YTS Floating action button Security & Risk Analysis

wordpress.org/plugins/yts-floating-action-button

A Basic floating action button plugin for your website.

10 active installs v1.0.6 PHP + WP 3.0.1+ Updated Nov 8, 2022
action-buttonfabfloating-action-buttonwhatsapp-button
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is YTS Floating action button Safe to Use in 2026?

Generally Safe

Score 85/100

YTS Floating action button has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "yts-floating-action-button" plugin v1.0.6 exhibits a strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface. The code also demonstrates good development practices by utilizing prepared statements for all SQL queries and performing a high percentage of output escaping. The lack of file operations and external HTTP requests further reduces potential vulnerabilities. Crucially, the plugin has no known vulnerability history, indicating a well-maintained or simply less-attacked codebase thus far.

The static analysis reveals a very low risk profile. There are no identified dangerous functions, no taint analysis findings, and a complete absence of nonce and capability checks. While the absence of these checks might seem like a weakness, it's mitigated by the plugin's extremely small attack surface. The lack of explicit authentication checks on entry points is less concerning given that there are no entry points identified in the first place. However, it's important to note that the lack of explicit capability checks on potential future entry points could become a concern if the plugin evolves.

In conclusion, the "yts-floating-action-button" plugin currently presents a very low security risk. Its minimal attack surface, sound coding practices regarding SQL and output escaping, and clean vulnerability history are all positive indicators. The absence of specific vulnerability types like taint flows or unpatched CVEs further strengthens its security. The primary area for potential future improvement, should the plugin's functionality expand, would be the explicit inclusion of capability checks on any new entry points.

Vulnerabilities
None known

YTS Floating action button Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

YTS Floating action button Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
23 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

92% escaped25 total outputs
Attack Surface

YTS Floating action button Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionplugins_loadedincludes\class-yts-fab.php:146
actionadmin_enqueue_scriptsincludes\class-yts-fab.php:161
actionadmin_enqueue_scriptsincludes\class-yts-fab.php:162
actionadmin_menuincludes\class-yts-fab.php:163
actionadmin_initincludes\class-yts-fab.php:164
actionwp_enqueue_scriptsincludes\class-yts-fab.php:179
actionwp_enqueue_scriptsincludes\class-yts-fab.php:180
actionet_before_main_contentincludes\class-yts-fab.php:183
actionwp_body_openincludes\class-yts-fab.php:186
Maintenance & Trust

YTS Floating action button Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedNov 8, 2022
PHP min version
Downloads877

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

YTS Floating action button Developer Profile

yigitus2

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect YTS Floating action button

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/yts-floating-action-button/admin/css/yts-fab-admin.css/wp-content/plugins/yts-floating-action-button/admin/js/yts-fab-admin.js
Script Paths
/wp-content/plugins/yts-floating-action-button/admin/js/yts-fab-admin.js
Version Parameters
yts-fab-admin-scriptyts-fab-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
wrapsettings-error
HTML Comments
Generated by the WordPress Option Page generator * at http://jeremyhixon.com/wp-tools/option-page/
Data Attributes
id="yts-fab-admin"name="yts_fab_option_name"id="yts_fab_setting_section"id="yts_fab_advanced_setting_section"id="isActive_0"id="text_1"+14 more
FAQ

Frequently Asked Questions about YTS Floating action button