
Aklamator – Twitch Videofloat Security & Risk Analysis
wordpress.org/plugins/aklamator-twitch-videofloatAdd Twitch Float Video widget to your wordpress and promote your YouTube video, channel or playlist (with e.g. new campaign).
Is Aklamator – Twitch Videofloat Safe to Use in 2026?
Generally Safe
Score 85/100Aklamator – Twitch Videofloat has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'aklamator-twitch-videofloat' v1.2 plugin presents a mixed security picture. On the positive side, the plugin has no recorded vulnerabilities or CVEs, indicating a relatively clean history. The static analysis also shows no dangerous functions, no SQL queries that are not prepared statements, and no file operations, which are all good security practices. Furthermore, there are no observed taint flows with unsanitized paths. However, a significant concern is the complete lack of output escaping, with 0% of 32 outputs being properly escaped. This leaves the plugin highly susceptible to Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data, if ever processed by the plugin, could be injected directly into the HTML output without sanitization. The absence of nonce checks, capability checks, and the presence of an external HTTP request without apparent authentication or validation further raise red flags, creating potential vectors for various attacks if the external resource is compromised or malicious.
While the plugin boasts a zero attack surface from traditional entry points like AJAX handlers, REST API routes, and shortcodes, and its SQL usage is secure, the critical lack of output escaping is a major deficiency. This oversight drastically increases the risk of XSS attacks. The presence of an external HTTP request also requires careful scrutiny to ensure it's not being used in a way that could be exploited. The bundled DataTables v1.9.3 library is outdated, which could potentially introduce vulnerabilities if exploited. The absence of any authentication or permission checks on the external HTTP request is a significant concern. Overall, while the plugin avoids common plugin vulnerabilities like raw SQL and unpatched CVEs, the severe lack of output escaping and the unauthenticated external HTTP request create significant security risks that must be addressed.
Key Concerns
- 0% output escaping
- Bundled outdated library (DataTables v1.9.3)
- External HTTP request without auth/permission
- No nonce checks
- No capability checks
Aklamator – Twitch Videofloat Security Vulnerabilities
Aklamator – Twitch Videofloat Code Analysis
Bundled Libraries
Output Escaping
Aklamator – Twitch Videofloat Attack Surface
WordPress Hooks 4
Maintenance & Trust
Aklamator – Twitch Videofloat Maintenance & Trust
Maintenance Signals
Community Trust
Aklamator – Twitch Videofloat Alternatives
StreamWeasels Twitch Integration
streamweasels-twitch-integration
Embed Twitch streams with our collection of Twitch Blocks and Shortcodes. Works with Block Editor, Classic Editor, and Page Builders.
SV Block for Twitch
sv-twitch
Display Twitch streams with this Gutenberg block. = Team = * Developed and maintenanced by straightvisions GmbH
Twitch Player
ttv-easy-embed-player
Twitch streams for your WordPress website - Twitch Player unlocks a compact, cinema-style layout, great for embedded stream experience.
Twitch Rail
ttv-easy-embed
Twitch streams for your WordPress website - Twitch Rail unlocks a horizontal scrolling layout, to display many streams in a small space.
Twitch Wall
ttv-easy-embed-wall
Twitch streams for your WordPress website - Twitch Wall unlocks a classic Twitch layout for displaying many streams at once.
Aklamator – Twitch Videofloat Developer Profile
7 plugins · 50 total installs
How We Detect Aklamator – Twitch Videofloat
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/aklamator-twitch-videofloat/js/aklamator-twitch-videofloat.js/wp-content/plugins/aklamator-twitch-videofloat/css/aklamator-twitch-videofloat.css/wp-content/plugins/aklamator-twitch-videofloat/images/aklamator-icon.png/wp-content/plugins/aklamator-twitch-videofloat/js/aklamator-twitch-videofloat.jsaklamator-twitch-videofloat/js/aklamator-twitch-videofloat.js?ver=aklamator-twitch-videofloat/css/aklamator-twitch-videofloat.css?ver=HTML / DOM Fingerprints
created 2014-11-25 16:22:10 aklamatorTwitchFVChannelaklamatorTwitchFVApplicationIDaklamatorTwitchFVPoweredByaklamatorTwitchFVSingleWidgetIDaklamatorTwitchFVPageWidgetIDaklamatorTwitchFVSingleWidgetTitle+2 more