
Floating Related Posts by Views or Publish Date Security & Risk Analysis
wordpress.org/plugins/floating-related-posts-by-views-or-publish-dateIncrease your page views and bounce rate with Floating Related Posts by Views or Publish Date
Is Floating Related Posts by Views or Publish Date Safe to Use in 2026?
Generally Safe
Score 92/100Floating Related Posts by Views or Publish Date has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "floating-related-posts-by-views-or-publish-date" v1.2.0 exhibits a generally strong security posture with no known historical vulnerabilities. The static analysis reveals a very small attack surface with no identified entry points that are unprotected. The plugin also makes good use of prepared statements for its SQL queries, which is a positive indicator. However, there are a few areas that warrant attention. A concerning finding is a single flow with unsanitized paths during taint analysis, even though it was not flagged as critical or high severity. This suggests a potential for vulnerabilities if an attacker can control the input leading to this path. Additionally, while the majority of output is properly escaped, 19% of outputs are not, which could lead to Cross-Site Scripting (XSS) vulnerabilities if user-controlled data is involved in these unescaped outputs.
While the plugin's vulnerability history is clean, suggesting good development practices and a proactive approach to security, the identified taint flow and unescaped outputs are weaknesses. The lack of any capability checks or nonce checks on its (admittedly zero) entry points is not necessarily a flaw given the absence of entry points, but it's a practice that would be a concern if the attack surface were larger or included AJAX or REST API endpoints without proper authorization. Overall, the plugin is relatively secure, but the identified taint flow and unescaped outputs represent areas where improvements could be made to further harden its security.
Key Concerns
- Flow with unsanitized paths
- Unescaped output detected
Floating Related Posts by Views or Publish Date Security Vulnerabilities
Floating Related Posts by Views or Publish Date Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Floating Related Posts by Views or Publish Date Attack Surface
WordPress Hooks 5
Maintenance & Trust
Floating Related Posts by Views or Publish Date Maintenance & Trust
Maintenance Signals
Community Trust
Floating Related Posts by Views or Publish Date Alternatives
Related Posts Thumbnails Plugin for WordPress
related-posts-thumbnails
Related Posts by WPBrigade is The Best Customizable plugin, that nicely displays related posts thumbnails under the post.
Floating Related Posts
floating-related-posts
Increase your page views and bounce rate with Floating Related Posts
Related Posts With Slider
related-posts-with-slider
This plugin brings Related post slider to the WordPress blog post.
Inline Related Posts
intelly-related-posts
Inline Related Posts AUTOMATICALLY inserts related posts INSIDE your content, capturing immediately the reader's attention.
VK All in One Expansion Unit
vk-all-in-one-expansion-unit
This plug-in is an integrated plug-in with a variety of features that make it powerful your web site.
Floating Related Posts by Views or Publish Date Developer Profile
3 plugins · 40 total installs
How We Detect Floating Related Posts by Views or Publish Date
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/floating-related-posts-by-views-or-publish-date/style/style.css/wp-content/plugins/floating-related-posts-by-views-or-publish-date/js/script.js/wp-content/plugins/floating-related-posts-by-views-or-publish-date/js/script.jsfloating-related-posts-by-views-or-publish-date/style.css?ver=floating-related-posts-by-views-or-publish-date/js/script.js?ver=HTML / DOM Fingerprints
frp-wrapperdata-vertical-positiondata-horizontal-positiondata-background-colordata-excerpt-colordata-add-excerptdata-opacity+4 morefrp_vars