
WP Floating Menu Framework Security & Risk Analysis
wordpress.org/plugins/wp-floating-menu-frameworkThe plugin is the framework for setting up the floating menu in WordPress.
Is WP Floating Menu Framework Safe to Use in 2026?
Generally Safe
Score 85/100WP Floating Menu Framework has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of wp-floating-menu-framework v1.0.2 reveals a generally strong security posture with no identified critical vulnerabilities in the code. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is commendable. The plugin also demonstrates a good practice of utilizing prepared statements for its SQL queries and has a capability check in place. However, a significant concern arises from the very low percentage of properly escaped output (20%). This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data displayed on the frontend might not be adequately sanitized, allowing attackers to inject malicious scripts. The total lack of entry points (AJAX, REST API, shortcodes, cron events) is unusual and might suggest a very limited functionality or that the analysis might not have captured all potential interaction points. The plugin's vulnerability history is clean, with no known CVEs, which is a positive indicator. However, this could also be due to the limited attack surface or the relatively early version of the plugin. The primary risk remains the poor output escaping, which warrants immediate attention despite the otherwise clean analysis and history.
Key Concerns
- Low output escaping percentage
- No nonce checks detected
WP Floating Menu Framework Security Vulnerabilities
WP Floating Menu Framework Code Analysis
Output Escaping
WP Floating Menu Framework Attack Surface
WordPress Hooks 2
Maintenance & Trust
WP Floating Menu Framework Maintenance & Trust
Maintenance Signals
Community Trust
WP Floating Menu Framework Alternatives
Redux Framework
redux-framework
Redux is a simple, truly extensible, and fully responsive options framework for WordPress themes and plugins. It ships with an integrated demo.
Kirki Customizer Framework
kirki
The Ultimate Customizer Framework for WordPress Theme Developers
Sticky Menu & Sticky Header
sticky-menu-or-anything-on-scroll
Sticky Menu or Sticky Header sticks elements at the top of the screen when you scroll, or create a floating sticky menu or fixed widget.
Float menu – awesome floating side menu
float-menu
Easily create floating menus of varying complexity. Use its capabilities to place unique navigation on the site.
Bootstrap for Contact Form 7
bootstrap-for-contact-form-7
This plugin modifies the output of the popular Contact Form 7 plugin to be styled in compliance with themes using the Bootstrap CSS framework.
WP Floating Menu Framework Developer Profile
9 plugins · 54K total installs
How We Detect WP Floating Menu Framework
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-floating-menu-framework/js/floating-menu.js/wp-content/plugins/wp-floating-menu-framework/js/templates/floating-menu.js/wp-content/plugins/wp-floating-menu-framework/js/floating-menu.jsHTML / DOM Fingerprints
wp-floating-menu-framework_updatedname="selected_js_file"