
ActionButton Security & Risk Analysis
wordpress.org/plugins/actionbuttonAdd a responsive sticky footer button with animated text, gradient background, and customizable link and label.
Is ActionButton Safe to Use in 2026?
Generally Safe
Score 100/100ActionButton has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'actionbutton' plugin v1.0.0 exhibits a strong security posture based on the provided static analysis. All identified entry points, including the single shortcode, appear to be protected by nonces and lack any unescaped output, dangerous functions, or file operations. The absence of SQL queries, external HTTP requests, and bundled libraries further strengthens its defensive capabilities. Taint analysis shows no critical or high-severity unsanitized flows, indicating a lack of common vulnerability patterns that could lead to cross-site scripting or arbitrary code execution. The plugin's history is also clean, with no known CVEs, suggesting a commitment to security maintenance and development by its authors.
However, the plugin's security is not entirely without potential concerns. The lack of capability checks on the shortcode, while protected by a nonce, means that any user who can execute the shortcode could potentially trigger its functionality, regardless of their WordPress role. While the current functionality is not detailed, this could be a weakness if the shortcode's action has privileged operations. Furthermore, the limited scope of static analysis and taint flows means that complex vulnerabilities or issues arising from interactions with other plugins or themes might not be detected.
In conclusion, 'actionbutton' v1.0.0 is a well-secured plugin in its current state, adhering to many security best practices. The absence of critical vulnerabilities is a significant strength. The primary area for improvement lies in implementing capability checks to ensure that the shortcode's functionality is only accessible to authorized users, thus creating a more robust security model.
Key Concerns
- Missing capability checks on shortcode
ActionButton Security Vulnerabilities
ActionButton Code Analysis
Output Escaping
ActionButton Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
ActionButton Maintenance & Trust
Maintenance Signals
Community Trust
ActionButton Alternatives
Sticky Floating Button (Book Now, Contact, Call To Action…)
sticky-button
The button can be centered at the bottom of the page or placed on the left/right sides. Display the button on the entire website or on specific pages.
Floating Awesome Button (Sticky Button, Popup, Toast) & 200+ Website Custom Interactive Element
floating-awesome-button
Floating Awesome Button (FAB) helps website owner, getting more conversion, by adding interactive element such as (Sticky Button, Popup, Toast, etc)
Floating Button/CTA – Easy to use
floating-button-cta-easy-to-use
Easily add a floating button on your site with multiple sub-buttons in a half circle layout. Perfect for quick actions, call-to-action, or shortcuts.
LiveChapter Sticky Side CTA
livechapter-sticky-side-cta
Create stunning sticky side tab buttons with call-to-action features by LiveChapter. Perfect for contact, social media, and conversion buttons.
MaxButtons – Create buttons
maxbuttons
Maxbuttons is the best and easiest button plugin for WordPress. Within minutes you can create beautiful buttons, share buttons and social icons.
ActionButton Developer Profile
1 plugin · 60 total installs
How We Detect ActionButton
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/actionbutton/assets/actionbutton-frontend.cssactionbutton-admin-style?ver=1.0.0HTML / DOM Fingerprints
actionbutton-edit-buttondata-indexdata-textdata-linkdata-color1data-color2data-fontcolor[action_button id="