Floating Callout Security & Risk Analysis

wordpress.org/plugins/floating-callout

Creates a Gutenberg block displayed float right or float left relative to other content. You may set padding, margins, background color or background …

30 active installs v1.0.3 PHP 5.3+ WP 5.0+ Updated May 8, 2021
blockcalloutformattinggutenbergsidebar
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Floating Callout Safe to Use in 2026?

Generally Safe

Score 85/100

Floating Callout has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the 'floating-callout' plugin v1.0.3 exhibits a strong security posture. The static analysis reveals no identified entry points such as AJAX handlers, REST API routes, shortcodes, or cron events that are accessible to users. Furthermore, the code signals are overwhelmingly positive, indicating the absence of dangerous functions, all SQL queries utilizing prepared statements, and 100% of output being properly escaped. There are no file operations, external HTTP requests, or instances of missing nonce or capability checks. Taint analysis also shows no identified vulnerabilities. The plugin's vulnerability history is clean, with no recorded CVEs of any severity. This suggests a development team that prioritizes security best practices. The lack of any identified weaknesses in either static analysis or historical data leads to a very low-risk assessment. The only area for potential (though minor) concern is the complete absence of some security checks, which could be interpreted as a very small attack surface or simply a lack of features requiring those checks.

Vulnerabilities
None known

Floating Callout Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Floating Callout Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Floating Callout Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionenqueue_block_assetssrc\init.php:33
actionenqueue_block_editor_assetssrc\init.php:64
Maintenance & Trust

Floating Callout Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedMay 8, 2021
PHP min version5.3
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

Floating Callout Developer Profile

davidfcarr

10 plugins · 490 total installs

72
trust score
Avg Security Score
90/100
Avg Patch Time
527 days
View full developer profile
Detection Fingerprints

How We Detect Floating Callout

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/floating-callout/dist/blocks.style.build.css/wp-content/plugins/floating-callout/dist/blocks.build.js/wp-content/plugins/floating-callout/dist/blocks.editor.build.css
Script Paths
/wp-content/plugins/floating-callout/dist/blocks.build.js

HTML / DOM Fingerprints

CSS Classes
wp-block-floating-callout
FAQ

Frequently Asked Questions about Floating Callout