News Bar Plus Security & Risk Analysis

wordpress.org/plugins/news-bar

News bar with latest tweets or posts from specified blog category. Extended version.

10 active installs v2.0.0 PHP + WP 3.0+ Updated May 26, 2012
newsnews-tickerticker
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is News Bar Plus Safe to Use in 2026?

Generally Safe

Score 85/100

News Bar Plus has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 13yr ago
Risk Assessment

The "news-bar" plugin version 2.0.0 exhibits a seemingly strong security posture based on the provided static analysis and vulnerability history. The absence of any identified entry points like AJAX handlers, REST API routes, or shortcodes significantly limits the plugin's attack surface. Furthermore, the analysis shows no dangerous functions, no file operations, no external HTTP requests, and all SQL queries are prepared, indicating good development practices in these areas. The lack of any recorded vulnerabilities or CVEs further suggests a history of secure development.

However, a critical concern emerges from the output escaping analysis. With 118 outputs and 0% properly escaped, this indicates a very high risk of Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data, or data fetched from an untrusted source and displayed by the plugin, could be manipulated to inject malicious scripts. The complete absence of nonce and capability checks, while not immediately exploitable due to the lack of entry points, would be a significant weakness if any entry points were introduced or discovered. The bundled outdated jQuery library, while not necessarily a direct vulnerability in this specific version, is a potential risk factor as it might contain known vulnerabilities that could be exploited if its functionality were ever leveraged by the plugin.

Key Concerns

  • 0% properly escaped output
  • Bundled outdated jQuery v1.6.4
  • 0 capability checks
  • 0 nonce checks
Vulnerabilities
None known

News Bar Plus Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

News Bar Plus Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
118
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

jQuery1.6.4

Output Escaping

0% escaped118 total outputs
Attack Surface

News Bar Plus Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_menuclasses\gn-plugin-framework.class.php:87
actionadmin_initclasses\gn-plugin-framework.class.php:90
actioninitclasses\gn-plugin-framework.class.php:97
actioninitclasses\gn-plugin-framework.class.php:100
actionadmin_initclasses\gn-plugin-framework.class.php:103
actioninitincludes\admin-bar.php:18
actionwp_footerincludes\frontend.php:58
actioninitincludes\post-type.php:42
Maintenance & Trust

News Bar Plus Maintenance & Trust

Maintenance Signals

WordPress version tested4.0.38
Last updatedMay 26, 2012
PHP min version
Downloads10K

Community Trust

Rating74/100
Number of ratings3
Active installs10
Developer Profile

News Bar Plus Developer Profile

Vova

4 plugins · 400K total installs

69
trust score
Avg Security Score
86/100
Avg Patch Time
403 days
View full developer profile
Detection Fingerprints

How We Detect News Bar Plus

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/news-bar/assets/css/frontend.css/wp-content/plugins/news-bar/assets/skins//wp-content/plugins/news-bar/assets/css/backend.css/wp-content/plugins/news-bar/assets/js/frontend.js/wp-content/plugins/news-bar/assets/js/form.js/wp-content/plugins/news-bar/assets/js/backend.js
Script Paths
/wp-content/plugins/news-bar/assets/js/frontend.js
Version Parameters
news-bar/assets/css/frontend.css?ver=news-bar/assets/skins/news-bar/assets/css/backend.css?ver=news-bar/assets/js/frontend.js?ver=news-bar/assets/js/form.js?ver=news-bar/assets/js/backend.js?ver=

HTML / DOM Fingerprints

CSS Classes
news-bar-plusnews-bar-plus-shellnews-bar-plus-tickernews-bar-plus-itemnews-bar-plus-social-icons
Data Attributes
data-news-bar-plus-animationdata-news-bar-plus-speeddata-news-bar-plus-delay
JS Globals
nbplus_social_iconsnbplus_display_tickernbplus_display
FAQ

Frequently Asked Questions about News Bar Plus