
MB Topbar Security & Risk Analysis
wordpress.org/plugins/mb-topbarThis is a theme demo bar that allow developers / designers to showcase their designs / websites.
Is MB Topbar Safe to Use in 2026?
Generally Safe
Score 85/100MB Topbar has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "mb-topbar" v1.0.0 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and avoids file operations and external HTTP requests. Its vulnerability history is clean, with no recorded CVEs, suggesting a potentially stable and well-maintained codebase in the past.
However, significant security concerns arise from the static analysis. The plugin has a single entry point exposed via the REST API that lacks any permission callbacks. Furthermore, there is a identified taint flow with an unsanitized path, which could potentially be exploited if an attacker can control the data flowing through it. The absence of nonce checks and capability checks across all entry points is also a critical oversight, leaving the plugin vulnerable to CSRF and privilege escalation attacks in conjunction with other identified weaknesses.
In conclusion, while the plugin has a clean vulnerability history and uses prepared statements, the presence of an unprotected REST API endpoint, an unsanitized taint flow, and a complete lack of authorization checks on its entry points present substantial risks. These issues indicate a need for immediate attention and remediation to secure the plugin against potential exploits.
Key Concerns
- Unprotected REST API route
- Flow with unsanitized path
- No nonce checks
- No capability checks
- Low output escaping coverage
MB Topbar Security Vulnerabilities
MB Topbar Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
MB Topbar Attack Surface
REST API Routes 1
WordPress Hooks 11
Maintenance & Trust
MB Topbar Maintenance & Trust
Maintenance Signals
Community Trust
MB Topbar Alternatives
Demonstrator
demonstrator
More than a theme switcher!
IJM Theme Switcher Bar
ijm-theme-bar
Add a theme switcher / theme demo bar to your site. Allows users to switch the theme they see on your site.
JP Theme Switcher Bar
jp-theme-bar
Adds a theme switcher/ theme demo bar to the bottom of your site to allow users to switch the theme they see on your site.
Arya Switch Theme
arya-switch-theme
Allows users to choose and preview all WordPress themes installed without
Theme Demo Switcher and Page Switch Bar
cp-demo-switcher
Showcase your product demo to your website beautifully into one place using CP Theme Demo Switch Bar. No coding required.
MB Topbar Developer Profile
2 plugins · 10 total installs
How We Detect MB Topbar
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mb-topbar/skin/public/styles/adminTopBar.css/wp-content/plugins/mb-topbar/skin/public/scripts/adminTopBar.js/wp-content/plugins/mb-topbar/skin/public/styles/applicationTopBar.css/wp-content/plugins/mb-topbar/skin/public/scripts/applicationTopBar.js/wp-content/plugins/mb-topbar/skin/public/scripts/adminTopBar.js/wp-content/plugins/mb-topbar/skin/public/scripts/applicationTopBar.jsmb-topbar/skin/public/styles/adminTopBar.css?ver=mb-topbar/skin/public/scripts/adminTopBar.js?ver=mb-topbar/skin/public/styles/applicationTopBar.css?ver=mb-topbar/skin/public/scripts/applicationTopBar.js?ver=HTML / DOM Fingerprints
mb_topbar_admin_topbarmb_topbar_admin_topbar_wrapper<!-- Plugin Name: MB Topbar --><!-- Plugin URI: https://github.com/Tihi321/mbwp-topbar --><!-- Description: This plugin implements topbar --><!-- Version: 1.0.0 -->+40 moredata-wp-i18n-messagestopbarOptionsmbwpAdminScriptsmbwpScriptstopbarOptions/mbwp-topbar/v1/api