ButtonFlow – Sticky Floating Mobile Button for Call, Messaging & Booking Security & Risk Analysis

wordpress.org/plugins/buttonflow

Boost conversions with a permanent floating CTA button on mobile. One tap to call, message, or book. Zero code required.

0 active installs v1.2.0 PHP 8.0+ WP 6.5+ Updated Apr 12, 2026
click-to-chatctanotification-barwhatsappwhatsapp-business
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ButtonFlow – Sticky Floating Mobile Button for Call, Messaging & Booking Safe to Use in 2026?

Generally Safe

Score 100/100

ButtonFlow – Sticky Floating Mobile Button for Call, Messaging & Booking has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The plugin 'buttonflow' v1.2.0 exhibits an excellent security posture based on the provided static analysis and vulnerability history. The absence of any identified attack surface points, such as AJAX handlers, REST API routes, shortcodes, or cron events, significantly reduces the potential for external exploitation. Furthermore, the code signals indicate strong security practices, with no dangerous functions, all SQL queries using prepared statements, and a very high percentage of properly escaped output. The presence of nonce and capability checks, even with a limited attack surface, demonstrates a proactive approach to access control.

The taint analysis also shows no identified flows with unsanitized paths, further reinforcing the plugin's robustness against common injection vulnerabilities. The lack of any recorded vulnerabilities, including critical or high-severity ones, in its history is a strong indicator of well-maintained and secure code over time. This history suggests the developers prioritize security and have effectively addressed any potential issues in past versions, if any existed.

In conclusion, 'buttonflow' v1.2.0 presents a very low security risk. The combination of a minimal attack surface, robust code security practices, and a clean vulnerability history makes it a highly secure plugin. While no code is ever entirely infallible, the data suggests a strong commitment to security by the developers.

Vulnerabilities
None known

ButtonFlow – Sticky Floating Mobile Button for Call, Messaging & Booking Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

ButtonFlow – Sticky Floating Mobile Button for Call, Messaging & Booking Release Timeline

v1.2.0Current
v1.1.0
Code Analysis
Analyzed Apr 16, 2026

ButtonFlow – Sticky Floating Mobile Button for Call, Messaging & Booking Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
62 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

98% escaped63 total outputs
Attack Surface

ButtonFlow – Sticky Floating Mobile Button for Call, Messaging & Booking Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionplugins_loadedbuttonflow.php:58
actionadmin_menuincludes/Admin/Settings.php:23
actionadmin_initincludes/Admin/Settings.php:24
actionadmin_initincludes/Admin/Settings.php:25
actionadmin_noticesincludes/Admin/Settings.php:26
actionadmin_enqueue_scriptsincludes/Admin/Settings.php:27
actionwp_enqueue_scriptsincludes/Frontend/Renderer.php:23
actionwp_footerincludes/Frontend/Renderer.php:24
Maintenance & Trust

ButtonFlow – Sticky Floating Mobile Button for Call, Messaging & Booking Maintenance & Trust

Maintenance Signals

WordPress version tested7.0
Last updatedApr 12, 2026
PHP min version8.0
Downloads183

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

ButtonFlow – Sticky Floating Mobile Button for Call, Messaging & Booking Developer Profile

Ga Satrya

3 plugins · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ButtonFlow – Sticky Floating Mobile Button for Call, Messaging & Booking

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/buttonflow/assets/css/admin-settings.css/wp-content/plugins/buttonflow/assets/js/admin-settings.js
Script Paths
/wp-content/plugins/buttonflow/assets/js/admin-settings.js
Version Parameters
buttonflow/assets/css/admin-settings.css?ver=buttonflow/assets/js/admin-settings.js?ver=

HTML / DOM Fingerprints

CSS Classes
buttonflow-settings-wrapbuttonflow-admin-wrap
HTML Comments
<!-- Main ButtonFlow settings wrapper --><!-- Start ButtonFlow Admin Wrapper -->
Data Attributes
data-buttonflow-colordata-buttonflow-textcolordata-buttonflow-sizedata-buttonflow-positiondata-buttonflow-actiontypedata-buttonflow-actionvalue+3 more
JS Globals
window.ButtonFlowAdmin
FAQ

Frequently Asked Questions about ButtonFlow – Sticky Floating Mobile Button for Call, Messaging & Booking