Advanced Floating Content Lite Security & Risk Analysis

wordpress.org/plugins/advanced-floating-content-lite

Create high-impact floating content that stays visible without annoying visitors. Perfect for announcements, CTAs, and promotions.

8K active installs v1.2.8 PHP + WP 4.0+ Updated Jan 6, 2026
announcement-barfloating-contentsticky-barsticky-footersticky-header
99
A · Safe
CVEs total2
Unpatched0
Last CVEApr 22, 2024
Safety Verdict

Is Advanced Floating Content Lite Safe to Use in 2026?

Generally Safe

Score 99/100

Advanced Floating Content Lite has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Apr 22, 2024Updated 2mo ago
Risk Assessment

The "advanced-floating-content-lite" v1.2.8 plugin exhibits a mixed security posture. While it demonstrates good practices such as using prepared statements for all SQL queries and a high percentage of properly escaped output, significant concerns arise from its attack surface and vulnerability history.

Static analysis reveals a considerable number of unprotected AJAX handlers, totaling 4 entry points that lack authentication checks. This creates a significant risk of unauthorized actions or data manipulation if these handlers are exploitable. The absence of taint analysis data is noted, but the presence of unprotected AJAX handlers is a direct indicator of potential vulnerabilities, especially considering the plugin's history. The vulnerability history shows two previously disclosed medium-severity Cross-Site Scripting (XSS) vulnerabilities, with the most recent one being very recent. Although currently unpatched CVEs are zero, the pattern of XSS vulnerabilities suggests a persistent weakness in input sanitization or output encoding that needs continuous vigilance.

In conclusion, the plugin's strengths lie in its database interaction security and output handling for the majority of its code. However, the high number of unprotected AJAX endpoints and the recurring XSS vulnerabilities in its history represent critical areas of concern. Users should be aware of the potential risks associated with these unprotected entry points and monitor for any new disclosures related to XSS.

Key Concerns

  • Unprotected AJAX handlers
  • Previous medium XSS vulnerabilities (2)
Vulnerabilities
2

Advanced Floating Content Lite Security Vulnerabilities

CVEs by Year

1 CVE in 2022
2022
1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2024-32723medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Advanced Floating Content Lite <= 1.2.5 - Authenticated (Editor+) Stored Cross-Site Scripting

Apr 22, 2024 Patched in 1.2.6 (8d)
CVE-2022-43458medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Advanced Floating Content <= 1.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

Oct 24, 2022 Patched in 1.2.2 (456d)
Code Analysis
Analyzed Mar 16, 2026

Advanced Floating Content Lite Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
70 escaped
Nonce Checks
3
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

90% escaped78 total outputs
Attack Surface
4 unprotected

Advanced Floating Content Lite Attack Surface

Entry Points4
Unprotected4

AJAX Handlers 4

authwp_ajax_update_remind_laterincludes\class-advanced-floating-content.php:166
noprivwp_ajax_update_remind_laterincludes\class-advanced-floating-content.php:167
authwp_ajax_afc_dismiss_permanentlyincludes\class-advanced-floating-content.php:168
noprivwp_ajax_afc_dismiss_permanentlyincludes\class-advanced-floating-content.php:169
WordPress Hooks 13
actionplugins_loadedincludes\class-advanced-floating-content.php:141
actionadmin_enqueue_scriptsincludes\class-advanced-floating-content.php:156
actionadmin_enqueue_scriptsincludes\class-advanced-floating-content.php:157
actioninitincludes\class-advanced-floating-content.php:158
actionadd_meta_boxesincludes\class-advanced-floating-content.php:159
actionsave_postincludes\class-advanced-floating-content.php:160
actionadd_meta_boxesincludes\class-advanced-floating-content.php:161
actionadmin_menuincludes\class-advanced-floating-content.php:162
actionadmin_initincludes\class-advanced-floating-content.php:163
actionadmin_noticesincludes\class-advanced-floating-content.php:164
filteradmin_footer_textincludes\class-advanced-floating-content.php:165
filterplugin_action_links_advanced-floating-content-lite/advanced-floating-content.phpincludes\class-advanced-floating-content.php:170
actionwp_footerincludes\class-advanced-floating-content.php:183
Maintenance & Trust

Advanced Floating Content Lite Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJan 6, 2026
PHP min version
Downloads147K

Community Trust

Rating82/100
Number of ratings30
Active installs8K
Developer Profile

Advanced Floating Content Lite Developer Profile

Code Tides

4 plugins · 8K total installs

75
trust score
Avg Security Score
94/100
Avg Patch Time
232 days
View full developer profile
Detection Fingerprints

How We Detect Advanced Floating Content Lite

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/advanced-floating-content-lite/admin/css/advanced-floating-content-admin.css/wp-content/plugins/advanced-floating-content-lite/admin/js/advanced-floating-content-admin.js/wp-content/plugins/advanced-floating-content-lite/public/css/advanced-floating-content-public.css/wp-content/plugins/advanced-floating-content-lite/public/js/advanced-floating-content-public.js
Script Paths
wp-content/plugins/advanced-floating-content-lite/admin/js/advanced-floating-content-admin.jswp-content/plugins/advanced-floating-content-lite/public/js/advanced-floating-content-public.js
Version Parameters
advanced-floating-content-lite/admin/css/advanced-floating-content-admin.css?ver=advanced-floating-content-lite/admin/js/advanced-floating-content-admin.js?ver=advanced-floating-content-lite/public/css/advanced-floating-content-public.css?ver=advanced-floating-content-lite/public/js/advanced-floating-content-public.js?ver=

HTML / DOM Fingerprints

CSS Classes
afc-modal-contentafc-modal-headerafc-modal-bodyafc-modal-footerct-afc-main-wrapperct-afc-wrapper
Data Attributes
data-ct-afc-iddata-ct-afc-display-settingsdata-ct-afc-custom-css
JS Globals
advanced_floating_content_admin_objectadvanced_floating_content_public_objectct_afc_data
Shortcode Output
[advanced_floating_content]
FAQ

Frequently Asked Questions about Advanced Floating Content Lite