
Larbous Floating Menu Security & Risk Analysis
wordpress.org/plugins/larbous-floating-menuThis plugin creates a floating menu set to the left position. Set the options in Settings / Larbous Floating Menu
Is Larbous Floating Menu Safe to Use in 2026?
Generally Safe
Score 85/100Larbous Floating Menu has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "larbous-floating-menu" v1.1 plugin presents a generally positive security posture due to the absence of known vulnerabilities and a limited attack surface. The static analysis shows no entry points such as AJAX handlers, REST API routes, shortcodes, or cron events that are exposed without proper authentication. Furthermore, the code avoids dangerous functions, file operations, and external HTTP requests, which are common vectors for attacks. The plugin also utilizes prepared statements for its SQL queries, a strong indicator of secure database interaction. However, a significant concern is the complete lack of output escaping for all identified output points. This means that any dynamic content rendered by the plugin is vulnerable to cross-site scripting (XSS) attacks, as user-supplied data could be injected and executed within the user's browser. The absence of nonce and capability checks across all entry points also indicates a potential weakness, as it relies solely on the absence of direct entry points rather than robust internal checks.
While the plugin has no recorded vulnerability history, this can be a double-edged sword. It might indicate a well-developed plugin with secure coding practices, but it could also mean that the plugin has not been extensively analyzed or that potential vulnerabilities have not yet been discovered. The lack of output escaping is a critical oversight that significantly increases the risk of XSS vulnerabilities. Therefore, despite the clean vulnerability history and limited attack surface, the unescaped output represents a substantial security risk that needs immediate attention. The plugin's strength lies in its minimal exposed functionalities, but its weakness lies in its failure to adequately protect against output manipulation.
Key Concerns
- Unescaped output detected
- Missing nonce checks
- Missing capability checks
Larbous Floating Menu Security Vulnerabilities
Larbous Floating Menu Release Timeline
Larbous Floating Menu Code Analysis
Output Escaping
Larbous Floating Menu Attack Surface
WordPress Hooks 5
Maintenance & Trust
Larbous Floating Menu Maintenance & Trust
Maintenance Signals
Community Trust
Larbous Floating Menu Alternatives
Simple Floating Menu
simple-floating-menu
Simple Floating Menu add a simple floating button with various layouts and settings.
Side Menu Lite – Sticky Floating Side Menu
side-menu-lite
Create a sticky vertical sidebar menu that enhances navigation and highlights important links on your website.
Sticky Menu & Sticky Header
sticky-menu-or-anything-on-scroll
Sticky Menu or Sticky Header sticks elements at the top of the screen when you scroll, or create a floating sticky menu or fixed widget.
Float menu – awesome floating side menu
float-menu
Easily create floating menus of varying complexity. Use its capabilities to place unique navigation on the site.
Sticky Buttons – Floating Buttons Builder
sticky-buttons
Increase user engagement by incorporating sticky buttons that highlight relevant information on your website.
Larbous Floating Menu Developer Profile
1 plugin · 10 total installs
How We Detect Larbous Floating Menu
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/larbous-floating-menu/css/style.css/wp-content/plugins/larbous-floating-menu/js/admin.jsHTML / DOM Fingerprints
lbfm-colorpickername="lbfm_menu"name="lbfm_width"name="lbfm_height"name="lbfm_position"name="lbfm_font_color"name="lbfm_font_color_hover"+3 more