading Bar Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Lightweight Loading Bar Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
2
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped4 total outputs
Attack Surface

Lightweight Loading Bar Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionwp_footerlw-loading-bar.php:59
actionlogin_footerlw-loading-bar.php:64
Maintenance & Trust

Lightweight Loading Bar Maintenance & Trust

Maintenance Signals

WordPress version tested5.0.25
Last updatedNov 17, 2018
PHP min version
Downloads1K

Community Trust

Rating20/100
Number of ratings1
Active installs10
Developer Profile

Lightweight Loading Bar Developer Profile

Phillip Roark

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Lightweight Loading Bar

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/lightweight-loading-bar/assets/configText.php

HTML / DOM Fingerprints

CSS Classes
lwloadingbarbar
Data Attributes
id="lw-loading-bar"
JS Globals
LWLoadingbarlwloadingbaroptions
FAQ

Frequently Asked Questions about Lightweight Loading Bar