Skill Bar WP Security & Risk Analysis

wordpress.org/plugins/skill-bar-wp

This plugin awesome wordpress progress bar to show skills in percentage at any page or post.

20 active installs v1.0.6 PHP 7.2+ WP 5.4+ Updated Apr 12, 2024
progress-barskill-barskill-bars
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Skill Bar WP Safe to Use in 2026?

Generally Safe

Score 92/100

Skill Bar WP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The skill-bar-wp plugin version 1.0.6 exhibits a generally strong security posture based on the provided static analysis. The plugin demonstrates excellent adherence to secure coding practices, with a very high percentage of output properly escaped and all SQL queries utilizing prepared statements. The absence of dangerous functions, file operations, and external HTTP requests further reinforces this positive assessment. The limited attack surface, consisting of a single shortcode, and the lack of any recorded vulnerabilities in its history are significant strengths.

Despite these positive indicators, there are a few areas that warrant attention. The most notable concern is the complete absence of nonce checks and capability checks across all entry points. While the current attack surface is small and there are no known vulnerabilities, this lack of built-in authorization mechanisms leaves the plugin susceptible to potential attacks if new entry points are introduced or existing ones are misused in the future. This is a common oversight that can lead to security issues if not addressed. The taint analysis reporting zero flows, while good, is also noted in conjunction with the limited analysis scope (0 total flows analyzed), suggesting it might not be fully comprehensive.

In conclusion, skill-bar-wp 1.0.6 is a well-developed plugin with a strong foundation in secure coding. Its strengths lie in output escaping, SQL sanitization, and a clean vulnerability history. However, the critical omission of nonce and capability checks represents a significant potential weakness that should be addressed to ensure long-term security and prevent future exploits.

Key Concerns

  • Missing nonce checks on entry points
  • Missing capability checks on entry points
  • Limited taint analysis scope
Vulnerabilities
None known

Skill Bar WP Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Skill Bar WP Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
92 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

99% escaped93 total outputs
Attack Surface

Skill Bar WP Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[WPSKILLBAR] inc\shortcode.php:82
WordPress Hooks 10
actionadmin_enqueue_scriptsadmin\admin-scripts.php:9
actionsave_postadmin\data-save.php:38
actionsave_postadmin\setting-data-save.php:48
actionadd_meta_boxesadmin\settings.php:5
actionadmin_enqueue_scriptsadmin\settings.php:197
actionadd_meta_boxesadmin\skill-metabox.php:13
actionadd_meta_boxesadmin\skill-metabox.php:174
actioninitadmin\skill-post-type.php:11
actionwp_enqueue_scriptsinc\class-template.php:62
actionplugins_loadedindex.php:28
Maintenance & Trust

Skill Bar WP Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedApr 12, 2024
PHP min version7.2
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Skill Bar WP Developer Profile

WPFound

5 plugins · 110 total installs

90
trust score
Avg Security Score
94/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Skill Bar WP

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/skill-bar-wp/admin/css/admin-style.css/wp-content/plugins/skill-bar-wp/admin/css/font-awesome.css/wp-content/plugins/skill-bar-wp/admin/js/admin-script.js
Script Paths
/wp-content/plugins/skill-bar-wp/admin/js/admin-script.js

HTML / DOM Fingerprints

CSS Classes
skill_settings_optionscolor_settings_option
Data Attributes
name="skill_title_color"name="skill_bar_bg_color"name="skill_bar_percentage_bg_color"name="skill_value_bg_color"name="skill_title_font_size"name="skill_title_font_family"+6 more
FAQ

Frequently Asked Questions about Skill Bar WP