Floyi Connect Security & Risk Analysis

wordpress.org/plugins/floyi

Publish content from Floyi directly to your WordPress site with SEO metadata, categories, and scheduling.

0 active installs v1.1.0 PHP 7.4+ WP 5.8+ Updated Mar 13, 2026
content-publishingcontent-strategyfloyiseowordpress-publishing
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Floyi Connect Safe to Use in 2026?

Generally Safe

Score 100/100

Floyi Connect has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "floyi" plugin v1.1.0 demonstrates a generally good security posture, with a limited attack surface and a significant majority of SQL queries utilizing prepared statements. The absence of dangerous functions, file operations, and critical taint flows is commendable. Furthermore, the plugin benefits from a clean vulnerability history, indicating a lack of past security incidents. This suggests a conscientious development approach.

However, there are areas for improvement. A notable concern is the output escaping, where only 64% of outputs are properly escaped. This leaves a substantial portion potentially vulnerable to cross-site scripting (XSS) attacks if untrusted data is not handled carefully. While the plugin has nonce and capability checks on its entry points, the specific implementation and coverage of these checks could be more robust. The presence of external HTTP requests also warrants careful scrutiny to ensure they are not introducing vulnerabilities through third-party services.

In conclusion, "floyi" v1.1.0 is not exhibiting immediate critical vulnerabilities based on the provided static analysis. Its strengths lie in its minimal attack surface and responsible SQL handling. The primary weakness lies in the moderate rate of unescaped output, which is the most significant area of potential risk. A review of the external HTTP requests and a more thorough audit of output escaping would further strengthen its security profile.

Key Concerns

  • Low percentage of properly escaped output
  • External HTTP requests present
Vulnerabilities
None known

Floyi Connect Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Floyi Connect Release Timeline

v1.1.0Current
v1.0.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 17, 2026

Floyi Connect Code Analysis

Dangerous Functions
0
Raw SQL Queries
5
14 prepared
Unescaped Output
40
70 escaped
Nonce Checks
3
Capability Checks
4
File Operations
0
External Requests
3
Bundled Libraries
0

SQL Query Safety

74% prepared19 total queries

Output Escaping

64% escaped110 total outputs
Attack Surface

Floyi Connect Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 3

authwp_ajax_floyi_connectadmin\class-floyi-admin.php:37
authwp_ajax_floyi_disconnectadmin\class-floyi-admin.php:38
authwp_ajax_floyi_retry_webhookadmin\class-floyi-admin.php:39
WordPress Hooks 11
actioninitfloyi.php:89
actionrest_api_initfloyi.php:90
actionadmin_menufloyi.php:94
actionadmin_initfloyi.php:95
actionadmin_enqueue_scriptsfloyi.php:96
actionfloyi_process_webhook_queuefloyi.php:101
actionwp_headfloyi.php:104
filteris_protected_metafloyi.php:107
actiontransition_post_statusfloyi.php:110
actionbefore_delete_postfloyi.php:113
filtercron_schedulesfloyi.php:447

Scheduled Events 1

floyi_process_webhook_queue
Maintenance & Trust

Floyi Connect Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 13, 2026
PHP min version7.4
Downloads289

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Floyi Connect Developer Profile

Floyi

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Floyi Connect

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/floyi/assets/css/floyi-admin-settings.css/wp-content/plugins/floyi/assets/js/floyi-admin-settings.js/wp-content/plugins/floyi/assets/js/floyi-settings.js
Script Paths
/wp-content/plugins/floyi/assets/js/floyi-admin-settings.js/wp-content/plugins/floyi/assets/js/floyi-settings.js
Version Parameters
floyi/assets/css/floyi-admin-settings.css?ver=floyi/assets/js/floyi-admin-settings.js?ver=floyi/assets/js/floyi-settings.js?ver=

HTML / DOM Fingerprints

JS Globals
floyi_settingsfloyi_admin_settings
REST Endpoints
/wp-json/floyi/v1/settings/wp-json/floyi/v1/sync
FAQ

Frequently Asked Questions about Floyi Connect