
Blog Floating Button Security & Risk Analysis
wordpress.org/plugins/blog-floating-buttonBlog Floating Button(BFB)は、ブログにフロートボタンを簡単に実装できるプラグインです。フロートボタンでキラーページに簡単に誘導することができるため、商品購入数や問い合わせ数の向上が期待できます。
Is Blog Floating Button Safe to Use in 2026?
Generally Safe
Score 100/100Blog Floating Button has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The blog-floating-button plugin, version 1.4.20, exhibits a mixed security posture. While it demonstrates some good practices like implementing nonce checks and capability checks, a significant concern arises from its attack surface. A substantial portion of its entry points, specifically 6 out of 10, lack proper authentication checks, making them potentially vulnerable to unauthorized access and manipulation. The presence of the `unserialize` function is another red flag, as it can be a vector for remote code execution if not handled with extreme care and validation of the serialized data. Furthermore, the plugin's vulnerability history, while currently showing no unpatched CVEs, includes a past medium severity vulnerability, specifically Cross-Site Request Forgery (CSRF). This pattern suggests a recurring need for diligent security practices and potentially highlights areas where past vulnerabilities may not have been fully addressed at a fundamental level. The taint analysis results are positive, showing no critical or high severity flows with unsanitized paths, which is a strength, but this is overshadowed by the exposed attack surface and the dangerous function usage.
Key Concerns
- REST API routes without permission callbacks
- Dangerous function: unserialize
- SQL queries with low prepared statement usage
- Output escaping below threshold
- Bundled library: DataTables
- Past medium severity CVE (CSRF)
Blog Floating Button Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Blog Floating Button <= 1.4.12 - Cross-Site Request Forgery
Blog Floating Button Release Timeline
Blog Floating Button Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Blog Floating Button Attack Surface
REST API Routes 6
Shortcodes 4
WordPress Hooks 32
Scheduled Events 2
Maintenance & Trust
Blog Floating Button Maintenance & Trust
Maintenance Signals
Community Trust
Blog Floating Button Alternatives
Simple Banner – Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website
simple-banner
Display a simple banner/bar at the top or bottom of your website. Now with multi-banner support.
Notibar – Notification Bar for WordPress
notibar
Customizer for sticky header, notification bar, alert, promo code, marketing campaign, top banner
Announcement & Notification Banner – Bulletin
bulletin-announcements
Publish a slick announcement banner notice across your website or Woocommerce shop. Extend with icons, countdowns, placement rules and more!
Sticky Banner
sticky-banner
Create eye-catching announcement banners that stick to the top or bottom of your site. Perfect for promotions, alerts, and important updates.
Announcement Banner
announcement-banner
Display a banner at the top or bottom of your WordPress site.
Blog Floating Button Developer Profile
1 plugin · 9K total installs
How We Detect Blog Floating Button
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/blog-floating-button/css/bfb_style.css/wp-content/plugins/blog-floating-button/js/bfb.js/wp-content/plugins/blog-floating-button/js/bfb_setting.js/wp-content/plugins/blog-floating-button/js/bfb_init.js/wp-content/plugins/blog-floating-button/js/bfb.js/wp-content/plugins/blog-floating-button/js/bfb_setting.js/wp-content/plugins/blog-floating-button/js/bfb_init.js/wp-content/plugins/blog-floating-button/css/bfb_style.css?ver=/wp-content/plugins/blog-floating-button/js/bfb.js?ver=/wp-content/plugins/blog-floating-button/js/bfb_setting.js?ver=/wp-content/plugins/blog-floating-button/js/bfb_init.js?ver=HTML / DOM Fingerprints
bfb_positionbfb_design_textBtnbfb_design_textTextBtnbfb_design_textBtnTextBtnbfb_design_imgBanner<!-- BFB --><!-- START BFB_optimize --><!-- END BFB_optimize --><!-- BFB_optimize_preview -->data-bfb-opt-idbfb_setting/wp-json/bfb/api/echo_bfb_optimize[bfb_show[bfb_hide