Larbous Floating Menu Security & Risk Analysis

wordpress.org/plugins/larbous-floating-menu

This plugin creates a floating menu set to the left position. Set the options in Settings / Larbous Floating Menu

10 active installs v1.1 PHP + WP 3.9+ Updated Aug 25, 2014
fixed-menufloating-menumenu
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Larbous Floating Menu Safe to Use in 2026?

Generally Safe

Score 85/100

Larbous Floating Menu has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The "larbous-floating-menu" v1.1 plugin presents a generally positive security posture due to the absence of known vulnerabilities and a limited attack surface. The static analysis shows no entry points such as AJAX handlers, REST API routes, shortcodes, or cron events that are exposed without proper authentication. Furthermore, the code avoids dangerous functions, file operations, and external HTTP requests, which are common vectors for attacks. The plugin also utilizes prepared statements for its SQL queries, a strong indicator of secure database interaction. However, a significant concern is the complete lack of output escaping for all identified output points. This means that any dynamic content rendered by the plugin is vulnerable to cross-site scripting (XSS) attacks, as user-supplied data could be injected and executed within the user's browser. The absence of nonce and capability checks across all entry points also indicates a potential weakness, as it relies solely on the absence of direct entry points rather than robust internal checks.

While the plugin has no recorded vulnerability history, this can be a double-edged sword. It might indicate a well-developed plugin with secure coding practices, but it could also mean that the plugin has not been extensively analyzed or that potential vulnerabilities have not yet been discovered. The lack of output escaping is a critical oversight that significantly increases the risk of XSS vulnerabilities. Therefore, despite the clean vulnerability history and limited attack surface, the unescaped output represents a substantial security risk that needs immediate attention. The plugin's strength lies in its minimal exposed functionalities, but its weakness lies in its failure to adequately protect against output manipulation.

Key Concerns

  • Unescaped output detected
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Larbous Floating Menu Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Larbous Floating Menu Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

Larbous Floating Menu Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
9
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped9 total outputs
Attack Surface

Larbous Floating Menu Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actioninitlarbous-floating-menu.php:54
actionadmin_menularbous-floating-menu.php:60
actionadmin_initlarbous-floating-menu.php:61
actionadmin_enqueue_scriptslarbous-floating-menu.php:79
actionwp_enqueue_scriptslarbous-floating-menu.php:98
Maintenance & Trust

Larbous Floating Menu Maintenance & Trust

Maintenance Signals

WordPress version tested3.9.40
Last updatedAug 25, 2014
PHP min version
Downloads5K

Community Trust

Rating60/100
Number of ratings2
Active installs10
Developer Profile

Larbous Floating Menu Developer Profile

Luiz Sobral

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Larbous Floating Menu

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/larbous-floating-menu/css/style.css
Script Paths
/wp-content/plugins/larbous-floating-menu/js/admin.js

HTML / DOM Fingerprints

CSS Classes
lbfm-colorpicker
Data Attributes
name="lbfm_menu"name="lbfm_width"name="lbfm_height"name="lbfm_position"name="lbfm_font_color"name="lbfm_font_color_hover"+3 more
FAQ

Frequently Asked Questions about Larbous Floating Menu