
Bottom suspended window, 底部悬浮窗 Security & Risk Analysis
wordpress.org/plugins/bottom-fixed-windowA simple sticky/suspended/fixed bar to the page footer. It can display ads and form content inside, which can be defined from back end.
Is Bottom suspended window, 底部悬浮窗 Safe to Use in 2026?
Generally Safe
Score 100/100Bottom suspended window, 底部悬浮窗 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'bottom-fixed-window' v1.0 exhibits a strong adherence to secure coding practices in its static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits its attack surface. Furthermore, the code doesn't utilize dangerous functions, all SQL queries are prepared, and there are no file operations or external HTTP requests, all of which are positive indicators of a secure development approach. The lack of any recorded vulnerabilities, including CVEs, also suggests a history of good security, or at least a lack of discovery.
Despite these strengths, a critical concern arises from the complete lack of output escaping. This indicates that any data processed and displayed by the plugin, if not inherently safe, could be exposed to cross-site scripting (XSS) vulnerabilities. The absence of nonce and capability checks, while seemingly less critical given the limited attack surface, means that any potential entry points, however small, are not protected against unauthorized access or manipulation.
In conclusion, while the plugin benefits from a minimal attack surface and the proper use of prepared statements, the severe deficiency in output escaping presents a notable risk. The vulnerability history is a positive sign, but the identified code signals do not fully mitigate the potential for injection attacks via unescaped output. Developers should prioritize implementing proper output sanitization to address this significant weakness.
Key Concerns
- 0% output escaping
- 0 nonce checks
- 0 capability checks
Bottom suspended window, 底部悬浮窗 Security Vulnerabilities
Bottom suspended window, 底部悬浮窗 Code Analysis
Output Escaping
Bottom suspended window, 底部悬浮窗 Attack Surface
WordPress Hooks 5
Maintenance & Trust
Bottom suspended window, 底部悬浮窗 Maintenance & Trust
Maintenance Signals
Community Trust
Bottom suspended window, 底部悬浮窗 Alternatives
Peanut Butter Bar (smooth version)
peanut-butter-bar-smooth-version
Peanut Butter Bar allows you to attach sticky bars to the roof of your site that stays visible no matter how far a user scrolls.
ConvBoost Sticky Notification Bar
convboost-sticky-notification-bar
Lightweight sticky top/bottom bar for promos & announcements. CTA, scheduling, exclusions, and live admin preview.
Site Kit by Google – Analytics, Search Console, AdSense, Speed
google-site-kit
Site Kit is a one-stop solution for WordPress users to use everything Google has to offer to make them successful on the web.
Google for WooCommerce
google-listings-and-ads
Native integration with Google that allows merchants to easily display their products across Google’s network.
GTM4WP – A Google Tag Manager (GTM) plugin for WordPress
duracelltomi-google-tag-manager
Advanced tag management for WordPress with Google Tag Manager
Bottom suspended window, 底部悬浮窗 Developer Profile
2 plugins · 10 total installs
How We Detect Bottom suspended window, 底部悬浮窗
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cancms-float-bar/css/front.css/wp-content/plugins/cancms-float-bar/js/front.js/wp-content/plugins/cancms-float-bar/js/front.jscancms-float-bar/css/front.css?ver=cancms-float-bar/js/front.js?ver=