Header Bar Security & Risk Analysis

wordpress.org/plugins/responsive-welcome-bar

Header Bar to promote special offers, ebook download, free gifts. Responsive and fully customizable hello bar. 20+ onsite marketing tools included

100 active installs v1.3.0 PHP 7.0+ WP 3.0.1+ Updated Apr 14, 2025
hello-barnotification-barpromo-barpromotion-barwelcome-bar
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Header Bar Safe to Use in 2026?

Generally Safe

Score 100/100

Header Bar has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

The responsive-welcome-bar plugin v1.3.0 exhibits a generally good security posture. The static analysis reveals no dangerous functions, no direct SQL queries without prepared statements, and no observed file operations or external HTTP requests. The presence of two nonces and the complete lack of untainted critical or high-severity taint flows are positive indicators. Furthermore, the plugin has no recorded vulnerability history, suggesting a history of stable and secure releases.

However, a notable concern is the absence of capability checks on its entry points, specifically the two AJAX handlers. While nonces are present, relying solely on them for authentication can be a weakness if they are not implemented with sufficient protection against replay attacks or if the AJAX endpoints themselves do not enforce necessary user roles. The fact that 33% of output is not properly escaped also presents a minor risk of Cross-Site Scripting (XSS) vulnerabilities if the unescaped output is user-controlled. Despite these points, the overall risk is mitigated by the controlled attack surface and the absence of more severe code-level issues.

Key Concerns

  • Missing capability checks on AJAX handlers
  • Unescaped output identified
Vulnerabilities
None known

Header Bar Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Header Bar Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
4 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

67% escaped6 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
update_zb_pb_code (responsive-welcome-bar.php:181)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Header Bar Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_update_zb_pb_coderesponsive-welcome-bar.php:178
noprivwp_ajax_update_zb_pb_coderesponsive-welcome-bar.php:179
WordPress Hooks 4
actionadmin_initresponsive-welcome-bar.php:15
actionadmin_noticesresponsive-welcome-bar.php:46
actionadmin_menuresponsive-welcome-bar.php:82
actionwp_headresponsive-welcome-bar.php:175
Maintenance & Trust

Header Bar Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedApr 14, 2025
PHP min version7.0
Downloads30K

Community Trust

Rating56/100
Number of ratings14
Active installs100
Developer Profile

Header Bar Developer Profile

Zotabox

12 plugins · 4K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
1712 days
View full developer profile
Detection Fingerprints

How We Detect Header Bar

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/responsive-welcome-bar/assets/css/style.css/wp-content/plugins/responsive-welcome-bar/assets/js/main.js
Script Paths
/wp-content/plugins/responsive-welcome-bar/assets/js/main.js
Version Parameters
responsive-welcome-bar/assets/js/main.js?v=

HTML / DOM Fingerprints

CSS Classes
ztb-register-formztb-wrapperztb-logoztb-code-wrapperztb-titleaccount-inputztb-buttonform-group+2 more
Data Attributes
zb-plugin="zb_pb"
JS Globals
ZBT_WP_ADMIN_URLZTB_BASE_URL
FAQ

Frequently Asked Questions about Header Bar