
Floating Contact Button Security & Risk Analysis
wordpress.org/plugins/floating-contactIntegrates a floating contact button and opens an modal contact form.
Is Floating Contact Button Safe to Use in 2026?
Generally Safe
Score 99/100Floating Contact Button has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of the 'floating-contact' plugin v2.9 reveals a generally strong security posture. The absence of any identified attack surface, dangerous functions, raw SQL queries, file operations, or external HTTP requests is highly encouraging. The presence of capability checks and 100% prepared statement usage for SQL queries indicates good development practices in these critical areas.
However, a notable concern is the output escaping. With 17 total outputs, only 65% are properly escaped, leaving a significant portion potentially vulnerable to cross-site scripting (XSS) attacks. This aligns with the plugin's vulnerability history, which shows a past medium-severity XSS vulnerability. While there are no currently unpatched CVEs, the historical presence of XSS issues combined with the observed incomplete output escaping warrants caution.
In conclusion, the plugin demonstrates strengths in preventing common vulnerabilities like SQL injection and unauthorized access through robust checks. The main area for improvement and continued monitoring is output escaping to mitigate the risk of XSS, especially given its past. The lack of a large attack surface is a significant positive, but the unescaped outputs present a tangible risk that should be addressed.
Key Concerns
- Incomplete output escaping
- Past medium severity XSS vulnerability
Floating Contact Button Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Floating Contact Button <= 2.7 - Authenticated (Admin+) Stored Cross-Site Scripting
Floating Contact Button Code Analysis
Output Escaping
Floating Contact Button Attack Surface
WordPress Hooks 7
Maintenance & Trust
Floating Contact Button Maintenance & Trust
Maintenance Signals
Community Trust
Floating Contact Button Alternatives
Button Generator – Easily Create Custom Buttons with Icons and Analytics
button-generation
Design and display custom buttons anywhere on your site. Add floating or inline buttons with icons, advanced targeting, and built-in analytics.
Floating Button – Easily Create Sticky, Fixed & Floating Buttons
floating-button
Floating Buttons let you easily create sticky, fixed, and floating action buttons
Nút Bấm Liên Hệ Dibrother
dibrother-floating-buttons
Thêm các nút liên hệ (Gọi, Zalo, Messenger) cố định vào website WordPress. Kết nối tức thì với khách hàng.
Floating Contact Button for MAX and Telegram
floating-contact-button-for-max-and-telegram
A lightweight floating contact button for WordPress with support for Telegram, WhatsApp, Facebook Messenger and MAX.
Sticky Action Buttons – Call, Chat, Navigate and more
sticky-action-buttons-call-chat-navigate-and-more
The ultimate flexible and lightweight responsive sticky floating contact buttons. over 100 different design options.
Floating Contact Button Developer Profile
1 plugin · 1K total installs
How We Detect Floating Contact Button
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/floating-contact/assets/css/style.min.cssHTML / DOM Fingerprints
fcb-link-buttonfcb-iconsfcb-headerclose-fcb-modalfcb-header-closefcb-closefcb-modal-contentfcb_custom_data$<p>