
Floating Button – Easily Create Sticky, Fixed & Floating Buttons Security & Risk Analysis
wordpress.org/plugins/floating-buttonFloating Buttons let you easily create sticky, fixed, and floating action buttons
Is Floating Button – Easily Create Sticky, Fixed & Floating Buttons Safe to Use in 2026?
Generally Safe
Score 100/100Floating Button – Easily Create Sticky, Fixed & Floating Buttons has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "floating-button" plugin v7.0.2 exhibits a generally good security posture, with robust practices in place such as extensive use of prepared statements for SQL queries and proper output escaping. The presence of nonce and capability checks on its single AJAX entry point is also commendable, indicating an awareness of common web vulnerabilities. However, the taint analysis reveals a significant concern: 7 out of 8 analyzed flows contain unsanitized paths, with 2 identified as high severity. This suggests potential vulnerabilities where user-controlled input might be used in sensitive operations without adequate sanitization, possibly leading to path traversal or other file manipulation issues.
The plugin's vulnerability history, while showing no currently unpatched CVEs, does list one medium severity Cross-Site Request Forgery (CSRF) vulnerability discovered relatively recently. This indicates that while developers are addressing known issues, the historical presence of CSRF, combined with the high severity taint flows, suggests a need for heightened vigilance regarding input validation and sanitization to prevent potential exploitation. Overall, the plugin is well-maintained in terms of patching and employs good security practices, but the taint analysis highlights critical areas requiring immediate attention to mitigate potential security risks.
Key Concerns
- High severity taint flows found
- Unsanitized paths in taint flows
- Medium severity CVE in history
Floating Button – Easily Create Sticky, Fixed & Floating Buttons Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Floating Button <= 6.0 - Cross-Site Request Forgery via process_bulk_action
Floating Button – Easily Create Sticky, Fixed & Floating Buttons Release Timeline
Floating Button – Easily Create Sticky, Fixed & Floating Buttons Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Floating Button – Easily Create Sticky, Fixed & Floating Buttons Attack Surface
AJAX Handlers 1
WordPress Hooks 11
Maintenance & Trust
Floating Button – Easily Create Sticky, Fixed & Floating Buttons Maintenance & Trust
Maintenance Signals
Community Trust
Floating Button – Easily Create Sticky, Fixed & Floating Buttons Alternatives
Button Generator – Easily Create Custom Buttons with Icons and Analytics
button-generation
Design and display custom buttons anywhere on your site. Add floating or inline buttons with icons, advanced targeting, and built-in analytics.
Sticky Action Buttons – Call, Chat, Navigate and more
sticky-action-buttons-call-chat-navigate-and-more
The ultimate flexible and lightweight responsive sticky floating contact buttons. over 100 different design options.
Floating Contact Buttons
degx-floating-buttons
Add customizable WhatsApp and Phone floating buttons to your WordPress website.
Nút Bấm Liên Hệ Dibrother
dibrother-floating-buttons
Thêm các nút liên hệ (Gọi, Zalo, Messenger) cố định vào website WordPress. Kết nối tức thì với khách hàng.
Mobile Contact Buttons
mobile-contact-buttons
Adds Call, Email and SMS buttons on bottom of website. Only for Mobile View of website.
Floating Button – Easily Create Sticky, Fixed & Floating Buttons Developer Profile
26 plugins · 98K total installs
How We Detect Floating Button – Easily Create Sticky, Fixed & Floating Buttons
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/floating-button/admin/css/dashboard.css/wp-content/plugins/floating-button/admin/css/style.css/wp-content/plugins/floating-button/assets/css/floating-button.css/wp-content/plugins/floating-button/assets/js/floating-button.js/wp-content/plugins/floating-button/assets/js/sticky.js/wp-content/plugins/floating-button/assets/js/vue.js/wp-content/plugins/floating-button/assets/js/wow-icon.js/wp-content/plugins/floating-button/assets/js/floating-button.js/wp-content/plugins/floating-button/assets/js/sticky.js/wp-content/plugins/floating-button/assets/js/vue.js/wp-content/plugins/floating-button/assets/js/wow-icon.jsfloating-button/style.css?ver=floating-button/script.js?ver=HTML / DOM Fingerprints
wowp-link-changewowp-link-ratingwowp-link-prowowp-link-docswowp-link-demowpie-linkswpie-links-dividerdata-wowp-slugdata-wowp-prefixfloatingButtonWOWP_Plugin_Data/wp-json/floating-button/v1/settings[Floating-Button]