
WP Category Sticky Posts Security & Risk Analysis
wordpress.org/plugins/category-sticky-postsAllows you to set Sticky posts for individual category archives.
Is WP Category Sticky Posts Safe to Use in 2026?
Generally Safe
Score 85/100WP Category Sticky Posts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "category-sticky-posts" plugin v0.13 exhibits a strong security posture based on the provided static analysis. There are no identified vulnerabilities in its vulnerability history, and the static analysis reveals a very clean codebase with no dangerous functions, no SQL queries that aren't prepared, and no file operations. The absence of external HTTP requests further reduces the attack surface. Furthermore, the plugin implements nonce and capability checks, which are crucial for secure WordPress development.
However, a significant concern arises from the output escaping. With 0% of outputs being properly escaped, this plugin presents a clear risk of Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data that is displayed on the frontend without proper sanitization or escaping could be exploited by attackers. While the taint analysis shows no flows, this is likely due to the limited scope of the analysis or the absence of complex data handling that would trigger taint detection. The lack of recorded vulnerabilities in its history is positive, but the current risk of unescaped output is a serious, albeit common, oversight that needs immediate attention. The plugin has strengths in its controlled entry points and use of prepared statements, but the lack of output escaping is a critical weakness.
Key Concerns
- Output escaping is not properly handled (0%)
WP Category Sticky Posts Security Vulnerabilities
WP Category Sticky Posts Release Timeline
WP Category Sticky Posts Code Analysis
Output Escaping
WP Category Sticky Posts Attack Surface
WordPress Hooks 8
Maintenance & Trust
WP Category Sticky Posts Maintenance & Trust
Maintenance Signals
Community Trust
WP Category Sticky Posts Alternatives
Category Order and Taxonomy Terms Order
taxonomy-terms-order
Drag-and-drop ordering for Categories & any taxonomy (hierarchically) using a Drag and Drop Sortable JavaScript capability.
No Category Base (WPML)
no-category-base-wpml
This plugin removes the mandatory 'Category Base' from your category permalinks. It's compatible with WPML.
Pages with category and tag
pages-with-category-and-tag
Add Categories and Tags to Pages.
Remove Category URL – Remove 'category' base from category permalinks
remove-category-url
Remove Category URL strips the /category/ base from your category URLs, turning something like /category/my-category/ into simply /my-category/.
Categories Images
categories-images
The Categories Images is a Wordpress plugin allow you to add image to category, tag or custom taxonomy.
WP Category Sticky Posts Developer Profile
4 plugins · 140 total installs
How We Detect WP Category Sticky Posts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/category-sticky-posts/js/bz_sticky_categories.js/wp-content/plugins/category-sticky-posts/css/bz_sticky_categories.css/wp-content/plugins/category-sticky-posts/js/bz_sticky_categories.jscategory-sticky-posts/js/bz_sticky_categories.js?ver=category-sticky-posts/css/bz_sticky_categories.css?ver=HTML / DOM Fingerprints
bz-wp-multiselectbz-category-sticky-multiselectcategory_sticky_postname="bz_post_sticky_categories[]"