نوار اطلاع رسانی | ایمن وب Security & Risk Analysis

wordpress.org/plugins/plugin-notification-bar

نمایش نوار اطلاع رسانی در سایت با سفارشی سازی کامل

10 active installs v1.4 PHP 7.0+ WP 5.4+ Updated Oct 14, 2021
notification-bar
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is نوار اطلاع رسانی | ایمن وب Safe to Use in 2026?

Generally Safe

Score 85/100

نوار اطلاع رسانی | ایمن وب has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The "plugin-notification-bar" v1.4 exhibits a generally good security posture, with no recorded vulnerabilities or CVEs in its history. The static analysis reveals a minimal attack surface with zero entry points that are unprotected, and the code adheres to good practices like using prepared statements for all SQL queries and proper output escaping for the vast majority of outputs. There are no dangerous functions, file operations, or external HTTP requests, further contributing to a low-risk profile.

However, the taint analysis identified two flows with unsanitized paths. While these are not classified as critical or high severity, they represent a potential area of concern. The complete absence of nonce checks and capability checks across all identified code signals is a significant weakness. This lack of authentication and authorization checks on potential entry points, even though they are currently zero in number, means that if new entry points are introduced or if the existing ones are somehow exposed, they would be vulnerable to unauthorized access or manipulation. The plugin's history of no vulnerabilities might be due to its limited functionality or a lack of targeted attacks rather than inherent robust security.

In conclusion, "plugin-notification-bar" v1.4 is in a relatively strong security position due to its clean history and adherence to several security best practices. The primary weaknesses lie in the presence of unsanitized taint flows and the complete lack of nonce and capability checks, which represent potential vulnerabilities that could be exploited if the attack surface were to expand or change. Addressing these specific points would further enhance the plugin's security.

Key Concerns

  • Taint flow with unsanitized path (2 instances)
  • No nonce checks
  • No capability checks
  • Unescaped output (5% of outputs)
Vulnerabilities
None known

نوار اطلاع رسانی | ایمن وب Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

نوار اطلاع رسانی | ایمن وب Release Timeline

v1.3
v1.2
v1.1
v1.0
Code Analysis
Analyzed Mar 17, 2026

نوار اطلاع رسانی | ایمن وب Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
38 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

95% escaped40 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
notification_bar_settings (notification-bar-settings.php:16)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

نوار اطلاع رسانی | ایمن وب Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_menunotification-bar-settings.php:11
actionwp_footernotification-bar.php:2
actionwp_enqueue_scriptsnotification-bar.php:18
actionwp_enqueue_scriptsnotification-bar.php:19
Maintenance & Trust

نوار اطلاع رسانی | ایمن وب Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedOct 14, 2021
PHP min version7.0
Downloads968

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

نوار اطلاع رسانی | ایمن وب Developer Profile

arshojaei

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect نوار اطلاع رسانی | ایمن وب

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/plugin-notification-bar/notification-bar-style.css/wp-content/plugins/plugin-notification-bar/close.png
Script Paths
/wp-content/plugins/plugin-notification-bar/notification-bar-script.js
Version Parameters
plugin-notification-bar/notification-bar-style.css?ver=plugin-notification-bar/notification-bar-script.js?ver=

HTML / DOM Fingerprints

Data Attributes
id="notification_bar"
FAQ

Frequently Asked Questions about نوار اطلاع رسانی | ایمن وب