Pagebar2 Security & Risk Analysis

wordpress.org/plugins/pagebar

Pagebar adds a nice page bar to your blog posts, multipaged posts and paged comments.

1K active installs v2.70 PHP 7.4+ WP 5.0+ Updated Jul 31, 2022
commentsnavinavigationpage
84
B · Generally Safe
CVEs total1
Unpatched0
Last CVEJun 15, 2022
Safety Verdict

Is Pagebar2 Safe to Use in 2026?

Mostly Safe

Score 84/100

Pagebar2 is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved. Keep it updated.

1 known CVELast CVE: Jun 15, 2022Updated 3yr ago
Risk Assessment

The 'pagebar' plugin version 2.70 exhibits a generally good security posture based on the static analysis. The absence of any identified dangerous functions, raw SQL queries, or file operations is commendable. Furthermore, the code demonstrates strong output escaping practices (98% properly escaped) and includes necessary nonce and capability checks, indicating attention to preventing common vulnerabilities. The lack of any identified taint flows with unsanitized paths, especially critical or high severity ones, is a positive sign.

Key Concerns

  • One high severity CVE in history
  • One historical CVE (CSRF)
Vulnerabilities
1

Pagebar2 Security Vulnerabilities

CVEs by Year

1 CVE in 2022
2022
Patched Has unpatched

Severity Breakdown

High
1

1 total CVE

CVE-2022-1757high · 8.8Cross-Site Request Forgery (CSRF)

pagebar <= 2.65 - Cross-Site Request Forgery to Settings Update and Cross-Site Scripting

Jun 15, 2022 Patched in 2.66 (587d)
Code Analysis
Analyzed Mar 16, 2026

Pagebar2 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
2
119 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

98% escaped121 total outputs
Data Flows
All sanitized

Data Flow Analysis

3 flows
pboptions (pagebar_options.php:287)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Pagebar2 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 14
filterthe_contentpagebar2.php:161
actioninitpagebar2.php:166
filterquery_varspagebar2.php:194
actionplugins_loadedpagebar2.php:226
actionplugins_loadedpagebar2.php:232
actionadmin_print_scriptspagebar2.php:236
actionadmin_initpagebar2.php:240
actionwp_headpagebar2.php:255
actionwp_print_stylespagebar2.php:256
actionloop_startpagebar2.php:260
actionloop_endpagebar2.php:263
actionwp_footerpagebar2.php:266
actionwp_headpagebar2.php:269
actionadmin_menupagebar_options.php:6
Maintenance & Trust

Pagebar2 Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedJul 31, 2022
PHP min version7.4
Downloads175K

Community Trust

Rating74/100
Number of ratings3
Active installs1K
Developer Profile

Pagebar2 Developer Profile

latz

8 plugins · 2K total installs

69
trust score
Avg Security Score
85/100
Avg Patch Time
587 days
View full developer profile
Detection Fingerprints

How We Detect Pagebar2

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/pagebar/css/twentyten.css/wp-content/plugins/pagebar/css/twentyeleven.css/wp-content/plugins/pagebar/css/twentytwelve.css/wp-content/plugins/pagebar/css/twentythirteen.css/wp-content/plugins/pagebar/css/twentyfourteen.css

HTML / DOM Fingerprints

CSS Classes
pagebar
Data Attributes
data-pb-autoadvance
FAQ

Frequently Asked Questions about Pagebar2