WP Guest Bar Security & Risk Analysis

wordpress.org/plugins/wp-guest-bar

Add a customizable guest bar to your WordPress site.

10 active installs v3.0.1 PHP + WP 3.3+ Updated May 29, 2025
adminbarguestlogintoolbar
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Guest Bar Safe to Use in 2026?

Generally Safe

Score 100/100

WP Guest Bar has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

Based on the static analysis and vulnerability history, the wp-guest-bar plugin version 3.0.1 exhibits a strong security posture. The absence of any identified dangerous functions, unsanitized taint flows, or raw SQL queries is highly commendable. Furthermore, all identified output operations are properly escaped, and file operations and external HTTP requests are not present, significantly reducing potential attack vectors. The plugin also demonstrates good practice by including a capability check, although the absence of nonce checks across its identified entry points is a point of concern. The clean vulnerability history, with zero known CVEs, suggests a commitment to security from the developers or a lack of historical exploits. However, the fact that there are no AJAX handlers, REST API routes, or shortcodes means the attack surface is effectively zero, which, while inherently secure, also limits its potential functionality and thus the scope of analysis for certain vulnerability types. The overall assessment is positive, with a few minor areas for potential improvement regarding input validation and authorization for any future additions that might expand its attack surface.

Key Concerns

  • No nonce checks on potential entry points
Vulnerabilities
None known

WP Guest Bar Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

WP Guest Bar Release Timeline

v3.0.1Current
v2.3
v2.2
v2.1
v1.1.1
v1.1
v1.0
Code Analysis
Analyzed Apr 16, 2026

WP Guest Bar Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
34 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped34 total outputs
Attack Surface

WP Guest Bar Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actioninitguestbar.php:14
actionadmin_initguestbar.php:15
actionadmin_bar_menuguestbar.php:16
actionadmin_menuguestbar.php:17
actionwp_enqueue_scriptsguestbar.php:18
actionadmin_enqueue_scriptsguestbar.php:19
filtershow_admin_barguestbar.php:117
actionadmin_footerguestbar.php:144
Maintenance & Trust

WP Guest Bar Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMay 29, 2025
PHP min version
Downloads6K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

WP Guest Bar Developer Profile

Marco Milesi

14 plugins · 12K total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
280 days
View full developer profile
Detection Fingerprints

How We Detect WP Guest Bar

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-guest-bar/admin.css/wp-content/plugins/wp-guest-bar/guestbar.js
Script Paths
/wp-content/plugins/wp-guest-bar/guestbar.js
Version Parameters
wp-guest-bar/admin.css?ver=wp-guest-bar/guestbar.js?ver=

HTML / DOM Fingerprints

CSS Classes
wpdb-hide-mobilewpgb-custom-link
Data Attributes
id="wpgb_logo_upload"id="wpgov_wpgb_logo"id="wpgb_logo_preview"name="wpgb_nonce"
JS Globals
wp.mediacustom_uploader
FAQ

Frequently Asked Questions about WP Guest Bar