TopBar Buddy – Announcement Bar, Notification Bar and Sticky Alert Bar Security & Risk Analysis

wordpress.org/plugins/topbar-buddy

Display announcement bars, notification bars, and sticky top banners in WordPress with scheduling, start/end dates, and page targeting

0 active installs v1.1.0 PHP 7.4+ WP 6.0+ Updated Feb 21, 2026
alertannouncementbannernotificationscheduling
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is TopBar Buddy – Announcement Bar, Notification Bar and Sticky Alert Bar Safe to Use in 2026?

Generally Safe

Score 100/100

TopBar Buddy – Announcement Bar, Notification Bar and Sticky Alert Bar has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The plugin "topbar-buddy" v1.1.0 exhibits a generally strong security posture with excellent adherence to several best practices. The absence of any known vulnerabilities in its history is a significant positive indicator, suggesting a history of secure development and maintenance. Furthermore, the code demonstrates a commitment to security by exclusively using prepared statements for all SQL queries and achieving a very high percentage of properly escaped output. The plugin also utilizes nonce checks, contributing to the integrity of its operations.

However, a critical concern is highlighted by the taint analysis, which reveals one flow with unsanitized paths. While no "critical" severity taint flows were found, the presence of a "high" severity flow, even if only one, warrants attention as it could potentially lead to vulnerabilities if exploited. The lack of capability checks is another area of concern, especially if any of the plugin's functionalities could be sensitive or lead to unintended actions by unauthorized users. The fact that there are no reported vulnerabilities might be due to the limited attack surface or the effectiveness of its current (though potentially incomplete) security measures.

In conclusion, "topbar-buddy" v1.1.0 is built on a solid foundation with good coding practices like prepared statements and output escaping. Its vulnerability history is clean, which is reassuring. Nevertheless, the identified high-severity taint flow and the absence of capability checks introduce specific risks that should be addressed to further strengthen its security.

Key Concerns

  • High severity unsanitized path flow
  • Missing capability checks
Vulnerabilities
None known

TopBar Buddy – Announcement Bar, Notification Bar and Sticky Alert Bar Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

TopBar Buddy – Announcement Bar, Notification Bar and Sticky Alert Bar Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
10 prepared
Unescaped Output
7
289 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared10 total queries

Output Escaping

98% escaped296 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<banner-management> (admin\banner-management.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

TopBar Buddy – Announcement Bar, Notification Bar and Sticky Alert Bar Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionadmin_noticesold-versions.php:13
Maintenance & Trust

TopBar Buddy – Announcement Bar, Notification Bar and Sticky Alert Bar Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 21, 2026
PHP min version7.4
Downloads191

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

TopBar Buddy – Announcement Bar, Notification Bar and Sticky Alert Bar Developer Profile

eLearning evolve

2 plugins · 500 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect TopBar Buddy – Announcement Bar, Notification Bar and Sticky Alert Bar

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/topbar-buddy/assets/css/style.css/wp-content/plugins/topbar-buddy/assets/js/admin-script.js/wp-content/plugins/topbar-buddy/assets/js/script.js
Script Paths
/wp-content/plugins/topbar-buddy/assets/js/admin-script.js/wp-content/plugins/topbar-buddy/assets/js/script.js
Version Parameters
topbar-buddy/assets/css/style.css?ver=topbar-buddy/assets/js/admin-script.js?ver=topbar-buddy/assets/js/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
tb_buddy_banner
Data Attributes
data-tb-banner-id
JS Globals
tb_buddy_ajax_object
FAQ

Frequently Asked Questions about TopBar Buddy – Announcement Bar, Notification Bar and Sticky Alert Bar