
Surface Kit – The All in One Engagement Platform. Sticky Headers, Floating Buttons, AI Chatbot, Popups Security & Risk Analysis
wordpress.org/plugins/dear-stickyOne plugin replaces 5-7 engagement tools. AI chatbot, sticky navigation, floating buttons, and smart popups in a single unified dashboard.
Is Surface Kit – The All in One Engagement Platform. Sticky Headers, Floating Buttons, AI Chatbot, Popups Safe to Use in 2026?
Generally Safe
Score 100/100Surface Kit – The All in One Engagement Platform. Sticky Headers, Floating Buttons, AI Chatbot, Popups has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "dear-sticky" plugin v1.1.1 exhibits a generally strong security posture based on the provided static analysis. The absence of detected dangerous functions, file operations, and external HTTP requests is a positive indicator. The plugin also demonstrates good practices in its use of prepared statements for SQL queries (80%) and proper output escaping (99%), significantly reducing the risk of common vulnerabilities like SQL injection and cross-site scripting.
However, a few areas warrant attention. While the attack surface is small with only two AJAX handlers, the analysis does not explicitly state if these handlers are protected by nonce checks. The presence of a single nonce check and five capability checks suggests some security measures are in place, but a lack of clarity on the protection of AJAX endpoints could be a potential weakness. The zero taint analysis results are excellent, indicating no observable unsanitized data flows within the analyzed code.
Given the complete absence of recorded historical vulnerabilities, this plugin appears to have a robust track record. In conclusion, "dear-sticky" v1.1.1 shows a commendable focus on secure coding practices, particularly in database interactions and output handling. The primary area for potential improvement or further scrutiny lies in ensuring all entry points, especially AJAX handlers, are adequately protected with appropriate authentication and authorization mechanisms.
Key Concerns
- Unclear AJAX endpoint protection
Surface Kit – The All in One Engagement Platform. Sticky Headers, Floating Buttons, AI Chatbot, Popups Security Vulnerabilities
Surface Kit – The All in One Engagement Platform. Sticky Headers, Floating Buttons, AI Chatbot, Popups Release Timeline
Surface Kit – The All in One Engagement Platform. Sticky Headers, Floating Buttons, AI Chatbot, Popups Code Analysis
SQL Query Safety
Output Escaping
Surface Kit – The All in One Engagement Platform. Sticky Headers, Floating Buttons, AI Chatbot, Popups Attack Surface
AJAX Handlers 2
WordPress Hooks 7
Maintenance & Trust
Surface Kit – The All in One Engagement Platform. Sticky Headers, Floating Buttons, AI Chatbot, Popups Maintenance & Trust
Maintenance Signals
Community Trust
Surface Kit – The All in One Engagement Platform. Sticky Headers, Floating Buttons, AI Chatbot, Popups Alternatives
Cognix AI
cognix-ai-bots
Get started with our AI-powered bots completely free during the trial period. Customize your bots to perfectly match your brand, and experience quick, …
Furie™ AI Chat / Live Handoff, Auto Engagement, and Lead Generation
furie-ai-chat-widget
Add a powerful AI chat widget to your site. Engage visitors, automate replies, capture leads, and boost conversions — FREE FOREVER.
Popup Builder – Create highly converting, mobile friendly marketing popups.
popup-builder
Increase Sales, Lead Generation, Conversion rates and receive good Call to Action rates with smart WordPress popup plugin.
Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers
popup-builder-block
Powerful Popup Builder Block for Gutenberg block editor.
WP ULike – Like & Dislike Buttons for Engagement and Feedback
wp-ulike
Voting buttons that let your visitors give instant feedback. See what your audience loves with no registration, no friction, just one click.
Surface Kit – The All in One Engagement Platform. Sticky Headers, Floating Buttons, AI Chatbot, Popups Developer Profile
2 plugins · 10 total installs
How We Detect Surface Kit – The All in One Engagement Platform. Sticky Headers, Floating Buttons, AI Chatbot, Popups
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/dear-sticky/assets/css/dear-sticky.css/wp-content/plugins/dear-sticky/assets/js/dear-sticky-admin.js/wp-content/plugins/dear-sticky/assets/js/dear-sticky-frontend.js/wp-content/plugins/dear-sticky/assets/js/dear-sticky-admin.js/wp-content/plugins/dear-sticky/assets/js/dear-sticky-frontend.jsdear-sticky/assets/css/dear-sticky.css?ver=dear-sticky/assets/js/dear-sticky-admin.js?ver=dear-sticky/assets/js/dear-sticky-frontend.js?ver=HTML / DOM Fingerprints
drstk-feedback-formdrstk-sticky-buttondrstk-notification-bardata-drstk-enableddata-drstk-settingsDearStickyFrontend/wp-json/dear-sticky/v1/submit-feedback