
Easy Sticky Buttons Security & Risk Analysis
wordpress.org/plugins/easy-sticky-buttonsWith the Easy Sticky Buttons plugin, you can add 1 to 4 sticky buttons at the bottom of your site's mobile view.
Is Easy Sticky Buttons Safe to Use in 2026?
Generally Safe
Score 85/100Easy Sticky Buttons has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "easy-sticky-buttons" v2.0.0 exhibits a strong security posture based on the provided static analysis. The absence of any identified attack surface entry points (AJAX handlers, REST API routes, shortcodes, cron events) is a significant strength, indicating a limited external interaction surface. Furthermore, the code shows good practices in handling SQL queries, with 100% using prepared statements, and a high rate of output escaping (88%), which mitigates common cross-site scripting (XSS) vulnerabilities. The lack of dangerous functions, file operations, external HTTP requests, and recorded vulnerabilities in its history further bolsters its security profile.
However, the analysis reveals some areas for potential concern. The complete absence of nonce checks and capability checks is a notable weakness. While the attack surface is currently zero, if any new entry points were introduced in future versions, the lack of these fundamental security mechanisms would expose the plugin to significant risks, particularly related to unauthorized actions and privilege escalation. The taint analysis indicating zero flows is positive, but the complete lack of analysis for flows and unsanitized paths suggests this might be an incomplete assessment rather than a guarantee of no taint issues.
In conclusion, "easy-sticky-buttons" v2.0.0 appears to be a securely coded plugin in its current state, with no known vulnerabilities or significant code-level risks. Its strengths lie in its limited attack surface and diligent use of prepared statements and output escaping. The primary weakness is the complete reliance on the absence of entry points for security, rather than implementing standard WordPress security checks like nonces and capability checks, which leaves it vulnerable should its attack surface expand.
Key Concerns
- Missing nonce checks
- Missing capability checks
- No taint analysis performed
Easy Sticky Buttons Security Vulnerabilities
Easy Sticky Buttons Code Analysis
Output Escaping
Easy Sticky Buttons Attack Surface
WordPress Hooks 8
Maintenance & Trust
Easy Sticky Buttons Maintenance & Trust
Maintenance Signals
Community Trust
Easy Sticky Buttons Alternatives
Call Now Button – The #1 Click to Call Button for WordPress
call-now-button
The web's #1 click to call button for your website! A simple and powerful plugin that adds a Call Now Button to your website.
WP Call Button – Easy Click to Call Button for WordPress
wp-call-button
The best WordPress call now button plugin. We help you add a clickable phone link (quick call button), so people can easily call your business phone.
Powerkit – Supercharge your WordPress Site
powerkit
Essential components for every WordPress site: share buttons, social links, social media integrations, galleries, lazyload, custom widgets, and more.
RaraTheme Companion
raratheme-companion
23 extremely useful custom widgets to create an engaging website.
Sticky Buttons – Floating Buttons Builder
sticky-buttons
Increase user engagement by incorporating sticky buttons that highlight relevant information on your website.
Easy Sticky Buttons Developer Profile
1 plugin · 700 total installs
How We Detect Easy Sticky Buttons
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/easy-sticky-buttons/css/easy-sticky-buttons.css/wp-content/plugins/easy-sticky-buttons/js/easy-sticky-buttons.jseasy-sticky-buttons/css/easy-sticky-buttons.css?ver=easy-sticky-buttons/js/easy-sticky-buttons.js?ver=HTML / DOM Fingerprints
easystickybuttons-containereasystickybuttons-buttoneasystickybuttons-contentesb-info-popupesb-popupesb-info-popup-closeesb_contentesb-info-tog+7 moredesign on main pagedesign on main pagedata-colordata-backgrounddata-usernamedata-textdata-link