Aklamator – Float Video on your blog Security & Risk Analysis

wordpress.org/plugins/aklamator-float-video-on-your-blog

Add Float Video widget to your wordpress and promote your YouTube video, channel or playlist (with e.g. new campaign). Additionally Aklamator service …

0 active installs v2.0.2 PHP + WP 3.0.1+ Updated Jul 3, 2018
floatvideovideovideofloatyoutubeyoutube-channel
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Aklamator – Float Video on your blog Safe to Use in 2026?

Generally Safe

Score 85/100

Aklamator – Float Video on your blog has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The 'aklamator-float-video-on-your-blog' plugin v2.0.2 presents a mixed security posture. On the positive side, the static analysis reveals no identified attack surface through common WordPress entry points like AJAX, REST API, shortcodes, or cron events. Furthermore, there are no recorded CVEs, indicating a historically clean security record. The plugin also exclusively uses prepared statements for SQL queries and performs no file operations, which are strong security practices.

However, there are significant concerns. The most glaring issue is that 100% of its 35 output operations are not properly escaped. This is a critical vulnerability that could allow for cross-site scripting (XSS) attacks if any of the data being output originates from user input or external sources. The absence of nonce and capability checks on all identified entry points, coupled with the lack of taint analysis data, further amplifies this risk. While the number of entry points is zero, the potential for XSS in the output still represents a serious threat.

In conclusion, while the plugin avoids common attack vectors and has a clean vulnerability history, the complete lack of output escaping is a severe weakness. This oversight could lead to critical security flaws. The zero-day nature of potential XSS vulnerabilities means they are not yet covered by historical CVEs, making proactive attention to output sanitization crucial for mitigating risks.

Key Concerns

  • All outputs are unescaped
  • No nonce checks on identified entry points
  • No capability checks on identified entry points
  • Bundled outdated library (DataTables v1.9.3)
Vulnerabilities
None known

Aklamator – Float Video on your blog Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Aklamator – Float Video on your blog Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

Aklamator – Float Video on your blog Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
35
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
1

Bundled Libraries

DataTables1.9.3

Output Escaping

0% escaped35 total outputs
Attack Surface

Aklamator – Float Video on your blog Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
filterplugin_row_metaaklamator-float-video-on-your-blog.php:59
actionadmin_menuaklamator-float-video-on-your-blog.php:140
actionadmin_initaklamator-float-video-on-your-blog.php:146
actionwp_footeraklamator-float-video-on-your-blog.php:167
Maintenance & Trust

Aklamator – Float Video on your blog Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedJul 3, 2018
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Aklamator – Float Video on your blog Developer Profile

aklamator

7 plugins · 50 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Aklamator – Float Video on your blog

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/aklamator-float-video-on-your-blog/aklamator-float-video.css/wp-content/plugins/aklamator-float-video-on-your-blog/aklamator-float-video.js/wp-content/plugins/aklamator-float-video-on-your-blog/images/aklamator-icon.png
Script Paths
/wp-content/plugins/aklamator-float-video-on-your-blog/aklamator-float-video.js

HTML / DOM Fingerprints

CSS Classes
aklamator-float-video-widgetaklamator-float-video-close-button
HTML Comments
created 2
Data Attributes
data-aklamator-app-iddata-aklamator-intro-urldata-aklamator-powered-bydata-aklamator-photo-urldata-aklamator-widget-id
JS Globals
aklamator_fv_data
FAQ

Frequently Asked Questions about Aklamator – Float Video on your blog