
Mobile Contact Bar Security & Risk Analysis
wordpress.org/plugins/mobile-contact-barAllow your visitors to contact you via mobile phones, or access your site's pages instantly.
Is Mobile Contact Bar Safe to Use in 2026?
Generally Safe
Score 99/100Mobile Contact Bar has a strong security track record. Known vulnerabilities have been patched promptly.
The mobile-contact-bar plugin, version 3.0.5, presents a mixed security posture. While it boasts a small attack surface and no identified critical or high severity taint flows, significant concerns arise from its handling of SQL queries and output escaping. All five SQL queries are executed without prepared statements, indicating a substantial risk of SQL injection vulnerabilities. Furthermore, the 13% of outputs that are not properly escaped introduce a potential for Cross-Site Scripting (XSS) attacks. The vulnerability history, including a past medium-severity XSS vulnerability, reinforces these concerns and suggests a pattern of inadequate input sanitization and output encoding, despite the absence of currently unpatched CVEs. The presence of a nonce check on the sole AJAX handler is a positive sign for that specific entry point, but the lack of capability checks on any entry points means that any user, regardless of role, could potentially interact with the AJAX handler. Overall, the plugin has strengths in its limited attack surface and recent vulnerability patching, but the prevalent use of raw SQL and unescaped output are significant weaknesses that require immediate attention.
Key Concerns
- All SQL queries use raw SQL without prepared statements
- Significant percentage of outputs are not properly escaped
- Past medium severity vulnerability (XSS)
- No capability checks on entry points
Mobile Contact Bar Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Mobile Contact Bar <= 3.0.4 - Authenticated (Admin+) Stored Cross-Site Scripting
Mobile Contact Bar Code Analysis
SQL Query Safety
Output Escaping
Mobile Contact Bar Attack Surface
AJAX Handlers 1
WordPress Hooks 42
Maintenance & Trust
Mobile Contact Bar Maintenance & Trust
Maintenance Signals
Community Trust
Mobile Contact Bar Alternatives
AddToAny Share Buttons
add-to-any
Share buttons for WordPress including the AddToAny button, Facebook, Bluesky, Mastodon, WhatsApp, Pinterest, Reddit, many more, and follow icons too.
Astra Widgets
astra-widgets
Quickest solution to add widgets like Address, Social Profiles and List icons on a website built with Astra.
Social Icons Widget & Block – Social Media Icons & Share Buttons
social-icons-widget-by-wpzoom
Social media icons plugin for WordPress - Add 400+ social icons and share buttons. Gutenberg block, widget & Elementor support. GDPR compliant.
Social Media Share Buttons & Social Sharing Icons
ultimate-social-media-icons
Share buttons and pop up share icons for social media sharing
Lightweight Social Icons
lightweight-social-icons
Looking to add simple social icons to your widget areas? Choose the size and color of your icons, and then choose from 47 different social profiles.
Mobile Contact Bar Developer Profile
1 plugin · 10K total installs
How We Detect Mobile Contact Bar
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mobile-contact-bar/assets/css/style.css/wp-content/plugins/mobile-contact-bar/assets/js/app.js/wp-content/plugins/mobile-contact-bar/assets/js/app.jsmobile-contact-bar/assets/css/style.css?ver=mobile-contact-bar/assets/js/app.js?ver=HTML / DOM Fingerprints
mobile-contact-barmobile_contact_bar