
Bubble Menu – Floating Button Menu with Sticky Navigation Security & Risk Analysis
wordpress.org/plugins/bubble-menuCreate interactive floating bubble menus to enhance site navigation and boost user engagement effortlessly.
Is Bubble Menu – Floating Button Menu with Sticky Navigation Safe to Use in 2026?
Generally Safe
Score 98/100Bubble Menu – Floating Button Menu with Sticky Navigation has a strong security track record. Known vulnerabilities have been patched promptly.
The 'bubble-menu' plugin v4.1.1 demonstrates a generally good security posture with a robust approach to output escaping and a low number of SQL queries that bypass prepared statements. The absence of any file operations or external HTTP requests further strengthens its security. However, the presence of taint analysis flows with unsanitized paths, specifically three flagged as high severity, indicates a potential risk for attackers to inject malicious code or exploit logic flaws. While there are no currently unpatched CVEs, the plugin's history of three medium-severity vulnerabilities, predominantly Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF), suggests a recurring pattern of input validation issues that need careful attention. The presence of non-critical entry points and a limited number of capability checks are positive signs, but the identified taint flows and past vulnerability types warrant vigilance.
Key Concerns
- High severity unsanitized taint flows found
- Medium severity vulnerabilities in history
- SQL queries without prepared statements
Bubble Menu – Floating Button Menu with Sticky Navigation Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Bubble Menu – circle floating menu <= 4.0.2 - Cross-Site Request Forgery
Bubble Menu <= 3.0.4 - Authenticated (Admin+) Stored Cross-Site Scripting
Bubble Menu – circle floating menu <= 3.0.1 - Cross Site Request Forgery
Bubble Menu – Floating Button Menu with Sticky Navigation Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Bubble Menu – Floating Button Menu with Sticky Navigation Attack Surface
WordPress Hooks 14
Maintenance & Trust
Bubble Menu – Floating Button Menu with Sticky Navigation Maintenance & Trust
Maintenance Signals
Community Trust
Bubble Menu – Floating Button Menu with Sticky Navigation Alternatives
Sticky Menu & Sticky Header
sticky-menu-or-anything-on-scroll
Sticky Menu or Sticky Header sticks elements at the top of the screen when you scroll, or create a floating sticky menu or fixed widget.
Float menu – awesome floating side menu
float-menu
Easily create floating menus of varying complexity. Use its capabilities to place unique navigation on the site.
Simple Floating Menu
simple-floating-menu
Simple Floating Menu add a simple floating button with various layouts and settings.
Sticky Buttons – Floating Buttons Builder
sticky-buttons
Increase user engagement by incorporating sticky buttons that highlight relevant information on your website.
Side Menu Lite – Sticky Floating Side Menu
side-menu-lite
Create a sticky vertical sidebar menu that enhances navigation and highlights important links on your website.
Bubble Menu – Floating Button Menu with Sticky Navigation Developer Profile
25 plugins · 98K total installs
How We Detect Bubble Menu – Floating Button Menu with Sticky Navigation
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bubble-menu/assets/css/bubble-menu.css/wp-content/plugins/bubble-menu/assets/js/bubble-menu.js/wp-content/plugins/bubble-menu/assets/js/bubble-menu.jsbubble-menu/assets/css/bubble-menu.css?ver=bubble-menu/assets/js/bubble-menu.js?ver=HTML / DOM Fingerprints
wow-bubble-menudata-wow-bubble-menu-idwow_bubble_menu_options[Bubble-Menu