All-in-One Sticky Anything – Fixed Widget, Sticky Header, Menu, Sidebar, Social Icons & Cookie Consent Security & Risk Analysis

wordpress.org/plugins/all-in-one-wp-sticky-anything

All-in-One Sticky Anything easily creates fixed widgets, sticky elements, sticky header, menu, sidebar, social icons & cookie consent on your website.

1K active installs v1.1.1 PHP 7.4+ WP 5.0+ Updated Feb 6, 2026
fixed-sidebarsocial-iconssticky-headersticky-menusticky-sidebar
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is All-in-One Sticky Anything – Fixed Widget, Sticky Header, Menu, Sidebar, Social Icons & Cookie Consent Safe to Use in 2026?

Generally Safe

Score 100/100

All-in-One Sticky Anything – Fixed Widget, Sticky Header, Menu, Sidebar, Social Icons & Cookie Consent has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The plugin "all-in-one-wp-sticky-anything" version 1.1.1 exhibits a generally strong security posture based on the provided static analysis. It demonstrates good practices by not utilizing dangerous functions, performing all SQL queries using prepared statements, and having a significant majority (81%) of its outputs properly escaped. Furthermore, all identified entry points (3 AJAX handlers) include nonce checks, and the plugin implements capability checks for its functionalities, indicating an effort to control access. The absence of any recorded vulnerabilities in its history is also a positive sign, suggesting a mature and well-maintained codebase.

Despite the positive indicators, a complete absence of risk cannot be assumed. While the static analysis found no critical or high severity taint flows, and no unsanitized paths, the analysis of "flows with unsanitized paths" is limited to 2. This suggests a very small scope of analysis or very straightforward code, and doesn't necessarily guarantee the absence of such issues in more complex parts of the plugin. The 81% output escaping rate, while good, still leaves a portion of outputs unescaped. This could potentially lead to Cross-Site Scripting (XSS) vulnerabilities if sensitive data is involved and not handled correctly in the remaining 19% of outputs.

In conclusion, "all-in-one-wp-sticky-anything" v1.1.1 appears to be a securely developed plugin with robust security features like prepared statements and nonce checks. Its clean vulnerability history is a significant advantage. However, the minor unescaped outputs present a theoretical attack vector for XSS, and the limited taint analysis scope warrants a degree of caution. Overall, the risk is low, but continuous monitoring and updates are always recommended for any software.

Key Concerns

  • Outputs not properly escaped (19%)
Vulnerabilities
None known

All-in-One Sticky Anything – Fixed Widget, Sticky Header, Menu, Sidebar, Social Icons & Cookie Consent Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

All-in-One Sticky Anything – Fixed Widget, Sticky Header, Menu, Sidebar, Social Icons & Cookie Consent Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
9
38 escaped
Nonce Checks
3
Capability Checks
5
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

81% escaped47 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
save_settings (includes\Ajax.php:54)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

All-in-One Sticky Anything – Fixed Widget, Sticky Header, Menu, Sidebar, Social Icons & Cookie Consent Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 3

authwp_ajax_ai1wpsa_get_settingsincludes\Ajax.php:18
authwp_ajax_ai1wpsa_save_settingsincludes\Ajax.php:19
authwp_ajax_ai1wpsa_review_noticeincludes\Ajax.php:22
WordPress Hooks 19
actionplugins_loadedall-in-one-wp-sticky-anything.php:51
actionadmin_menuincludes\Admin.php:18
actionadmin_initincludes\Admin.php:21
actioncustomize_registerincludes\Customizer.php:15
actionelementor/element/container/section_effects/after_section_endincludes\Elementor.php:23
actionelementor/element/section/section_effects/after_section_endincludes\Elementor.php:24
actionwp_enqueue_scriptsincludes\Enqueue.php:13
actioncustomize_preview_initincludes\Enqueue.php:16
actionadmin_enqueue_scriptsincludes\Enqueue.php:19
actionenqueue_block_editor_assetsincludes\Enqueue.php:22
actionwp_print_stylesincludes\Hooks.php:15
actionwp_footerincludes\Hooks.php:16
actionwp_footerincludes\Hooks.php:17
actionin_widget_formincludes\Hooks.php:19
actionwidget_update_callbackincludes\Hooks.php:20
filterdynamic_sidebar_paramsincludes\Hooks.php:21
actionadmin_noticesincludes\Main.php:56
actionadmin_noticesincludes\Main.php:58
actioninitincludes\Main.php:61
Maintenance & Trust

All-in-One Sticky Anything – Fixed Widget, Sticky Header, Menu, Sidebar, Social Icons & Cookie Consent Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 6, 2026
PHP min version7.4
Downloads20K

Community Trust

Rating100/100
Number of ratings11
Active installs1K
Developer Profile

All-in-One Sticky Anything – Fixed Widget, Sticky Header, Menu, Sidebar, Social Icons & Cookie Consent Developer Profile

Monzur Alam

3 plugins · 1K total installs

92
trust score
Avg Security Score
97/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect All-in-One Sticky Anything – Fixed Widget, Sticky Header, Menu, Sidebar, Social Icons & Cookie Consent

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/all-in-one-wp-sticky-anything/assets/css/frontend.min.css/wp-content/plugins/all-in-one-wp-sticky-anything/assets/vendor/fontawesome/fontawesome.min.css/wp-content/plugins/all-in-one-wp-sticky-anything/assets/vendor/fontawesome/brands.min.css/wp-content/plugins/all-in-one-wp-sticky-anything/assets/vendor/bootstrap-icons/bootstrap-icons.min.css/wp-content/plugins/all-in-one-wp-sticky-anything/assets/vendor/remixicon/remixicon.min.css/wp-content/plugins/all-in-one-wp-sticky-anything/assets/vendor/lineicon/lineicons.min.css/wp-content/plugins/all-in-one-wp-sticky-anything/assets/vendor/stickr.min.js/wp-content/plugins/all-in-one-wp-sticky-anything/assets/vendor/theia-sticky-sidebar.js+7 more
Script Paths
/wp-content/plugins/all-in-one-wp-sticky-anything/assets/vendor/stickr.min.js/wp-content/plugins/all-in-one-wp-sticky-anything/assets/vendor/theia-sticky-sidebar.js/wp-content/plugins/all-in-one-wp-sticky-anything/assets/js/frontend.min.js/wp-content/plugins/all-in-one-wp-sticky-anything/assets/js/customizer.min.js/wp-content/plugins/all-in-one-wp-sticky-anything/assets/vendor/sweetalert2/sweetalert2.min.js/wp-content/plugins/all-in-one-wp-sticky-anything/assets/js/admin.min.js+1 more
Version Parameters
/wp-content/plugins/all-in-one-wp-sticky-anything/assets/css/frontend.min.css?ver=/wp-content/plugins/all-in-one-wp-sticky-anything/assets/css/admin.min.css?ver=/wp-content/plugins/all-in-one-wp-sticky-anything/assets/js/admin.min.js?ver=/wp-content/plugins/all-in-one-wp-sticky-anything/assets/js/frontend.min.js?ver=/wp-content/plugins/all-in-one-wp-sticky-anything/assets/js/block-editor.min.js?ver=/wp-content/plugins/all-in-one-wp-sticky-anything/assets/js/customizer.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
ai1wpsa-frontend
Data Attributes
data-ai1wpsa-sticky
JS Globals
ai1wpsa
FAQ

Frequently Asked Questions about All-in-One Sticky Anything – Fixed Widget, Sticky Header, Menu, Sidebar, Social Icons & Cookie Consent