Floating News Headline Security & Risk Analysis

wordpress.org/plugins/floating-news-headline

Premium, modern, and highly customizable floating news ticker for WordPress — rebuilt with a React dashboard, GPU-accelerated CSS animations, and BEM …

100 active installs v1.3.2 PHP 5.6+ WP 5.8+ Updated Apr 1, 2026
breaking-newsfloating-barmarqueenews-headlinenews-ticker
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Floating News Headline Safe to Use in 2026?

Generally Safe

Score 100/100

Floating News Headline has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "floating-news-headline" plugin v1.2.9 exhibits a generally good security posture with several strengths. The absence of known CVEs and a clean vulnerability history suggest a commitment to security or a lack of historically targeted vulnerabilities. The code analysis shows a strong reliance on prepared statements for SQL queries, a robust number of capability checks, and a good proportion of output escaping. Nonce checks are also present, indicating an awareness of common attack vectors. However, the presence of two `unserialize` calls is a significant concern. While the static analysis and taint flows didn't explicitly reveal a vulnerability, the `unserialize` function is notorious for its potential to lead to Remote Code Execution (RCE) or other severe vulnerabilities if used with untrusted input. This function should be avoided or, at the very least, heavily scrutinized for input validation.

The plugin has a small attack surface with only one shortcode identified as an entry point, and importantly, none of these entry points are directly unprotected. This is a positive sign for its overall security. The limited external interactions (no HTTP requests, no file operations) also reduce potential attack vectors. Despite the lack of historical vulnerabilities and the presence of good security practices like prepared statements and capability checks, the inherent risk associated with `unserialize` means this plugin cannot be considered entirely risk-free. Further manual code review focusing on how and where `unserialize` is used would be highly recommended to confirm the absence of exploitable flaws.

Key Concerns

  • Dangerous function unserialize used
  • Output escaping not properly done on 35% of outputs
Vulnerabilities
None known

Floating News Headline Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Floating News Headline Release Timeline

v1.3.2Current
v1.3.1
v1.2.9
v1.2.8
v1.2.7
v1.2.6
v1.2.5
v1.2.4
v1.2.3
v1.2.2
v1.2.1
v1.2.0
v1.1.7
v1.1.6
v1.1.5
v1.1.4
v1.1.3
v1.1.2
v1.1.1
v1.1.0
Code Analysis
Analyzed Mar 16, 2026

Floating News Headline Code Analysis

Dangerous Functions
2
Raw SQL Queries
0
0 prepared
Unescaped Output
44
81 escaped
Nonce Checks
6
Capability Checks
13
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

unserialize$fh_settings = unserialize(base64_decode(get_post_meta( $post->ID, 'awl_fh_settings_'.$post->ID, trufloating-headline-setting.php:18
unserialize$fh_settings = unserialize(base64_decode(get_post_meta( $fhs_id, 'awl_fh_settings_'.$fhs_id, true)))floating-headline-shortcode.php:14

Output Escaping

65% escaped125 total outputs
Attack Surface

Floating News Headline Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[FHS] floating-headline-shortcode.php:4
WordPress Hooks 34
actioninitclass-tgm-plugin-activation.php:268
filterload_textdomain_mofileclass-tgm-plugin-activation.php:269
actioninitclass-tgm-plugin-activation.php:272
actionadmin_menuclass-tgm-plugin-activation.php:421
actionadmin_headclass-tgm-plugin-activation.php:422
filterinstall_plugin_complete_actionsclass-tgm-plugin-activation.php:425
filterupdate_plugin_complete_actionsclass-tgm-plugin-activation.php:426
actionadmin_noticesclass-tgm-plugin-activation.php:429
actionadmin_initclass-tgm-plugin-activation.php:430
actionadmin_enqueue_scriptsclass-tgm-plugin-activation.php:431
actionload-plugins.phpclass-tgm-plugin-activation.php:436
actionswitch_themeclass-tgm-plugin-activation.php:439
actionswitch_themeclass-tgm-plugin-activation.php:442
actionadmin_initclass-tgm-plugin-activation.php:447
actionswitch_themeclass-tgm-plugin-activation.php:452
actionload_textdomain_mofileclass-tgm-plugin-activation.php:475
filterupgrader_source_selectionclass-tgm-plugin-activation.php:889
actionplugins_loadedclass-tgm-plugin-activation.php:2112
filtertgmpa_table_data_itemsclass-tgm-plugin-activation.php:2236
filterupgrader_source_selectionclass-tgm-plugin-activation.php:2977
actionadmin_initclass-tgm-plugin-activation.php:3147
actionupgrader_process_completeclass-tgm-plugin-activation.php:3242
filterupgrader_post_installclass-tgm-plugin-activation.php:3301
filterupgrader_post_installclass-tgm-plugin-activation.php:3446
actionplugins_loadedfloating-news-headlines.php:58
actionadmin_menufloating-news-headlines.php:61
actioninitfloating-news-headlines.php:64
actionadd_meta_boxesfloating-news-headlines.php:67
actionsave_postfloating-news-headlines.php:69
filterwidget_textfloating-news-headlines.php:72
filtermanage_floating_headline_posts_columnsfloating-news-headlines.php:75
actionmanage_floating_headline_posts_custom_columnfloating-news-headlines.php:78
actionwp_enqueue_scriptsfloating-news-headlines.php:80
actiontgmpa_registerfloating-news-headlines.php:235
Maintenance & Trust

Floating News Headline Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 1, 2026
PHP min version5.6
Downloads18K

Community Trust

Rating60/100
Number of ratings2
Active installs100
Developer Profile

Floating News Headline Developer Profile

A WP Life

65 plugins · 90K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
266 days
View full developer profile
Detection Fingerprints

How We Detect Floating News Headline

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/floating-news-headline/css/fh-uploader.css/wp-content/plugins/floating-news-headline/js/fh-uploader.js/wp-content/plugins/floating-news-headline/js/fh-color-picker.js
Script Paths
/wp-content/plugins/floating-news-headline/js/fh-uploader.js/wp-content/plugins/floating-news-headline/js/fh-color-picker.js

HTML / DOM Fingerprints

CSS Classes
floating-headline-shortcodecopy-msg-floating-headline
Data Attributes
data-id
JS Globals
FloatingCopyShortcode
Shortcode Output
[FHS id=
FAQ

Frequently Asked Questions about Floating News Headline