Astro Sticky Buttons Security & Risk Analysis

wordpress.org/plugins/astro-sticky-buttons

Add sticky buttons for easy contact and social sharing on your site. Supports email, phone, WhatsApp, Skype, Facebook, Instagram, and more.

10 active installs v1.3.0 PHP 7.4+ WP 5.2+ Updated Oct 31, 2025
email-buttonfloating-buttonssticky-buttonstelephone-buttonwhatsapp-button
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Astro Sticky Buttons Safe to Use in 2026?

Generally Safe

Score 100/100

Astro Sticky Buttons has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The "astro-sticky-buttons" v1.3.0 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of any critical or high severity taint flows, along with the complete use of prepared statements for SQL queries and proper output escaping for the vast majority of outputs, indicates good development practices regarding data sanitization and protection against common web vulnerabilities. The presence of nonce and capability checks on the identified entry points further reinforces this positive assessment, suggesting an effort to restrict access to potentially sensitive actions.

Despite the overall good standing, the plugin has a single shortcode as its sole entry point, which is not explicitly protected by authentication checks in the provided data. While this shortcode may not inherently carry significant risk, the lack of specific authorization for it represents a minor concern. The plugin's vulnerability history is also a strong positive, with zero recorded CVEs, suggesting a well-maintained and secure codebase over time.

In conclusion, "astro-sticky-buttons" v1.3.0 appears to be a secure plugin with robust coding practices. The main area for potential improvement is ensuring that even single entry points like shortcodes have appropriate access control mechanisms in place, although the risk associated with this specific shortcode is not explicitly defined as high without further context. The lack of historical vulnerabilities is a significant strength, indicating reliability.

Key Concerns

  • Single entry point (shortcode) potentially lacking specific auth checks
Vulnerabilities
None known

Astro Sticky Buttons Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Astro Sticky Buttons Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
8
446 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

98% escaped454 total outputs
Attack Surface

Astro Sticky Buttons Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[astro-sticky-buttons] astro-sticky-buttons-common.php:110
WordPress Hooks 7
actionadmin_enqueue_scriptsastro-sticky-buttons-admin.php:51
actionadmin_initastro-sticky-buttons-admin.php:114
actionastro_plugin_panel_pagesastro-sticky-buttons-admin.php:121
actionwp_footerastro-sticky-buttons-common.php:232
actioninitastro-sticky-buttons.php:44
actioninitastro-sticky-buttons.php:52
actionadmin_menuincludes\classes\class-astro-plugin-panel.php:16
Maintenance & Trust

Astro Sticky Buttons Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 31, 2025
PHP min version7.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Astro Sticky Buttons Developer Profile

Mojtaba Amalian

5 plugins · 50 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Astro Sticky Buttons

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/astro-sticky-buttons/css/astro-sticky-buttons.css/wp-content/plugins/astro-sticky-buttons/js/astro-sticky-buttons.js
Script Paths
/wp-content/plugins/astro-sticky-buttons/js/astro-sticky-buttons.js
Version Parameters
astro-sticky-buttons/css/astro-sticky-buttons.css?ver=astro-sticky-buttons/js/astro-sticky-buttons.js?ver=

HTML / DOM Fingerprints

CSS Classes
astro-sticky-buttons
Data Attributes
data-astro-sb
JS Globals
astro_sb_frontend_options
FAQ

Frequently Asked Questions about Astro Sticky Buttons