Bottom suspended window, 底部悬浮窗 Security & Risk Analysis

wordpress.org/plugins/bottom-fixed-window

A simple sticky/suspended/fixed bar to the page footer. It can display ads and form content inside, which can be defined from back end.

10 active installs v1.0 PHP + WP 5.0+ Updated Unknown
adsbottom-barfixed-barsticky-barsuspended-window
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Bottom suspended window, 底部悬浮窗 Safe to Use in 2026?

Generally Safe

Score 100/100

Bottom suspended window, 底部悬浮窗 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The plugin 'bottom-fixed-window' v1.0 exhibits a strong adherence to secure coding practices in its static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits its attack surface. Furthermore, the code doesn't utilize dangerous functions, all SQL queries are prepared, and there are no file operations or external HTTP requests, all of which are positive indicators of a secure development approach. The lack of any recorded vulnerabilities, including CVEs, also suggests a history of good security, or at least a lack of discovery.

Despite these strengths, a critical concern arises from the complete lack of output escaping. This indicates that any data processed and displayed by the plugin, if not inherently safe, could be exposed to cross-site scripting (XSS) vulnerabilities. The absence of nonce and capability checks, while seemingly less critical given the limited attack surface, means that any potential entry points, however small, are not protected against unauthorized access or manipulation.

In conclusion, while the plugin benefits from a minimal attack surface and the proper use of prepared statements, the severe deficiency in output escaping presents a notable risk. The vulnerability history is a positive sign, but the identified code signals do not fully mitigate the potential for injection attacks via unescaped output. Developers should prioritize implementing proper output sanitization to address this significant weakness.

Key Concerns

  • 0% output escaping
  • 0 nonce checks
  • 0 capability checks
Vulnerabilities
None known

Bottom suspended window, 底部悬浮窗 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Bottom suspended window, 底部悬浮窗 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped2 total outputs
Attack Surface

Bottom suspended window, 底部悬浮窗 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actioninitcancms-float-bar.php:67
actionplugins_loadedcancms-float-bar.php:73
actionadmin_menusrc\Admin\BottomBar.php:22
actionadmin_initsrc\Admin\BottomBar.php:25
actionwp_footersrc\Front\Hooks.php:15
Maintenance & Trust

Bottom suspended window, 底部悬浮窗 Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedUnknown
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Bottom suspended window, 底部悬浮窗 Developer Profile

cc2017

2 plugins · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Bottom suspended window, 底部悬浮窗

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cancms-float-bar/css/front.css/wp-content/plugins/cancms-float-bar/js/front.js
Script Paths
/wp-content/plugins/cancms-float-bar/js/front.js
Version Parameters
cancms-float-bar/css/front.css?ver=cancms-float-bar/js/front.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Bottom suspended window, 底部悬浮窗