
Swifty Bar, sticky bar by WPGens Security & Risk Analysis
wordpress.org/plugins/swifty-barAdds sticky bar at the bottom of post that shows category,post title, author, time needed to read article, share buttons and previous/next post links
Is Swifty Bar, sticky bar by WPGens Safe to Use in 2026?
Generally Safe
Score 85/100Swifty Bar, sticky bar by WPGens has a strong security track record. Known vulnerabilities have been patched promptly.
The Swifty Bar plugin presents a concerning security posture, primarily due to its unprotected entry points. The static analysis reveals two AJAX handlers, both of which lack authentication checks. This creates a significant attack surface, allowing any authenticated user to potentially interact with these endpoints without proper authorization. While the plugin demonstrates good practices in other areas, such as using prepared statements for all SQL queries and having no file operations, the absence of capability checks and the low percentage of properly escaped output (23%) are significant weaknesses.
The vulnerability history indicates a past Cross-site Scripting (XSS) vulnerability, which is a common and potentially severe issue. Although there are no currently unpatched CVEs, the historical pattern suggests a predisposition to input validation and output escaping flaws. The limited taint analysis results (0 flows analyzed) make it difficult to definitively assess the risk of complex vulnerabilities, but the presence of unprotected AJAX endpoints and poor output escaping strongly suggests that new XSS vulnerabilities could easily be introduced.
In conclusion, while Swifty Bar benefits from secure SQL handling and a lack of certain risky code patterns, the unprotected AJAX endpoints and inadequate output escaping represent critical security weaknesses that expose users to potential XSS and unauthorized action risks. Addressing these specific issues should be the immediate priority for improving the plugin's security.
Key Concerns
- Unprotected AJAX handlers
- Low percentage of properly escaped output
- No capability checks
- Past XSS vulnerability history
Swifty Bar, sticky bar by WPGens Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Swifty Bar, sticky bar by WPGens <= 1.2.10 - Authenticated (Administrator+) Stored Cross-Site Scripting
Swifty Bar, sticky bar by WPGens Code Analysis
Output Escaping
Swifty Bar, sticky bar by WPGens Attack Surface
AJAX Handlers 2
WordPress Hooks 9
Maintenance & Trust
Swifty Bar, sticky bar by WPGens Maintenance & Trust
Maintenance Signals
Community Trust
Swifty Bar, sticky bar by WPGens Alternatives
AddToAny Share Buttons
add-to-any
Share buttons for WordPress including the AddToAny button, Facebook, Bluesky, Mastodon, WhatsApp, Pinterest, Reddit, many more, and follow icons too.
My Sticky Bar – Floating Notification Bar & Sticky Header (formerly myStickymenu)
mystickymenu
Create a welcome notification bar for your website. Also, My Sticky Bar plugin can make your menu or header sticky to the top when scrolled 📌
Social Sharing Plugin – Sassy Social Share
sassy-social-share
The Simplest and Optimized Social Share buttons. Facebook, X, Reddit, Pinterest, Whatsapp, Grok, ChatGPT, Gab, Gettr and over 100 more.
Social Icons Widget & Block – Social Media Icons & Share Buttons
social-icons-widget-by-wpzoom
Social media icons plugin for WordPress - Add 400+ social icons and share buttons. Gutenberg block, widget & Elementor support. GDPR compliant.
Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More
themeisle-companion
Add modules like share buttons, header & footer scripts, disable comments, reading progress bar, custom fonts, custom login page & more in one plugin.
Swifty Bar, sticky bar by WPGens Developer Profile
4 plugins · 2K total installs
How We Detect Swifty Bar, sticky bar by WPGens
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/swifty-bar/public/css/sb-bar-public.css/wp-content/plugins/swifty-bar/public/js/sb-bar-public.js/wp-content/plugins/swifty-bar/public/js/sb-bar-public.jsswifty-bar/public/css/sb-bar-public.css?ver=swifty-bar/public/js/sb-bar-public.js?ver=HTML / DOM Fingerprints
sb-bar-wrappersb-bar-containerdata-sb-bar-positiondata-sb-bar-themedata-sb-bar-aligndata-sb-bar-btn-textdata-sb-bar-btn-linksb_bar_obj