
Smart Floating / Sticky Buttons For Post and Page Read Status Security & Risk Analysis
wordpress.org/plugins/post-read-unread-floating-sticky-buttonSmart Floating / Sticky Buttons used to get the read status of the post or page or any custom post if user reach at the end of post.
Is Smart Floating / Sticky Buttons For Post and Page Read Status Safe to Use in 2026?
Generally Safe
Score 85/100Smart Floating / Sticky Buttons For Post and Page Read Status has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "post-read-unread-floating-sticky-button" v1.0 exhibits a mixed security posture. While it has a very small attack surface and no recorded vulnerability history, suggesting good maintenance and minimal exposure, the static code analysis reveals significant concerns. Specifically, the taint analysis indicates a high severity flow with unsanitized paths, which could be exploited for injection attacks. Furthermore, the plugin demonstrates poor output escaping practices, with only 25% of outputs being properly sanitized, leaving it vulnerable to Cross-Site Scripting (XSS) attacks. The lack of capability checks on its single AJAX handler is also a notable weakness, as it means any logged-in user could potentially trigger this functionality without proper authorization.
Key Concerns
- High severity taint flow with unsanitized path
- Poor output escaping (25% properly escaped)
- No capability checks on AJAX handler
Smart Floating / Sticky Buttons For Post and Page Read Status Security Vulnerabilities
Smart Floating / Sticky Buttons For Post and Page Read Status Release Timeline
Smart Floating / Sticky Buttons For Post and Page Read Status Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Smart Floating / Sticky Buttons For Post and Page Read Status Attack Surface
AJAX Handlers 1
WordPress Hooks 3
Maintenance & Trust
Smart Floating / Sticky Buttons For Post and Page Read Status Maintenance & Trust
Maintenance Signals
Community Trust
Smart Floating / Sticky Buttons For Post and Page Read Status Alternatives
Simple Floating Menu
simple-floating-menu
Simple Floating Menu add a simple floating button with various layouts and settings.
Sticky Buttons – Floating Buttons Builder
sticky-buttons
Increase user engagement by incorporating sticky buttons that highlight relevant information on your website.
WP Sticky Button – Click to Chat
wa-sticky-button
Display the beautiful WhatsApp Sticky Button on the WordPress frontend.
WP CTA – Call Now Button, Sticky Button & Call to Action Builder
easy-sticky-sidebar
WordPress Call To Action builder that creates sticky buttons, call now buttons and CTAs to boost clicks, increase sales and generate leads.
WP Click to Chat – Email, Live Chat, Call & Book Now Buttons
support-chat
Offer unlimited chat apps and support channels to your WordPress website.
Smart Floating / Sticky Buttons For Post and Page Read Status Developer Profile
2 plugins · 0 total installs
How We Detect Smart Floating / Sticky Buttons For Post and Page Read Status
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/post-read-unread-floating-sticky-button/assets/css/veemain.css/wp-content/plugins/post-read-unread-floating-sticky-button/assets/js/main.js/wp-content/plugins/post-read-unread-floating-sticky-button/assets/js/main.jspost-read-unread-floating-sticky-button/assets/css/veemain.css?ver=post-read-unread-floating-sticky-button/assets/js/main.js?ver=HTML / DOM Fingerprints
read_unreadvee_plugin_ajax_object<div id="read_unread">Already read!</div>