
Dear Sticky – Floating Action Buttons, Sticky Notifications & Navbar Security & Risk Analysis
wordpress.org/plugins/dear-stickyAdd floating action buttons, sticky notifications & announcement bars. Connect via WhatsApp, collect feedback & boost engagement.
Is Dear Sticky – Floating Action Buttons, Sticky Notifications & Navbar Safe to Use in 2026?
Generally Safe
Score 100/100Dear Sticky – Floating Action Buttons, Sticky Notifications & Navbar has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "dear-sticky" plugin v1.1.1 exhibits a generally strong security posture based on the provided static analysis. The absence of detected dangerous functions, file operations, and external HTTP requests is a positive indicator. The plugin also demonstrates good practices in its use of prepared statements for SQL queries (80%) and proper output escaping (99%), significantly reducing the risk of common vulnerabilities like SQL injection and cross-site scripting.
However, a few areas warrant attention. While the attack surface is small with only two AJAX handlers, the analysis does not explicitly state if these handlers are protected by nonce checks. The presence of a single nonce check and five capability checks suggests some security measures are in place, but a lack of clarity on the protection of AJAX endpoints could be a potential weakness. The zero taint analysis results are excellent, indicating no observable unsanitized data flows within the analyzed code.
Given the complete absence of recorded historical vulnerabilities, this plugin appears to have a robust track record. In conclusion, "dear-sticky" v1.1.1 shows a commendable focus on secure coding practices, particularly in database interactions and output handling. The primary area for potential improvement or further scrutiny lies in ensuring all entry points, especially AJAX handlers, are adequately protected with appropriate authentication and authorization mechanisms.
Key Concerns
- Unclear AJAX endpoint protection
Dear Sticky – Floating Action Buttons, Sticky Notifications & Navbar Security Vulnerabilities
Dear Sticky – Floating Action Buttons, Sticky Notifications & Navbar Code Analysis
SQL Query Safety
Output Escaping
Dear Sticky – Floating Action Buttons, Sticky Notifications & Navbar Attack Surface
AJAX Handlers 2
WordPress Hooks 7
Maintenance & Trust
Dear Sticky – Floating Action Buttons, Sticky Notifications & Navbar Maintenance & Trust
Maintenance Signals
Community Trust
Dear Sticky – Floating Action Buttons, Sticky Notifications & Navbar Alternatives
Bubble Chat
bubble-chat
Add a bubble chat so your users can contact you directly faster and more efficiently
GreenEcho Floating Chat Button
greenecho-chat-button
Best lightweight WhatsApp Chat button for WordPress. Add a professional Floating Button and Click to Chat feature to connect with customers instantly.
WBJet-HelloTap
wbjet-hellotap
Boost your leads and sales! Add beautiful, customizable floating WhatsApp and Call buttons to your WordPress website in seconds.
Click to Chat – HoliThemes
click-to-chat-for-whatsapp
WhatsApp Chat🔥. Let's make your Web page visitors contact you through 'WhatsApp', 'WhatsApp Business'. Add matching Widget✅
Joinchat
creame-whatsapp-me
WhatsApp, Messenger, Telegram, Phone call… capture users through their favorite Apps and turn into clients
Dear Sticky – Floating Action Buttons, Sticky Notifications & Navbar Developer Profile
2 plugins · 0 total installs
How We Detect Dear Sticky – Floating Action Buttons, Sticky Notifications & Navbar
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/dear-sticky/assets/css/dear-sticky.css/wp-content/plugins/dear-sticky/assets/js/dear-sticky-admin.js/wp-content/plugins/dear-sticky/assets/js/dear-sticky-frontend.js/wp-content/plugins/dear-sticky/assets/js/dear-sticky-admin.js/wp-content/plugins/dear-sticky/assets/js/dear-sticky-frontend.jsdear-sticky/assets/css/dear-sticky.css?ver=dear-sticky/assets/js/dear-sticky-admin.js?ver=dear-sticky/assets/js/dear-sticky-frontend.js?ver=HTML / DOM Fingerprints
drstk-feedback-formdrstk-sticky-buttondrstk-notification-bardata-drstk-enableddata-drstk-settingsDearStickyFrontend/wp-json/dear-sticky/v1/submit-feedback