WP Admin Bar Effect Security & Risk Analysis

wordpress.org/plugins/wp-admin-bar-effect

Add slide effect to admin bar for show & hide with mouse hover

10 active installs v3.0 PHP + WP 3.8+ Updated Sep 6, 2017
adminadmin-barcustomize-menueffectmenu
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Admin Bar Effect Safe to Use in 2026?

Generally Safe

Score 85/100

WP Admin Bar Effect has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The 'wp-admin-bar-effect' v3.0 plugin exhibits a surprisingly clean static analysis report, with no identified attack surface points, dangerous functions, file operations, external requests, or issues with taint analysis. This suggests a potentially strong adherence to secure coding practices regarding common entry points and data handling. The absence of any recorded vulnerabilities or CVEs further reinforces this perception of a secure plugin.

However, the plugin's code analysis reveals critical weaknesses. The presence of a single SQL query that is not prepared is a significant concern, as it introduces a high risk of SQL injection vulnerabilities. Furthermore, the fact that none of the observed output operations are properly escaped poses a substantial risk of Cross-Site Scripting (XSS) attacks. The complete lack of nonce and capability checks across all potential, albeit currently non-existent, entry points is also a notable oversight, which could be exploited if new entry points are introduced in the future without proper security measures.

In conclusion, while the plugin's limited attack surface and clean vulnerability history are positive indicators, the identified flaws in SQL preparation and output escaping represent critical security risks that must be addressed. The absence of checks on potential entry points, even though there are none currently, is a design weakness that should be rectified for future-proofing. Addressing these specific code-level issues is paramount to improving the plugin's overall security posture.

Key Concerns

  • SQL queries without prepared statements
  • Output escaping not properly handled
  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

WP Admin Bar Effect Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

WP Admin Bar Effect Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
5
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

0% escaped5 total outputs
Attack Surface

WP Admin Bar Effect Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actionadmin_enqueue_scriptsadmin\class-admin-bar.php:17
filtercustom_menu_orderadmin\class-admin-menu.php:36
filtermenu_orderadmin\class-admin-menu.php:37
actionadmin_enqueue_scriptsadmin\class-admin-menu.php:38
actionadmin_enqueue_scriptsadmin\class-settings.php:44
actionpersonal_options_updateadmin\class-settings.php:45
actionprofile_personal_optionsadmin\class-settings.php:46
filterplugin_action_linkswp-admin-bar-effect.php:24
filterplugin_row_metawp-admin-bar-effect.php:25
actionadmin_bar_initwp-admin-bar-effect.php:39
actionadmin_menuwp-admin-bar-effect.php:45
actioninitwp-admin-bar-effect.php:81
Maintenance & Trust

WP Admin Bar Effect Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedSep 6, 2017
PHP min version
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

WP Admin Bar Effect Developer Profile

Sergio

4 plugins · 10K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP Admin Bar Effect

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-admin-bar-effect/css/admin-bar.min.css/wp-content/plugins/wp-admin-bar-effect/css/menu.min.css/wp-content/plugins/wp-admin-bar-effect/js/admin-bar.min.js/wp-content/plugins/wp-admin-bar-effect/js/menu.min.js/wp-content/plugins/wp-admin-bar-effect/js/settings.min.js
Script Paths
/wp-content/plugins/wp-admin-bar-effect/js/admin-bar.min.js/wp-content/plugins/wp-admin-bar-effect/js/menu.min.js/wp-content/plugins/wp-admin-bar-effect/js/settings.min.js
Version Parameters
wp-admin-bar-effect/css/admin-bar.min.css?ver=wp-admin-bar-effect/css/menu.min.css?ver=wp-admin-bar-effect/js/admin-bar.min.js?ver=wp-admin-bar-effect/js/menu.min.js?ver=wp-admin-bar-effect/js/settings.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
wp-admin-bar-effect-menu
Data Attributes
data-speeddata-sensitivitydata-intervaldata-timeout
JS Globals
wabewabe_settings
FAQ

Frequently Asked Questions about WP Admin Bar Effect