
Floating Side Tab Security & Risk Analysis
wordpress.org/plugins/floating-side-tabFloating Side Tab lets you add customizable sticky tab menus on any page to showcase quick links, social icons, forms, or custom content.
Is Floating Side Tab Safe to Use in 2026?
Generally Safe
Score 100/100Floating Side Tab has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "floating-side-tab" v1.1.5 plugin exhibits a generally strong security posture with good development practices in place. The absence of known vulnerabilities and the high percentage of SQL queries using prepared statements, along with properly escaped output, are positive indicators. Furthermore, the plugin avoids potentially risky operations like file modifications or external HTTP requests.
However, the static analysis reveals some areas of concern. The presence of 4 "flows with unsanitized paths" classified as High severity taint flows is the most significant risk. While there are no directly exploitable vulnerabilities indicated by these flows in this version, they represent potential weaknesses that could be exploited if input validation or sanitization were to be improperly handled in future updates or related code. The complete lack of capability checks on the single AJAX handler also presents a potential risk, as it means any authenticated user, regardless of their role, can trigger this functionality, which could be leveraged in certain attack scenarios.
Despite the lack of historical vulnerabilities, the identified taint flows and the absence of capability checks on the AJAX handler suggest that the plugin could benefit from more rigorous input validation and authorization mechanisms. The plugin's strengths lie in its avoidance of common pitfalls like raw SQL and unescaped output, but the taint analysis highlights a need for caution regarding data sanitization.
Key Concerns
- High severity taint flows
- AJAX handler without capability checks
Floating Side Tab Security Vulnerabilities
Floating Side Tab Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Floating Side Tab Attack Surface
AJAX Handlers 1
WordPress Hooks 9
Maintenance & Trust
Floating Side Tab Maintenance & Trust
Maintenance Signals
Community Trust
Floating Side Tab Alternatives
Sticky Menu & Sticky Header
sticky-menu-or-anything-on-scroll
Sticky Menu or Sticky Header sticks elements at the top of the screen when you scroll, or create a floating sticky menu or fixed widget.
Float menu – awesome floating side menu
float-menu
Easily create floating menus of varying complexity. Use its capabilities to place unique navigation on the site.
Boxzilla – Pop-Ups for WordPress
boxzilla
Flexible pop-ups or slide-ins, showing up at just the right time.
Icegram Engage – Popups, Optins, CTAs & lot more…
icegram
Create popups, opt-in forms, and call-to-action messages to capture leads and engage visitors on your WordPress site.
Mobile Contact Bar
mobile-contact-bar
Allow your visitors to contact you via mobile phones, or access your site's pages instantly.
Floating Side Tab Developer Profile
8 plugins · 4K total installs
How We Detect Floating Side Tab
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/floating-side-tab/assets/css/fsdt-metabox.css/wp-content/plugins/floating-side-tab/assets/js/fsdt-frontend.js/wp-content/plugins/floating-side-tab/assets/js/fsdt-frontend.jsfloating-side-tab/assets/css/fsdt-metabox.css?ver=floating-side-tab/assets/js/fsdt-frontend.js?ver=HTML / DOM Fingerprints
fsdt-field-wrapfsdt-meta-flxfsdt-fieldfsdt-checkbox-togglename="fsdt_meta_detail[menu_status]"name="fsdt_meta_detail[post_type_menu]"data-fsdt-menu-positiondata-fsdt-menu-templatesdata-fsdt-icon-animationfsdt_frontend_params