Yelp Bar Security & Risk Analysis

wordpress.org/plugins/yelp-bar

A powerful bar that shows Yelp Rating & Reviews at the top of any WordPress theme, provides instant credibility.

40 active installs v1.3 PHP + WP 3.0+ Updated Jun 16, 2012
placesqyperatingurbanspoonyelp
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Yelp Bar Safe to Use in 2026?

Generally Safe

Score 85/100

Yelp Bar has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 13yr ago
Risk Assessment

The "yelp-bar" plugin version 1.3 exhibits a concerning security posture despite its limited attack surface and lack of known vulnerabilities. While it boasts zero AJAX handlers, REST API routes, shortcodes, or cron events, and performs no file operations or external HTTP requests (beyond one, which is not detailed), the static analysis reveals significant shortcomings in secure coding practices. A critical area of concern is the complete absence of output escaping for all 21 identified output points. This leaves the plugin highly susceptible to Cross-Site Scripting (XSS) vulnerabilities, where malicious code could be injected and executed in users' browsers. Furthermore, the lack of nonce checks and capability checks for its entry points (even though there are none reported) is a general weakness that would be problematic if new entry points were added without proper security. The plugin's vulnerability history being clean is a positive sign, but it cannot negate the immediate risks posed by the unescaped output. Therefore, while the attack surface is currently minimal, the plugin's internal coding practices present a substantial risk that needs immediate remediation.

Key Concerns

  • 0% output escaping for 21 outputs
  • No capability checks for entry points
  • No nonce checks for entry points
Vulnerabilities
None known

Yelp Bar Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Yelp Bar Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
21
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

0% escaped21 total outputs
Attack Surface

Yelp Bar Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_menuyelpbar.php:31
actionadmin_inityelpbar.php:32
actionwp_print_stylesyelpbar.php:33
actionwp_print_scriptsyelpbar.php:34
actionadmin_print_stylesyelpbar.php:35
actionwp_headyelpbar.php:36
actionwp_headyelpbar.php:258
Maintenance & Trust

Yelp Bar Maintenance & Trust

Maintenance Signals

WordPress version tested3.4.2
Last updatedJun 16, 2012
PHP min version
Downloads12K

Community Trust

Rating100/100
Number of ratings6
Active installs40
Developer Profile

Yelp Bar Developer Profile

Noel Tock

3 plugins · 340 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Yelp Bar

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/yelp-bar/css/yelpbar.css
Version Parameters
yelpbar.css?ver=yelpadmin.css?ver=

HTML / DOM Fingerprints

CSS Classes
yelpstatusyelpapi
FAQ

Frequently Asked Questions about Yelp Bar