WP Nanobar.js Security & Risk Analysis

wordpress.org/plugins/wp-nanobar-js

A simple WordPress loading bar using the nanobar.js script written by Jacobo Tabernero.

10 active installs v1.0 PHP + WP 3.0.0+ Updated May 22, 2017
barjavascriptloaderloadingnanobar
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is WP Nanobar.js Safe to Use in 2026?

Generally Safe

Score 85/100

WP Nanobar.js has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

Based on the static analysis and vulnerability history, wp-nanobar-js v1.0 exhibits a generally strong security posture for this version. The absence of any identified attack surface (AJAX, REST API, shortcodes, cron events) is a significant positive. Furthermore, the lack of dangerous functions, file operations, external HTTP requests, and the use of prepared statements for SQL queries are excellent security practices. The only minor concern is that 33% of output escaping is not properly handled, which could present a risk if user-supplied data is echoed without sanitization. The plugin's vulnerability history is also exceptionally clean, with zero recorded CVEs of any severity. This indicates a history of stable and secure code development or simply a lack of significant past scrutiny. Overall, for version 1.0, the plugin appears to be quite secure due to its limited attack surface and positive coding signals, with the unescaped output being the sole identifiable weakness.

Key Concerns

  • Improper output escaping on 33% of outputs
Vulnerabilities
None known

WP Nanobar.js Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

WP Nanobar.js Release Timeline

v1.0Current
Code Analysis
Analyzed Apr 16, 2026

WP Nanobar.js Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

67% escaped3 total outputs
Attack Surface

WP Nanobar.js Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_menusettings.php:5
actionadmin_menusettings.php:6
actionadmin_initsettings.php:25
actionwp_enqueue_scriptswp-nanobar.php:17
actionwp_footerwp-nanobar.php:48
Maintenance & Trust

WP Nanobar.js Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedMay 22, 2017
PHP min version
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

WP Nanobar.js Developer Profile

Wouter Postma

3 plugins · 820 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP Nanobar.js

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-nanobar-js/js/nanobar.js
Script Paths
/wp-content/plugins/wp-nanobar-js/js/nanobar.js

HTML / DOM Fingerprints

CSS Classes
nanobarbar
Data Attributes
id="wp-nanobar"
JS Globals
var nanobar = new Nanobar( options )
FAQ

Frequently Asked Questions about WP Nanobar.js