PACE Pro (EPIC Page Loading Progress Bar) Security & Risk Analysis

wordpress.org/plugins/pace-pro-epic-loading-progress-bar

Adds PACE page loading progress bar to your website, with live preview at the admin panel and dynamic color changing.

10 active installs v1.1 PHP + WP 2.5+ Updated May 21, 2016
barloadingprogresstop
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is PACE Pro (EPIC Page Loading Progress Bar) Safe to Use in 2026?

Generally Safe

Score 85/100

PACE Pro (EPIC Page Loading Progress Bar) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The "pace-pro-epic-loading-progress-bar" plugin v1.1 demonstrates a mixed security posture. On the positive side, it has no recorded vulnerabilities (CVEs), indicating a historically stable codebase. The absence of AJAX handlers, REST API routes, shortcodes, and cron events with unprotected entry points is a significant strength, minimizing the direct attack surface. Furthermore, all SQL queries are properly prepared, and there are no recorded taint flows indicating potential injection vulnerabilities. The presence of a nonce check and the use of prepared statements are good security practices.

However, significant concerns arise from the static analysis. The most critical finding is that 100% of the 11 identified output operations are not properly escaped. This presents a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected into the website and executed in users' browsers. Additionally, the plugin performs a file operation, and while the nature of this operation isn't detailed, it's an area that could potentially be exploited if not handled securely. The lack of capability checks on any potential entry points, though the attack surface is currently zero, means that if new entry points were added in the future without proper authentication, they would be vulnerable.

In conclusion, while the plugin has a clean vulnerability history and a small, mostly protected attack surface, the complete lack of output escaping is a severe weakness that could lead to widespread XSS issues. The file operation also warrants careful review. Given the excellent history, the focus should be on addressing the output escaping immediately to improve its overall security.

Key Concerns

  • 100% of outputs unescaped (XSS risk)
  • File operation present
  • No capability checks
Vulnerabilities
None known

PACE Pro (EPIC Page Loading Progress Bar) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

PACE Pro (EPIC Page Loading Progress Bar) Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

PACE Pro (EPIC Page Loading Progress Bar) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
11
0 escaped
Nonce Checks
1
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

0% escaped11 total outputs
Attack Surface

PACE Pro (EPIC Page Loading Progress Bar) Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_initclass/pacePro.backbone.php:24
actionadmin_menuclass/pacePro.backbone.php:25
filteradmin_enqueue_scriptsclass/pacePro.backbone.php:27
filterwp_enqueue_scriptsclass/pacePro.backbone.php:29
Maintenance & Trust

PACE Pro (EPIC Page Loading Progress Bar) Maintenance & Trust

Maintenance Signals

WordPress version tested4.5.33
Last updatedMay 21, 2016
PHP min version
Downloads6K

Community Trust

Rating84/100
Number of ratings6
Active installs10
Developer Profile

PACE Pro (EPIC Page Loading Progress Bar) Developer Profile

Ahmed Hussein

3 plugins · 30 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect PACE Pro (EPIC Page Loading Progress Bar)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/pace-pro-epic-loading-progress-bar/misc/css/colorpicker.css/wp-content/plugins/pace-pro-epic-loading-progress-bar/misc/js/colorpicker.js/wp-content/plugins/pace-pro-epic-loading-progress-bar/misc/js/live.preview.js/wp-content/plugins/pace-pro-epic-loading-progress-bar/misc/js/pace.min.js
Script Paths
misc/js/colorpicker.jsmisc/js/live.preview.jsmisc/js/pace.min.js

HTML / DOM Fingerprints

CSS Classes
pacepace-progress
FAQ

Frequently Asked Questions about PACE Pro (EPIC Page Loading Progress Bar)