WP Alerts Bars Security & Risk Analysis

wordpress.org/plugins/wp-alerts-bars

WP Alerts Bars allows you to create beautiful custom alerts that appear on pages or posts of your choice. use this shortcode [wab_bars type="prim …

0 active installs v1.1.0 PHP 7.2+ WP 5.2+ Updated Unknown
alertalert-notice-boxnotice-boxesshuvo66
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Alerts Bars Safe to Use in 2026?

Generally Safe

Score 100/100

WP Alerts Bars has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The wp-alerts-bars plugin v1.1.0 exhibits a strong static security posture with no identified dangerous functions, all SQL queries using prepared statements, and all output properly escaped. The absence of file operations, external HTTP requests, and a small, protected attack surface further contribute to its good security practices. Taint analysis also shows no critical or high-severity unsanitized paths. The plugin's vulnerability history is entirely clean, with no recorded CVEs, which suggests a history of secure development and maintenance.

Despite the excellent code signals, a notable concern is the complete absence of nonce checks and capability checks. While the attack surface is currently small and appears protected, the lack of these fundamental WordPress security mechanisms leaves potential vulnerabilities open if new entry points are introduced or if existing ones are overlooked in future updates. Relying solely on the existing protected nature of the current entry points, especially the shortcode, without these checks, is a weakness that could be exploited if the context of the shortcode's usage changes or if other security measures are bypassed.

In conclusion, wp-alerts-bars v1.1.0 is a well-coded plugin with a clean security record. However, the complete omission of nonce and capability checks, despite a currently protected attack surface, represents a significant potential weakness that needs to be addressed to ensure long-term security robustness.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

WP Alerts Bars Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

WP Alerts Bars Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped2 total outputs
Attack Surface

WP Alerts Bars Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[wab_bars] wp_alerts_bar.php:35
WordPress Hooks 1
actionwp_enqueue_scriptswp_alerts_bar.php:46
Maintenance & Trust

WP Alerts Bars Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedUnknown
PHP min version7.2
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

WP Alerts Bars Developer Profile

shuvo66

2 plugins · 1K total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP Alerts Bars

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-alerts-bars/assets/css/bootstrap.min.css
Version Parameters
/wp-content/plugins/wp-alerts-bars/assets/css/bootstrap.min.css?ver=wp-alerts-bars/assets/css/bootstrap.min.css?ver=

HTML / DOM Fingerprints

CSS Classes
alertalert-primaryalert-secondaryalert-successalert-dangeralert-warningalert-infoalert-light+1 more
Shortcode Output
<div class="alert alert-
FAQ

Frequently Asked Questions about WP Alerts Bars