
Toolbar Publish Button Security & Risk Analysis
wordpress.org/plugins/toolbar-publish-buttonScroll less in WordPress admin area! A small UX improvement will keep Publish button within reach and retain the scrollbar position after saving.
Is Toolbar Publish Button Safe to Use in 2026?
Generally Safe
Score 85/100Toolbar Publish Button has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "toolbar-publish-button" v1.8 plugin exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The plugin has no known CVEs, indicating a history of security awareness or lack of exploitable vulnerabilities. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface, which is a major positive. The code signals also show that all SQL queries are prepared, and there are no dangerous functions or file operations. This suggests careful development practices to prevent common web vulnerabilities.
However, there is a notable concern regarding output escaping, as 100% of the identified outputs are not properly escaped. This presents a potential risk for cross-site scripting (XSS) vulnerabilities if any user-controlled data is rendered directly to the browser without sanitization. While the plugin has only one capability check, the lack of explicit checks on other potential entry points (though none were identified) and the absence of nonce checks on any identified entry points are areas to monitor. The overall lack of identified taint flows is positive, but the unescaped output remains the most significant immediate risk.
In conclusion, the plugin has strengths in its minimal attack surface and secure handling of database interactions. The vulnerability history is clean, which is reassuring. The primary weakness lies in the unescaped output, which should be addressed to mitigate XSS risks. The absence of certain security checks is less concerning given the limited attack surface but could become an issue if the plugin's functionality expands or if previously undiscovered entry points exist.
Key Concerns
- Output escaping not properly implemented
Toolbar Publish Button Security Vulnerabilities
Toolbar Publish Button Code Analysis
Output Escaping
Toolbar Publish Button Attack Surface
WordPress Hooks 6
Maintenance & Trust
Toolbar Publish Button Maintenance & Trust
Maintenance Signals
Community Trust
Toolbar Publish Button Alternatives
Simple Save Redirect Button
simple-save-redirect-button
A new "Save" button which is enhanced post's standard "Save" button. It saves post and execute next action: Next/Previous Post, Next/Previous Page, Posts list page, scroll and highlight last edited post, etc. Saves a lot of clicks and time if you have a lot of posts.
WPFront Scroll Top
wpfront-scroll-top
Adds a lightweight and smooth "Scroll to Top" button to your WordPress site, improving navigation and user experience with customizable options.
WP Ghost (Hide My WP Ghost) – Security & Firewall
hide-my-wp
Hide and Secure WP paths, wp-login, wp-admin, and more. Hack Prevention, Security, Brute Force protection, 8G Firewall, 2FA Passkey Login, and more.
MouseWheel Smooth Scroll
mousewheel-smooth-scroll
Smooth scrolling experience, with mousewheel, touchpad or keyboard
Page scroll to id
page-scroll-to-id
Create links that scroll the page smoothly to any id within the document.
Toolbar Publish Button Developer Profile
2 plugins · 76K total installs
How We Detect Toolbar Publish Button
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/toolbar-publish-button/js/tpb.js/wp-content/plugins/toolbar-publish-button/js/tpb-options.js/wp-content/plugins/toolbar-publish-button/js/tpb-scrollbar.js/wp-content/plugins/toolbar-publish-button/js/tpb-color-picker.js/wp-content/plugins/toolbar-publish-button/css/tpb-admin.css/wp-content/plugins/toolbar-publish-button/js/tpb.js/wp-content/plugins/toolbar-publish-button/js/tpb-options.js/wp-content/plugins/toolbar-publish-button/js/tpb-scrollbar.js/wp-content/plugins/toolbar-publish-button/js/tpb-color-picker.jstoolbar-publish-button/js/tpb.js?ver=toolbar-publish-button/js/tpb-options.js?ver=toolbar-publish-button/js/tpb-scrollbar.js?ver=toolbar-publish-button/js/tpb-color-picker.js?ver=toolbar-publish-button/css/tpb-admin.css?ver=HTML / DOM Fingerprints
tpb_l10n