
Floating Login Security & Risk Analysis
wordpress.org/plugins/floating-loginFloating login/ register element that sticks to the top of the screen and changes depending on user login state.
Is Floating Login Safe to Use in 2026?
Generally Safe
Score 85/100Floating Login has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "floating-login" v1.2.2 plugin exhibits a generally positive security posture based on the provided static analysis and vulnerability history. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface. Furthermore, the fact that all SQL queries utilize prepared statements is a strong indicator of good database security practices. The lack of any recorded vulnerabilities, including CVEs, also suggests a history of secure development or diligent patching by the developers. This overall picture points to a plugin that, on the surface, appears to be reasonably well-secured.
However, a critical concern arises from the complete lack of output escaping. With 35 total outputs analyzed and 0% properly escaped, this indicates a high likelihood of Cross-Site Scripting (XSS) vulnerabilities. Any data displayed to users, even if originating from trusted sources, could be maliciously manipulated and executed within the user's browser. While there are no critical taint flows or dangerous functions identified, the unescaped output presents a clear and present danger that could be exploited. The lack of nonce and capability checks on the limited entry points is also a minor concern, though less impactful given the limited attack surface.
In conclusion, while the "floating-login" plugin benefits from a small attack surface and secure database practices, the pervasive issue of unescaped output introduces a significant risk of XSS vulnerabilities. The vulnerability history is a positive sign, but it doesn't mitigate the immediate danger posed by the identified code signals. Developers should prioritize addressing the output escaping immediately to improve the plugin's security.
Key Concerns
- 0% properly escaped output
- 0 capability checks
- 0 nonce checks
Floating Login Security Vulnerabilities
Floating Login Code Analysis
Output Escaping
Floating Login Attack Surface
WordPress Hooks 6
Maintenance & Trust
Floating Login Maintenance & Trust
Maintenance Signals
Community Trust
Floating Login Alternatives
Login Logout Menu
login-logout-menu
Login Logout Menu is a handy plugin which allows you to add login, logout, register and profile menu items in your selected menu.
Easy Login Logout
easy-login-logout
Easy Login Logout Menus is the perfect plugin for websites which have login user or logout user.
StranoWeb Ajax Login
stranoweb-ajax-login
Stranoweb Ajax Login replaces default Wordpress login, register and lost password forms with a beautiful ajax modal popup and comes with a lot of amaz …
Custom Welcome Messages
custom-welcome-messages
This plugin will allow you to add a custom welcome message to your login/register screens. It will also allow you to add a separate custom message fo …
LoginWP (Formerly Peter's Login Redirect)
peters-login-redirect
Redirect users to different locations after they log in, log out and register based on different conditions.
Floating Login Developer Profile
1 plugin · 60 total installs
How We Detect Floating Login
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/floating-login/style.cssfloating-login/style.css?ver=HTML / DOM Fingerprints
login-float-containerlogin-float-loginfl_login_afl_login_displayfl_hover_colorfl_bg_colorfl_border_colorfl_border_widthfl_float_position+9 more