Floating Related Posts by Views or Publish Date Security & Risk Analysis

wordpress.org/plugins/floating-related-posts-by-views-or-publish-date

Increase your page views and bounce rate with Floating Related Posts by Views or Publish Date

0 active installs v1.2.0 PHP 5.6+ WP 5.6+ Updated Jan 13, 2025
floatingfloating-related-postsfree-related-postsrelatedrelated-posts
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Floating Related Posts by Views or Publish Date Safe to Use in 2026?

Generally Safe

Score 92/100

Floating Related Posts by Views or Publish Date has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The plugin "floating-related-posts-by-views-or-publish-date" v1.2.0 exhibits a generally strong security posture with no known historical vulnerabilities. The static analysis reveals a very small attack surface with no identified entry points that are unprotected. The plugin also makes good use of prepared statements for its SQL queries, which is a positive indicator. However, there are a few areas that warrant attention. A concerning finding is a single flow with unsanitized paths during taint analysis, even though it was not flagged as critical or high severity. This suggests a potential for vulnerabilities if an attacker can control the input leading to this path. Additionally, while the majority of output is properly escaped, 19% of outputs are not, which could lead to Cross-Site Scripting (XSS) vulnerabilities if user-controlled data is involved in these unescaped outputs.

While the plugin's vulnerability history is clean, suggesting good development practices and a proactive approach to security, the identified taint flow and unescaped outputs are weaknesses. The lack of any capability checks or nonce checks on its (admittedly zero) entry points is not necessarily a flaw given the absence of entry points, but it's a practice that would be a concern if the attack surface were larger or included AJAX or REST API endpoints without proper authorization. Overall, the plugin is relatively secure, but the identified taint flow and unescaped outputs represent areas where improvements could be made to further harden its security.

Key Concerns

  • Flow with unsanitized paths
  • Unescaped output detected
Vulnerabilities
None known

Floating Related Posts by Views or Publish Date Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Floating Related Posts by Views or Publish Date Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
18
75 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

81% escaped93 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<floating-related-posts-by-views-or-date> (floating-related-posts-by-views-or-date.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Floating Related Posts by Views or Publish Date Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_menuadmin\floating-related-posts-by-views-or-date-admin.php:28
actionadmin_initadmin\floating-related-posts-by-views-or-date-admin.php:29
actionwp_enqueue_scriptsfloating-related-posts-by-views-or-date.php:323
actionwp_headfloating-related-posts-by-views-or-date.php:476
actionwp_footerfloating-related-posts-by-views-or-date.php:571
Maintenance & Trust

Floating Related Posts by Views or Publish Date Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedJan 13, 2025
PHP min version5.6
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Floating Related Posts by Views or Publish Date Developer Profile

Antonio Lamorgese

3 plugins · 40 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Floating Related Posts by Views or Publish Date

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/floating-related-posts-by-views-or-publish-date/style/style.css/wp-content/plugins/floating-related-posts-by-views-or-publish-date/js/script.js
Script Paths
/wp-content/plugins/floating-related-posts-by-views-or-publish-date/js/script.js
Version Parameters
floating-related-posts-by-views-or-publish-date/style.css?ver=floating-related-posts-by-views-or-publish-date/js/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
frp-wrapper
Data Attributes
data-vertical-positiondata-horizontal-positiondata-background-colordata-excerpt-colordata-add-excerptdata-opacity+4 more
JS Globals
frp_vars
FAQ

Frequently Asked Questions about Floating Related Posts by Views or Publish Date