Catch Sticky Menu Security & Risk Analysis

wordpress.org/plugins/catch-sticky-menu

Catch Sticky Menu is a lightweight, simple yet feature-rich free WordPress plugin for sticky menu that allows you to lock the menu on your website.

2K active installs v1.8 PHP + WP 5.9+ Updated Feb 24, 2026
fixednavigationstickysticky-menu
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Catch Sticky Menu Safe to Use in 2026?

Generally Safe

Score 100/100

Catch Sticky Menu has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The plugin "catch-sticky-menu" version 1.8 exhibits a strong security posture based on the provided static analysis and vulnerability history. The code analysis reveals no dangerous functions, no SQL queries using raw SQL, and an exceptionally high percentage of properly escaped output. Furthermore, the presence of numerous nonce and capability checks on its entry points, particularly the AJAX handlers, indicates a proactive approach to access control. The absence of any known CVEs and the lack of recorded historical vulnerabilities further bolster confidence in its security.

However, while the overall picture is positive, it's important to acknowledge potential, albeit currently unproven, risks. The presence of three AJAX handlers, even though they appear to have authorization checks, represents an attack surface. Without the full context of these checks, there's a theoretical, though unlikely given the other data, possibility of bypass. The taint analysis showing zero flows is excellent but relies on the completeness of the analysis. If the analysis scope was limited or certain complex interactions were not captured, subtle vulnerabilities might exist.

In conclusion, "catch-sticky-menu" v1.8 appears to be a very secure plugin. The developers have implemented good security practices. The lack of historical vulnerabilities and the clean static analysis results are significant strengths. The only minor points of caution would be the theoretical possibility of issues within the AJAX handlers that are not immediately apparent from this report's scope, and the reliance on the thoroughness of the taint analysis.

Vulnerabilities
None known

Catch Sticky Menu Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Catch Sticky Menu Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
64 escaped
Nonce Checks
4
Capability Checks
9
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

94% escaped68 total outputs
Attack Surface

Catch Sticky Menu Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 3

authwp_ajax_query-themesincludes\CatchThemesThemePlugin.php:11
authwp_ajax_customize_load_themesincludes\CatchThemesThemePlugin.php:21
authwp_ajax_ctp_switchincludes\ctp-tabs-removal.php:85
WordPress Hooks 17
actionadmin_enqueue_scriptsincludes\CatchThemesThemePlugin.php:13
actioncustomize_registerincludes\CatchThemesThemePlugin.php:16
filterinstall_plugins_tabsincludes\CatchThemesThemePlugin.php:23
filterinstall_plugins_table_api_args_catchpluginsincludes\CatchThemesThemePlugin.php:24
actioninstall_plugins_catchpluginsincludes\CatchThemesThemePlugin.php:25
actionplugins_loadedincludes\class-catch-sticky-menu.php:134
actionadmin_enqueue_scriptsincludes\class-catch-sticky-menu.php:149
actionadmin_enqueue_scriptsincludes\class-catch-sticky-menu.php:150
actionadmin_menuincludes\class-catch-sticky-menu.php:151
actionadmin_initincludes\class-catch-sticky-menu.php:152
filterplugin_action_linksincludes\class-catch-sticky-menu.php:153
filterplugin_row_metaincludes\class-catch-sticky-menu.php:154
actionwp_enqueue_scriptsincludes\class-catch-sticky-menu.php:169
actionwp_enqueue_scriptsincludes\class-catch-sticky-menu.php:170
actionwp_enqueue_scriptsincludes\class-catch-sticky-menu.php:171
actionwp_localize_scriptincludes\class-catch-sticky-menu.php:172
actionadmin_initincludes\ctp-tabs-removal.php:17
Maintenance & Trust

Catch Sticky Menu Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 24, 2026
PHP min version
Downloads45K

Community Trust

Rating100/100
Number of ratings15
Active installs2K
Developer Profile

Catch Sticky Menu Developer Profile

Catch Themes

155 plugins · 226K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
251 days
View full developer profile
Detection Fingerprints

How We Detect Catch Sticky Menu

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/catch-sticky-menu/includes/css/catch-sticky-menu-admin.css/wp-content/plugins/catch-sticky-menu/public/css/catch-sticky-menu-public.css/wp-content/plugins/catch-sticky-menu/public/js/catch-sticky-menu-public.js
Script Paths
includes/css/catch-sticky-menu-admin.csspublic/css/catch-sticky-menu-public.csspublic/js/catch-sticky-menu-public.js
Version Parameters
catch-sticky-menu/includes/css/catch-sticky-menu-admin.css?ver=catch-sticky-menu/public/css/catch-sticky-menu-public.css?ver=catch-sticky-menu/public/js/catch-sticky-menu-public.js?ver=

HTML / DOM Fingerprints

CSS Classes
catch-sticky-menu-active
Data Attributes
data-sticky-desktop-menu-selectordata-sticky-mobile-menu-selectordata-sticky-background-colordata-sticky-text-colordata-sticky-z-indexdata-sticky-opacity+3 more
JS Globals
catchStickyMenu
FAQ

Frequently Asked Questions about Catch Sticky Menu