Dear Sticky – Floating Action Buttons, Sticky Notifications & Navbar Security & Risk Analysis

wordpress.org/plugins/dear-sticky

Add floating action buttons, sticky notifications & announcement bars. Connect via WhatsApp, collect feedback & boost engagement.

0 active installs v1.1.1 PHP 7.2+ WP 5.2+ Updated Unknown
feedback-formfloating-buttonnotification-barsticky-navbarwhatsapp-chat
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Dear Sticky – Floating Action Buttons, Sticky Notifications & Navbar Safe to Use in 2026?

Generally Safe

Score 100/100

Dear Sticky – Floating Action Buttons, Sticky Notifications & Navbar has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "dear-sticky" plugin v1.1.1 exhibits a generally strong security posture based on the provided static analysis. The absence of detected dangerous functions, file operations, and external HTTP requests is a positive indicator. The plugin also demonstrates good practices in its use of prepared statements for SQL queries (80%) and proper output escaping (99%), significantly reducing the risk of common vulnerabilities like SQL injection and cross-site scripting.

However, a few areas warrant attention. While the attack surface is small with only two AJAX handlers, the analysis does not explicitly state if these handlers are protected by nonce checks. The presence of a single nonce check and five capability checks suggests some security measures are in place, but a lack of clarity on the protection of AJAX endpoints could be a potential weakness. The zero taint analysis results are excellent, indicating no observable unsanitized data flows within the analyzed code.

Given the complete absence of recorded historical vulnerabilities, this plugin appears to have a robust track record. In conclusion, "dear-sticky" v1.1.1 shows a commendable focus on secure coding practices, particularly in database interactions and output handling. The primary area for potential improvement or further scrutiny lies in ensuring all entry points, especially AJAX handlers, are adequately protected with appropriate authentication and authorization mechanisms.

Key Concerns

  • Unclear AJAX endpoint protection
Vulnerabilities
None known

Dear Sticky – Floating Action Buttons, Sticky Notifications & Navbar Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Dear Sticky – Floating Action Buttons, Sticky Notifications & Navbar Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
8 prepared
Unescaped Output
1
133 escaped
Nonce Checks
1
Capability Checks
5
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

80% prepared10 total queries

Output Escaping

99% escaped134 total outputs
Attack Surface

Dear Sticky – Floating Action Buttons, Sticky Notifications & Navbar Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_drstk_submit_feedbackincludes\class-api.php:50
noprivwp_ajax_drstk_submit_feedbackincludes\class-api.php:51
WordPress Hooks 7
actioninitdear-sticky.php:72
actionadmin_menuincludes\class-admin.php:49
actionadmin_enqueue_scriptsincludes\class-admin.php:50
actionrest_api_initincludes\class-api.php:49
actionwp_enqueue_scriptsincludes\class-frontend.php:53
actionwp_footerincludes\class-frontend.php:58
actionwp_body_openincludes\class-frontend.php:63
Maintenance & Trust

Dear Sticky – Floating Action Buttons, Sticky Notifications & Navbar Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedUnknown
PHP min version7.2
Downloads182

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Dear Sticky – Floating Action Buttons, Sticky Notifications & Navbar Developer Profile

Sanchit Pandey

2 plugins · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Dear Sticky – Floating Action Buttons, Sticky Notifications & Navbar

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/dear-sticky/assets/css/dear-sticky.css/wp-content/plugins/dear-sticky/assets/js/dear-sticky-admin.js/wp-content/plugins/dear-sticky/assets/js/dear-sticky-frontend.js
Script Paths
/wp-content/plugins/dear-sticky/assets/js/dear-sticky-admin.js/wp-content/plugins/dear-sticky/assets/js/dear-sticky-frontend.js
Version Parameters
dear-sticky/assets/css/dear-sticky.css?ver=dear-sticky/assets/js/dear-sticky-admin.js?ver=dear-sticky/assets/js/dear-sticky-frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
drstk-feedback-formdrstk-sticky-buttondrstk-notification-bar
Data Attributes
data-drstk-enableddata-drstk-settings
JS Globals
DearStickyFrontend
REST Endpoints
/wp-json/dear-sticky/v1/submit-feedback
FAQ

Frequently Asked Questions about Dear Sticky – Floating Action Buttons, Sticky Notifications & Navbar