TinyBar – Display notification bar, banner, announcement at the top or bottom of your website Security & Risk Analysis

wordpress.org/plugins/tiny-bar

Display a notification bar, banner at the top or bottom of your website. Display amazing discount announcement and create urgency among site visitors.

90 active installs v2.3.2 PHP 7.2+ WP 5.4+ Updated Jan 20, 2026
announcementbannerbarnoticenotification
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is TinyBar – Display notification bar, banner, announcement at the top or bottom of your website Safe to Use in 2026?

Generally Safe

Score 100/100

TinyBar – Display notification bar, banner, announcement at the top or bottom of your website has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The "tiny-bar" plugin v2.3.2 exhibits a generally strong security posture with no recorded vulnerabilities or critical issues found in static and taint analysis. The absence of known CVEs and the clean vulnerability history are positive indicators of the plugin's maintainers' attention to security. Furthermore, the plugin effectively uses prepared statements for all SQL queries, which is a crucial defense against SQL injection. The very limited attack surface and the presence of capability checks on entry points also contribute positively to its security.

However, there are a few areas of concern. The presence of the `unserialize` function, especially without clear input sanitization or validation, is a significant risk, as it can lead to Remote Code Execution (RCE) if malicious data is processed. The relatively low percentage of properly escaped output (37%) suggests a risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not adequately sanitized before being displayed. The bundled Freemius library, while not explicitly flagged as outdated, should be monitored for potential vulnerabilities. Overall, the plugin is well-maintained with a clean history, but the use of `unserialize` and the low output escaping rate warrant careful review and potential remediation.

Key Concerns

  • Dangerous function: unserialize detected
  • Low output escaping percentage (37%)
  • Bundled library Freemius v1.0 (potential for outdated issues)
Vulnerabilities
None known

TinyBar – Display notification bar, banner, announcement at the top or bottom of your website Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

TinyBar – Display notification bar, banner, announcement at the top or bottom of your website Release Timeline

v2.3.2Current
v2.3.1
v2.3
v2.2
v2.1
v2.0
v1.9
v1.8
v1.7
v1.6
v1.5
v1.4
v1.3
v1.2
v1.1
v1.0
Code Analysis
Analyzed Mar 16, 2026

TinyBar – Display notification bar, banner, announcement at the top or bottom of your website Code Analysis

Dangerous Functions
3
Raw SQL Queries
0
0 prepared
Unescaped Output
19
11 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
1

Dangerous Functions Found

unserialize$this->settings = stripslashes_deep( unserialize( get_option('hmtb_content_settings') ) );common\content.php:28
unserialize$this->settings = stripslashes_deep( unserialize( get_option('hmtb_general_settings') ) );common\general.php:28
unserialize$this->settings = stripslashes_deep( unserialize( get_option('hmtb_styles_settings') ) );common\styles.php:28

Bundled Libraries

Freemius1.0

Output Escaping

37% escaped30 total outputs
Attack Surface

TinyBar – Display notification bar, banner, announcement at the top or bottom of your website Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionplugins_loadedinc\cls-hm-tiny-bar-master.php:24
actionadmin_enqueue_scriptsinc\cls-hm-tiny-bar-master.php:45
actionadmin_menuinc\cls-hm-tiny-bar-master.php:46
actionwp_enqueue_scriptsinc\cls-hm-tiny-bar-master.php:52
actionwp_body_openinc\cls-hm-tiny-bar-master.php:55
actionwp_footerinc\cls-hm-tiny-bar-master.php:57
filterplugin_row_metatiny-bar.php:48
Maintenance & Trust

TinyBar – Display notification bar, banner, announcement at the top or bottom of your website Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 20, 2026
PHP min version7.2
Downloads10K

Community Trust

Rating100/100
Number of ratings2
Active installs90
Developer Profile

TinyBar – Display notification bar, banner, announcement at the top or bottom of your website Developer Profile

Hossni Mubarak

14 plugins · 8K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
136 days
View full developer profile
Detection Fingerprints

How We Detect TinyBar – Display notification bar, banner, announcement at the top or bottom of your website

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tiny-bar/assets/css/fontawesome/css/all.min.css/wp-content/plugins/tiny-bar/assets/css/cls-hm-tiny-bar-admin.css/wp-content/plugins/tiny-bar/assets/css/hmtb-countdown.css/wp-content/plugins/tiny-bar/assets/css/hmtb-front.css/wp-content/plugins/tiny-bar/assets/js/cls-hm-tiny-bar-admin.js/wp-content/plugins/tiny-bar/assets/js/hmtb-countdown.js/wp-content/plugins/tiny-bar/assets/js/hmtb-front.js
Script Paths
/wp-content/plugins/tiny-bar/assets/css/fontawesome/css/all.min.css/wp-content/plugins/tiny-bar/assets/css/cls-hm-tiny-bar-admin.css/wp-content/plugins/tiny-bar/assets/css/hmtb-countdown.css/wp-content/plugins/tiny-bar/assets/css/hmtb-front.css/wp-content/plugins/tiny-bar/assets/js/cls-hm-tiny-bar-admin.js/wp-content/plugins/tiny-bar/assets/js/hmtb-countdown.js+1 more

HTML / DOM Fingerprints

CSS Classes
hmtb-alerthmtb-closebtn
Data Attributes
hmtb_donation
FAQ

Frequently Asked Questions about TinyBar – Display notification bar, banner, announcement at the top or bottom of your website