Aklamator – Twitch Videofloat Security & Risk Analysis

wordpress.org/plugins/aklamator-twitch-videofloat

Add Twitch Float Video widget to your wordpress and promote your YouTube video, channel or playlist (with e.g. new campaign).

10 active installs v1.2 PHP + WP 3.0.1+ Updated Jul 16, 2018
floatvideostreamtwichtwitchvideofloat
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Aklamator – Twitch Videofloat Safe to Use in 2026?

Generally Safe

Score 85/100

Aklamator – Twitch Videofloat has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The 'aklamator-twitch-videofloat' v1.2 plugin presents a mixed security picture. On the positive side, the plugin has no recorded vulnerabilities or CVEs, indicating a relatively clean history. The static analysis also shows no dangerous functions, no SQL queries that are not prepared statements, and no file operations, which are all good security practices. Furthermore, there are no observed taint flows with unsanitized paths. However, a significant concern is the complete lack of output escaping, with 0% of 32 outputs being properly escaped. This leaves the plugin highly susceptible to Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data, if ever processed by the plugin, could be injected directly into the HTML output without sanitization. The absence of nonce checks, capability checks, and the presence of an external HTTP request without apparent authentication or validation further raise red flags, creating potential vectors for various attacks if the external resource is compromised or malicious.

While the plugin boasts a zero attack surface from traditional entry points like AJAX handlers, REST API routes, and shortcodes, and its SQL usage is secure, the critical lack of output escaping is a major deficiency. This oversight drastically increases the risk of XSS attacks. The presence of an external HTTP request also requires careful scrutiny to ensure it's not being used in a way that could be exploited. The bundled DataTables v1.9.3 library is outdated, which could potentially introduce vulnerabilities if exploited. The absence of any authentication or permission checks on the external HTTP request is a significant concern. Overall, while the plugin avoids common plugin vulnerabilities like raw SQL and unpatched CVEs, the severe lack of output escaping and the unauthenticated external HTTP request create significant security risks that must be addressed.

Key Concerns

  • 0% output escaping
  • Bundled outdated library (DataTables v1.9.3)
  • External HTTP request without auth/permission
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Aklamator – Twitch Videofloat Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Aklamator – Twitch Videofloat Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
32
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
1

Bundled Libraries

DataTables1.9.3

Output Escaping

0% escaped32 total outputs
Attack Surface

Aklamator – Twitch Videofloat Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
filterplugin_row_metaaklamator-twitch-videofloat.php:59
actionadmin_menuaklamator-twitch-videofloat.php:138
actionadmin_initaklamator-twitch-videofloat.php:144
actionwp_footeraklamator-twitch-videofloat.php:165
Maintenance & Trust

Aklamator – Twitch Videofloat Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedJul 16, 2018
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Aklamator – Twitch Videofloat Developer Profile

aklamator

7 plugins · 50 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Aklamator – Twitch Videofloat

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/aklamator-twitch-videofloat/js/aklamator-twitch-videofloat.js/wp-content/plugins/aklamator-twitch-videofloat/css/aklamator-twitch-videofloat.css/wp-content/plugins/aklamator-twitch-videofloat/images/aklamator-icon.png
Script Paths
/wp-content/plugins/aklamator-twitch-videofloat/js/aklamator-twitch-videofloat.js
Version Parameters
aklamator-twitch-videofloat/js/aklamator-twitch-videofloat.js?ver=aklamator-twitch-videofloat/css/aklamator-twitch-videofloat.css?ver=

HTML / DOM Fingerprints

HTML Comments
created 2014-11-25 16:22:10
Data Attributes
aklamatorTwitchFVChannelaklamatorTwitchFVApplicationIDaklamatorTwitchFVPoweredByaklamatorTwitchFVSingleWidgetIDaklamatorTwitchFVPageWidgetIDaklamatorTwitchFVSingleWidgetTitle+2 more
FAQ

Frequently Asked Questions about Aklamator – Twitch Videofloat