
Floating Action Button Security & Risk Analysis
wordpress.org/plugins/floating-action-buttonDisplay the beautiful FAB (Floating Action Button) on your WordPress front-end.
Is Floating Action Button Safe to Use in 2026?
Generally Safe
Score 98/100Floating Action Button has a strong security track record. Known vulnerabilities have been patched promptly.
The 'floating-action-button' plugin v1.2.2 exhibits a mixed security posture. While the code analysis reveals no dangerous functions, all SQL queries are prepared, and there are no critical or high severity taint flows, there are significant concerns regarding its attack surface and output sanitization. The presence of a single unprotected AJAX handler represents a direct entry point that could be exploited without proper authentication. Furthermore, only 40% of output is properly escaped, leaving potential for cross-site scripting (XSS) vulnerabilities if user-supplied data is directly echoed without adequate sanitization.
The plugin's vulnerability history is a notable red flag. With three known CVEs, including high and medium severity vulnerabilities, and a recent vulnerability recorded in November 2023, it indicates a pattern of past security weaknesses. The common vulnerability types, CSRF and Missing Authorization, directly align with the static analysis findings of an unprotected AJAX handler and a reliance on a single, potentially insufficient, capability check. While there are currently no unpatched CVEs, the recurring nature of these issues suggests a need for more robust and consistent security practices in development. The plugin has strengths in its SQL handling and lack of critical taint issues, but the unprotected AJAX handler and output escaping issues, combined with its history, elevate the risk.
Key Concerns
- Unprotected AJAX handler
- Insufficient output escaping (40%)
- History of 3 known CVEs
- History of 1 high severity vulnerability
- History of 2 medium severity vulnerabilities
- Common vulnerability type: Missing Authorization
- Common vulnerability type: Cross-Site Request Forgery
Floating Action Button Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Floating Action Button <= 1.2.1 - Cross-Site Request Forgery
Floating Action Button <= <=1.2.1 - Cross-Site Request Forgery to Settings Modification
Floating Action Button <= 1.2 - Missing Authorization
Floating Action Button Code Analysis
Output Escaping
Data Flow Analysis
Floating Action Button Attack Surface
AJAX Handlers 1
WordPress Hooks 4
Maintenance & Trust
Floating Action Button Maintenance & Trust
Maintenance Signals
Community Trust
Floating Action Button Alternatives
YTS Floating action button
yts-floating-action-button
A Basic floating action button plugin for your website.
Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat – Bit Assist
bit-assist
Floating sticky chat button for WhatsApp Chat, Facebook Messenger, Telegram, Instagram, SMS, Call, Discord chat, TikTok, Line & 30+ channels
Cresta Help Chat
cresta-whatsapp-chat
Allow your users and customers to contact you via WhatsApp with a single click.
WP Sticky Button – Click to Chat
wa-sticky-button
Display the beautiful WhatsApp Sticky Button on the WordPress frontend.
Add Chat App Button
add-whatsapp-button
Add Chat App Button enables adding a customizeable click-to-chat button that opens a chat on WhatsApp. This plugin is not affiliated with WhatsApp or …
Floating Action Button Developer Profile
2 plugins · 11K total installs
How We Detect Floating Action Button
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/floating-action-button/assets/home-conditional-script.js/wp-content/plugins/floating-action-button/assets/home-conditional-style.css/wp-content/plugins/floating-action-button/assets/home-script.js/wp-content/plugins/floating-action-button/assets/admin-style.css/wp-content/plugins/floating-action-button/assets/admin-script.js/wp-content/plugins/floating-action-button/assets/home-conditional-script.js/wp-content/plugins/floating-action-button/assets/home-script.js/wp-content/plugins/floating-action-button/assets/admin-script.jsHTML / DOM Fingerprints
data-fz-fab-activatedata-fz-fab-positiondata-fz-fab-typedata-fz-fab-main-img-iddata-fz-fab-main-colordata-fz-fab-main-bg-colorfz_fab_settings/wp-json/floating-action-button/v1/settings