
Buttonizer – Floating Menus, Sticky Buttons, & Popup Builder Security & Risk Analysis
wordpress.org/plugins/buttonizer-multifunctional-buttonFloating Menus, Sticky Buttons, & Popup builder. WhatsApp Chat, Facebook Messenger, Telegram, Live Chat, Call, SMS, Email & more.
Is Buttonizer – Floating Menus, Sticky Buttons, & Popup Builder Safe to Use in 2026?
Generally Safe
Score 100/100Buttonizer – Floating Menus, Sticky Buttons, & Popup Builder has a strong security track record. Known vulnerabilities have been patched promptly.
The 'buttonizer-multifunctional-button' plugin, version 3.4.12, exhibits a mixed security posture. While it demonstrates good practices like using prepared statements for all SQL queries and a notable number of nonce checks (27), significant concerns arise from its extensive attack surface. A substantial 27 out of 28 entry points, including all AJAX handlers and REST API routes, lack proper authentication or permission checks. This indicates a high potential for unauthorized access and manipulation of plugin functionalities by unauthenticated users.
The taint analysis shows three flows with unsanitized paths, although none are classified as critical or high severity. This suggests potential for localized issues, but the lack of severity is somewhat mitigated by the absence of raw SQL queries. The plugin's vulnerability history includes one medium-severity CVE related to Cross-site Scripting, last patched in late 2021. This historical pattern, combined with the current lack of proper authorization on numerous entry points, suggests a recurring need for careful attention to input sanitization and authorization mechanisms.
In conclusion, the plugin has strengths in its SQL handling and nonce implementation. However, the overwhelming number of unprotected entry points represents a critical security weakness. While taint analysis doesn't reveal immediate critical flaws, the historical vulnerability and the current unprotected endpoints necessitate caution. Further investigation into the specific nature of the unsanitized paths and the impact of unprotected AJAX/REST endpoints would be highly beneficial.
Key Concerns
- AJAX handlers without auth checks
- REST API routes without permission callbacks
- Flows with unsanitized paths
- Medium severity CVE in history
- Unescaped output present
Buttonizer – Floating Menus, Sticky Buttons, & Popup Builder Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Buttonizer - Smart Floating Action Button <= 2.5.4 - Admin+ Stored Cross-Site Scripting
Buttonizer – Floating Menus, Sticky Buttons, & Popup Builder Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Buttonizer – Floating Menus, Sticky Buttons, & Popup Builder Attack Surface
AJAX Handlers 2
REST API Routes 25
Shortcodes 1
WordPress Hooks 24
Maintenance & Trust
Buttonizer – Floating Menus, Sticky Buttons, & Popup Builder Maintenance & Trust
Maintenance Signals
Community Trust
Buttonizer – Floating Menus, Sticky Buttons, & Popup Builder Alternatives
Floating Awesome Button (Sticky Button, Popup, Toast) & 200+ Website Custom Interactive Element
floating-awesome-button
Floating Awesome Button (FAB) helps website owner, getting more conversion, by adding interactive element such as (Sticky Button, Popup, Toast, etc)
Simple CTA Button
simple-cta-button
特定のページにシンプルなCTAボタンを表示。PC/スマホ表示選択、表示タイミング設定機能付き。
GB Quick launch
gb-quick-launch
Hover over an icon to discover clickable icons with information. They can have a URL or a Contact form, a shortcode, or any content you choose.
Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder
popup-maker
Want to boost sales & marketing efforts? Use your favorite forms & builder. Unlimited popups & impressions, keep your data, no monthly subscription.
Jetpack Social
jetpack-social
Write once, publish everywhere. Reach your target audience by sharing your content with Jetpack Social!
Buttonizer – Floating Menus, Sticky Buttons, & Popup Builder Developer Profile
3 plugins · 190K total installs
How We Detect Buttonizer – Floating Menus, Sticky Buttons, & Popup Builder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/buttonizer-multifunctional-button/assets/app/index.html/wp-content/plugins/buttonizer-multifunctional-button/assets/app/common.js/wp-content/plugins/buttonizer-multifunctional-button/assets/app/app.js/wp-content/plugins/buttonizer-multifunctional-button/assets/app/index.html/wp-content/plugins/buttonizer-multifunctional-button/assets/app/common.js/wp-content/plugins/buttonizer-multifunctional-button/assets/app/app.jsbuttonizer-multifunctional-button/style.css?ver=buttonizer_admin_js?ver=HTML / DOM Fingerprints
buttonizer-buttonWELCOME TO THE BUTTONIZER SOURCE CODE!No script kiddies please!data-buttonizer-idbuttonizer_admin/wp-json/buttonizer[buttonizer]