
AStickyPostOrderER Show Sticky Security & Risk Analysis
wordpress.org/plugins/astickypostorderer-show-stickyAdds a new column to the posts table in the admin to display if a post is sticky or not.
Is AStickyPostOrderER Show Sticky Safe to Use in 2026?
Generally Safe
Score 85/100AStickyPostOrderER Show Sticky has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "astickypostorderer-show-sticky" version 1.2 exhibits a strong focus on security based on the provided static analysis. The absence of any identified entry points like AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the attack surface. Furthermore, the absence of dangerous functions, file operations, and external HTTP requests further bolsters its security posture. No taint analysis results indicating vulnerabilities were found, and the plugin has no recorded vulnerability history, which is a very positive sign.
However, the analysis does reveal some areas for improvement. The single SQL query is not using prepared statements, which, while not necessarily a vulnerability in isolation given the lack of entry points, represents a deviation from best practices and could become a risk if new entry points are introduced or the query's context changes. Similarly, the single output is not properly escaped. While the lack of exploitable entry points mitigates the immediate risk, this could lead to Cross-Site Scripting (XSS) vulnerabilities if the plugin's functionality were to be extended or integrated in a way that exposes this output to user-controlled data. The complete absence of nonce and capability checks is also a concern for general security hygiene, as these are fundamental WordPress security mechanisms.
Key Concerns
- SQL queries not using prepared statements
- Output not properly escaped
- Missing nonce checks
- Missing capability checks
AStickyPostOrderER Show Sticky Security Vulnerabilities
AStickyPostOrderER Show Sticky Code Analysis
SQL Query Safety
Output Escaping
AStickyPostOrderER Show Sticky Attack Surface
WordPress Hooks 3
Maintenance & Trust
AStickyPostOrderER Show Sticky Maintenance & Trust
Maintenance Signals
Community Trust
AStickyPostOrderER Show Sticky Alternatives
Admin Show Sticky
admin-show-sticky
Adds a new column to the posts table in the admin to display if a post is sticky or not.
Catch IDs
catch-ids
What this plugin does is to shows the IDs on admin section.
Hide Admin Menu
hide-admin-menu
Using this plugin, we can hide the admin menu easily.
Catch Web Tools
catch-web-tools
A top-notch modular plugin that can greatly enhance the capabilities of a WordPress website with its powerful features.
ShowID for Post/Page/Category/Tag/Comment
showid-for-postpagecategorytagcomment
This plugin shows post/page/category/tag/comment/media/user IDs on admin's edit post/page/category/tag/comment/media/user pages.
AStickyPostOrderER Show Sticky Developer Profile
1 plugin · 20 total installs
How We Detect AStickyPostOrderER Show Sticky
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
sticky