
Catch Sticky Menu Security & Risk Analysis
wordpress.org/plugins/catch-sticky-menuCatch Sticky Menu is a lightweight, simple yet feature-rich free WordPress plugin for sticky menu that allows you to lock the menu on your website.
Is Catch Sticky Menu Safe to Use in 2026?
Generally Safe
Score 100/100Catch Sticky Menu has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "catch-sticky-menu" version 1.8 exhibits a strong security posture based on the provided static analysis and vulnerability history. The code analysis reveals no dangerous functions, no SQL queries using raw SQL, and an exceptionally high percentage of properly escaped output. Furthermore, the presence of numerous nonce and capability checks on its entry points, particularly the AJAX handlers, indicates a proactive approach to access control. The absence of any known CVEs and the lack of recorded historical vulnerabilities further bolster confidence in its security.
However, while the overall picture is positive, it's important to acknowledge potential, albeit currently unproven, risks. The presence of three AJAX handlers, even though they appear to have authorization checks, represents an attack surface. Without the full context of these checks, there's a theoretical, though unlikely given the other data, possibility of bypass. The taint analysis showing zero flows is excellent but relies on the completeness of the analysis. If the analysis scope was limited or certain complex interactions were not captured, subtle vulnerabilities might exist.
In conclusion, "catch-sticky-menu" v1.8 appears to be a very secure plugin. The developers have implemented good security practices. The lack of historical vulnerabilities and the clean static analysis results are significant strengths. The only minor points of caution would be the theoretical possibility of issues within the AJAX handlers that are not immediately apparent from this report's scope, and the reliance on the thoroughness of the taint analysis.
Catch Sticky Menu Security Vulnerabilities
Catch Sticky Menu Code Analysis
Output Escaping
Catch Sticky Menu Attack Surface
AJAX Handlers 3
WordPress Hooks 17
Maintenance & Trust
Catch Sticky Menu Maintenance & Trust
Maintenance Signals
Community Trust
Catch Sticky Menu Alternatives
Float menu – awesome floating side menu
float-menu
Easily create floating menus of varying complexity. Use its capabilities to place unique navigation on the site.
WP Mobile Bottom Menu
mobile-bottom-menu-for-wp
Smooth Navigation for Mobile. Create an Eye-Catching Sticky Bottom Menu with Limitless Customization Options.
All-in-One Sticky Anything – Fixed Widget, Sticky Header, Menu, Sidebar, Social Icons & Cookie Consent
all-in-one-wp-sticky-anything
All-in-One Sticky Anything easily creates fixed widgets, sticky elements, sticky header, menu, sidebar, social icons & cookie consent on your website.
Fixed And Sticky Header
fixed-and-sticky-header
This plugin will made your header or menu fixed and sticky.
Sticky Header by ThematoSoup
sticky-header
Sticky Header by ThematoSoup allows you to add sticky header to any WordPress theme.
Catch Sticky Menu Developer Profile
155 plugins · 226K total installs
How We Detect Catch Sticky Menu
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/catch-sticky-menu/includes/css/catch-sticky-menu-admin.css/wp-content/plugins/catch-sticky-menu/public/css/catch-sticky-menu-public.css/wp-content/plugins/catch-sticky-menu/public/js/catch-sticky-menu-public.jsincludes/css/catch-sticky-menu-admin.csspublic/css/catch-sticky-menu-public.csspublic/js/catch-sticky-menu-public.jscatch-sticky-menu/includes/css/catch-sticky-menu-admin.css?ver=catch-sticky-menu/public/css/catch-sticky-menu-public.css?ver=catch-sticky-menu/public/js/catch-sticky-menu-public.js?ver=HTML / DOM Fingerprints
catch-sticky-menu-activedata-sticky-desktop-menu-selectordata-sticky-mobile-menu-selectordata-sticky-background-colordata-sticky-text-colordata-sticky-z-indexdata-sticky-opacity+3 morecatchStickyMenu