Smartarget Message Bar Security & Risk Analysis

wordpress.org/plugins/smartarget-message-bar

Display a message bar on your page

0 active installs v1.5 PHP 5.2.4+ WP 3.0.1+ Updated Feb 13, 2026
announcementcookiemessagepopupsale
79
B · Generally Safe
CVEs total1
Unpatched1
Last CVEMay 30, 2024
Safety Verdict

Is Smartarget Message Bar Safe to Use in 2026?

Mostly Safe

Score 79/100

Smartarget Message Bar is generally safe to use. 1 past CVE were resolved. Keep it updated.

1 known CVE 1 unpatched Last CVE: May 30, 2024Updated 1mo ago
Risk Assessment

The static analysis of the 'smartarget-message-bar' plugin v1.5 reveals a generally good security posture regarding code practices. There are no identified dangerous functions, all SQL queries utilize prepared statements, and output is properly escaped. The absence of file operations and external HTTP requests also contributes positively. However, a significant concern is the complete lack of any capability checks or nonce checks across all entry points. While the current static analysis reports zero unprotected entry points, this could be misleading if those entry points are intended to be protected by something other than capability or nonce checks, which are absent. The vulnerability history presents a major red flag: one known, unpatched CVE with a medium severity. This indicates a recent, exploitable flaw that has not been addressed by the developers. The common vulnerability type of Cross-site Scripting further highlights a potential for user data compromise or unauthorized actions within the WordPress environment.

Key Concerns

  • Unpatched CVE present
  • Missing capability checks on entry points
  • Missing nonce checks on entry points
Vulnerabilities
1

Smartarget Message Bar Security Vulnerabilities

CVEs by Year

1 CVE in 2024 · unpatched
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-35646medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Smartarget Message Bar <= 1.4 - Authenticated (Admin+) Stored Cross-Site Scripting

May 30, 2024Unpatched
Code Analysis
Analyzed Mar 17, 2026

Smartarget Message Bar Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped4 total outputs
Attack Surface

Smartarget Message Bar Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionplugins_loadedincludes\class-smartarget-message-bar.php:142
actionadmin_enqueue_scriptsincludes\class-smartarget-message-bar.php:157
actionadmin_enqueue_scriptsincludes\class-smartarget-message-bar.php:158
actionadmin_menuincludes\class-smartarget-message-bar.php:160
actionadmin_initincludes\class-smartarget-message-bar.php:165
actionwp_enqueue_scriptsincludes\class-smartarget-message-bar.php:179
actionwp_enqueue_scriptsincludes\class-smartarget-message-bar.php:180
Maintenance & Trust

Smartarget Message Bar Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 13, 2026
PHP min version5.2.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Smartarget Message Bar Developer Profile

Erez Hadas-Sonnenschein

21 plugins · 2K total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Smartarget Message Bar

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/smartarget-message-bar/assets/css/smartarget-message-bar.css/wp-content/plugins/smartarget-message-bar/assets/js/smartarget-message-bar.js
Script Paths
https://smartarget.online/wp-dashboard/package.jshttps://smartarget.online/loader.js
Version Parameters
smartarget-message-bar/assets/css/smartarget-message-bar.css?ver=smartarget-message-bar/assets/js/smartarget-message-bar.js?ver=

HTML / DOM Fingerprints

CSS Classes
smartarget-message-bar-wrappersmartarget-message-bar-closesmartarget-message-bar-text
HTML Comments
<!-- Smartarget Message Bar --><!-- End Smartarget Message Bar -->
Data Attributes
data-smartarget-user-id
JS Globals
Smartarget
Shortcode Output
[smartarget_message_bar]
FAQ

Frequently Asked Questions about Smartarget Message Bar