Tambar – Bottom Admin Bar Security & Risk Analysis

wordpress.org/plugins/tambar

The sticky header is a widely used feature on many websites, but it can conflict with the WordPress admin bar. Tambar effectively resolves this issue!

100 active installs v3.0.3 PHP 7.4+ WP 6.0+ Updated Dec 5, 2025
adminadminbarbarbottom-bartoolbar
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Tambar – Bottom Admin Bar Safe to Use in 2026?

Generally Safe

Score 100/100

Tambar – Bottom Admin Bar has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the 'tambar' plugin version 3.0.3 appears to have a strong security posture. The code analysis indicates no identified dangerous functions, SQL queries are all prepared, and all output is properly escaped. Furthermore, there are no file operations, external HTTP requests, or unsanitized taint flows detected, which are common sources of vulnerabilities. The plugin also seems to implement at least one capability check, a positive security practice.

However, the lack of nonce checks on AJAX handlers and REST API routes, combined with zero detected entry points, is peculiar. While this could mean the plugin has no such entry points, it's more likely that the static analysis tooling did not identify them or they are implemented in a way not recognized by the tool. The complete absence of any recorded vulnerabilities, including historical ones, suggests either a very mature and secure plugin or a lack of past rigorous security auditing. This could also mean the plugin is relatively new or has not been a target. Overall, the plugin demonstrates good coding practices, but the lack of observable authentication on potential interaction points (if they exist and were missed) and the complete absence of vulnerability history warrant careful consideration.

Key Concerns

  • No nonce checks identified on entry points
  • No capability checks on identified entry points
Vulnerabilities
None known

Tambar – Bottom Admin Bar Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Tambar – Bottom Admin Bar Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
15 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped15 total outputs
Attack Surface

Tambar – Bottom Admin Bar Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionadmin_menutambar.php:89
actionadmin_inittambar.php:100
actionwp_enqueue_scriptstambar.php:188
filtershow_admin_bartambar.php:196
filterbody_classtambar.php:225
actionwp_before_admin_bar_rendertambar.php:259
Maintenance & Trust

Tambar – Bottom Admin Bar Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 5, 2025
PHP min version7.4
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs100
Developer Profile

Tambar – Bottom Admin Bar Developer Profile

Yan Metelitsa

4 plugins · 220 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Tambar – Bottom Admin Bar

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tambar/assets/css/tambar.css/wp-content/plugins/tambar/assets/js/tambar.js
Script Paths
/wp-content/plugins/tambar/assets/js/tambar.js
Version Parameters
tambar-styles?ver=tambar-scripts?ver=

HTML / DOM Fingerprints

CSS Classes
tambar-desktop-bottomtambar-desktop-toptambar-mobile-bottomtambar-mobile-toptambar-switcher-desktop-lefttambar-switcher-desktop-righttambar-switcher-mobile-lefttambar-switcher-mobile-right+1 more
Data Attributes
data-tambar-option
JS Globals
tambarToggle
Shortcode Output
<div id="tambar-switcher" onclick="tambarToggle()"></div>
FAQ

Frequently Asked Questions about Tambar – Bottom Admin Bar