
Advanced Floating Content Lite Security & Risk Analysis
wordpress.org/plugins/advanced-floating-content-liteCreate high-impact floating content that stays visible without annoying visitors. Perfect for announcements, CTAs, and promotions.
Is Advanced Floating Content Lite Safe to Use in 2026?
Generally Safe
Score 99/100Advanced Floating Content Lite has a strong security track record. Known vulnerabilities have been patched promptly.
The "advanced-floating-content-lite" v1.2.8 plugin exhibits a mixed security posture. While it demonstrates good practices such as using prepared statements for all SQL queries and a high percentage of properly escaped output, significant concerns arise from its attack surface and vulnerability history.
Static analysis reveals a considerable number of unprotected AJAX handlers, totaling 4 entry points that lack authentication checks. This creates a significant risk of unauthorized actions or data manipulation if these handlers are exploitable. The absence of taint analysis data is noted, but the presence of unprotected AJAX handlers is a direct indicator of potential vulnerabilities, especially considering the plugin's history. The vulnerability history shows two previously disclosed medium-severity Cross-Site Scripting (XSS) vulnerabilities, with the most recent one being very recent. Although currently unpatched CVEs are zero, the pattern of XSS vulnerabilities suggests a persistent weakness in input sanitization or output encoding that needs continuous vigilance.
In conclusion, the plugin's strengths lie in its database interaction security and output handling for the majority of its code. However, the high number of unprotected AJAX endpoints and the recurring XSS vulnerabilities in its history represent critical areas of concern. Users should be aware of the potential risks associated with these unprotected entry points and monitor for any new disclosures related to XSS.
Key Concerns
- Unprotected AJAX handlers
- Previous medium XSS vulnerabilities (2)
Advanced Floating Content Lite Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Advanced Floating Content Lite <= 1.2.5 - Authenticated (Editor+) Stored Cross-Site Scripting
Advanced Floating Content <= 1.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Advanced Floating Content Lite Code Analysis
Output Escaping
Advanced Floating Content Lite Attack Surface
AJAX Handlers 4
WordPress Hooks 13
Maintenance & Trust
Advanced Floating Content Lite Maintenance & Trust
Maintenance Signals
Community Trust
Advanced Floating Content Lite Alternatives
My Sticky Bar – Floating Notification Bar & Sticky Header (formerly myStickymenu)
mystickymenu
Create a welcome notification bar for your website. Also, My Sticky Bar plugin can make your menu or header sticky to the top when scrolled 📌
Floaty Header – Sticky Header, Floating Bar & Announcement Bar
floatyheader-sticky-header
Easily create sticky headers, menus & announcement bars for Elementor or any theme. Simple, lightweight & fast.
FBar Social
fbar-social
FBar Social plugin is a social sticky header bar for wordpress that magically appears at a specific pixel.
ConvBoost Sticky Notification Bar
convboost-sticky-notification-bar
Lightweight sticky top/bottom bar for promos & announcements. CTA, scheduling, exclusions, and live admin preview.
Lightweight High Performance Sticky Bar
lightweight-high-performance-sticky-bar
Add a customizable sticky notification bar with countdown functionality to your website with minimal performance impact.
Advanced Floating Content Lite Developer Profile
4 plugins · 8K total installs
How We Detect Advanced Floating Content Lite
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/advanced-floating-content-lite/admin/css/advanced-floating-content-admin.css/wp-content/plugins/advanced-floating-content-lite/admin/js/advanced-floating-content-admin.js/wp-content/plugins/advanced-floating-content-lite/public/css/advanced-floating-content-public.css/wp-content/plugins/advanced-floating-content-lite/public/js/advanced-floating-content-public.jswp-content/plugins/advanced-floating-content-lite/admin/js/advanced-floating-content-admin.jswp-content/plugins/advanced-floating-content-lite/public/js/advanced-floating-content-public.jsadvanced-floating-content-lite/admin/css/advanced-floating-content-admin.css?ver=advanced-floating-content-lite/admin/js/advanced-floating-content-admin.js?ver=advanced-floating-content-lite/public/css/advanced-floating-content-public.css?ver=advanced-floating-content-lite/public/js/advanced-floating-content-public.js?ver=HTML / DOM Fingerprints
afc-modal-contentafc-modal-headerafc-modal-bodyafc-modal-footerct-afc-main-wrapperct-afc-wrapperdata-ct-afc-iddata-ct-afc-display-settingsdata-ct-afc-custom-cssadvanced_floating_content_admin_objectadvanced_floating_content_public_objectct_afc_data[advanced_floating_content]