
Float FAQ Security & Risk Analysis
wordpress.org/plugins/float-faqFloating block with FAQ
Is Float FAQ Safe to Use in 2026?
Generally Safe
Score 85/100Float FAQ has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The float-faq v2.1.1 plugin presents a generally positive security posture based on the provided static analysis and vulnerability history. The absence of identified dangerous functions, direct SQL queries (all use prepared statements), file operations, and external HTTP requests are strong indicators of good coding practices. The attack surface is minimal, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events. This lack of entry points significantly reduces the potential for exploitation. The taint analysis showing zero unsanitized paths further reinforces this positive assessment.
However, the analysis does flag a notable concern regarding capability checks and nonce checks. The complete absence of nonce checks is a significant weakness, especially if any of the entry points (even if currently zero) were to be added in future versions or if there's an undiscovered method of interaction. Similarly, the lack of capability checks on any potential code paths means that if an entry point were to be introduced, it might be accessible to users without the necessary permissions. The 17% of improperly escaped output also represents a potential avenue for cross-site scripting (XSS) vulnerabilities, though the severity depends on the context of the unescaped data.
The plugin's vulnerability history is exceptionally clean, with no recorded CVEs. This suggests a history of responsible development and maintenance. The combination of a small attack surface, secure coding practices in key areas, and a clean vulnerability record makes this plugin appear relatively safe. However, the noted lack of nonce and capability checks represents a systemic risk that could become critical if new interaction points are introduced.
Key Concerns
- Missing nonce checks
- Missing capability checks
- Improperly escaped output (17% of 12)
Float FAQ Security Vulnerabilities
Float FAQ Code Analysis
Output Escaping
Float FAQ Attack Surface
WordPress Hooks 7
Maintenance & Trust
Float FAQ Maintenance & Trust
Maintenance Signals
Community Trust
Float FAQ Alternatives
Askova – Smart FAQ Chat
askova
A lightweight FAQ chatbot for WordPress with floating widget, form builder, bilingual admin, quick replies, print/copy answers, and more.
Joinchat
creame-whatsapp-me
WhatsApp, Messenger, Telegram, Phone call… capture users through their favorite Apps and turn into clients
My Sticky Bar – Floating Notification Bar & Sticky Header (formerly myStickymenu)
mystickymenu
Create a welcome notification bar for your website. Also, My Sticky Bar plugin can make your menu or header sticky to the top when scrolled 📌
Sticky Menu & Sticky Header
sticky-menu-or-anything-on-scroll
Sticky Menu or Sticky Header sticks elements at the top of the screen when you scroll, or create a floating sticky menu or fixed widget.
VK Blocks
vk-blocks
This is a plugin that extends Gutenberg's blocks.
Float FAQ Developer Profile
7 plugins · 2K total installs
How We Detect Float FAQ
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/float-faq/_inc/float-faq-style.css/wp-content/plugins/float-faq/_inc/float-faq-script.js/wp-content/plugins/float-faq/_inc/float-faq-script.jsfloat-faq/style.css?ver=float-faq/script.js?ver=HTML / DOM Fingerprints
float-faqfloat-faq-widgetfloat-faq-widget-headerfaq-back-titlegoto-childs-icon-back-titlefloat-faq-bodylist-questionslist-questions-item+10 more<!-- Для того, чтобы этот файл не могли подключить вне WordPress -->/*------------Страница админки*//*------------Страница админки*//*------------фронт*------------*/+6 moredata-id/wp-json/wp/v2/float_faq