
Fixed Bottom Menu Security & Risk Analysis
wordpress.org/plugins/fixed-bottom-menuAdd a fixed menu. The basic menu is at the bottom, but it can also be displayed on the top, left, and right.
Is Fixed Bottom Menu Safe to Use in 2026?
Generally Safe
Score 100/100Fixed Bottom Menu has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "fixed-bottom-menu" v2.15 plugin exhibits a seemingly robust security posture based on the provided static analysis. A key strength is the complete absence of unescaped output and file operations, alongside no external HTTP requests. The plugin also appears to have a very limited attack surface, with zero identified entry points like AJAX handlers, REST API routes, or shortcodes. This suggests a focused and well-contained functionality. Furthermore, the plugin has no recorded vulnerability history, including no known CVEs across any severity level. This lack of historical issues is a positive indicator.
However, a significant concern arises from the handling of SQL queries. The analysis indicates one total SQL query, and critically, 0% of these use prepared statements. This is a substantial risk as it opens the door to potential SQL injection vulnerabilities if any part of the query can be influenced by user input, even indirectly through other means. Additionally, the absence of nonce checks and capability checks, while not necessarily a direct vulnerability in itself given the zero attack surface, indicates a lack of defensive programming practices that could become problematic if new entry points are added in future versions or if a vulnerability is found elsewhere that leads to unauthorized code execution.
In conclusion, while the plugin appears to have a clean track record and a controlled attack surface, the unescaped SQL query represents a significant and immediate risk. The lack of standard security checks like nonces and capability checks is also a weakness that should be addressed to improve its overall security resilience and future-proofing.
Key Concerns
- Raw SQL query without prepared statements
Fixed Bottom Menu Security Vulnerabilities
Fixed Bottom Menu Release Timeline
Fixed Bottom Menu Code Analysis
SQL Query Safety
Output Escaping
Fixed Bottom Menu Attack Surface
Maintenance & Trust
Fixed Bottom Menu Maintenance & Trust
Maintenance Signals
Community Trust
Fixed Bottom Menu Alternatives
Simple Floating Menu
simple-floating-menu
Simple Floating Menu add a simple floating button with various layouts and settings.
Side Menu Lite – Sticky Floating Side Menu
side-menu-lite
Create a sticky vertical sidebar menu that enhances navigation and highlights important links on your website.
Catch Sticky Menu
catch-sticky-menu
Catch Sticky Menu is a lightweight, simple yet feature-rich free WordPress plugin for sticky menu that allows you to lock the menu on your website.
All-in-One Sticky Anything – Click to Call, Fixed Widget, Sticky Header, Menu, Sidebar, Social Icons & Cookie Consent
all-in-one-wp-sticky-anything
All-in-One Sticky Anything easily creates click to call, fixed widgets, sticky elements, sticky header, menu, sidebar, social icons & cookie consent.
Fixed And Sticky Header
fixed-and-sticky-header
This plugin will made your header or menu fixed and sticky.
Fixed Bottom Menu Developer Profile
54 plugins · 56K total installs
How We Detect Fixed Bottom Menu
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/fixed-bottom-menu/lib/css/fixedbottommenu-style.css/wp-content/plugins/fixed-bottom-menu/lib/js/fixedbottommenu-script.js/wp-content/plugins/fixed-bottom-menu/lib/js/fixedbottommenu-script.jsfixed-bottom-menu/lib/css/fixedbottommenu-style.css?ver=fixed-bottom-menu/lib/js/fixedbottommenu-script.js?ver=HTML / DOM Fingerprints
fixed-bottom-menudata-fixedbottommenu-idfbm_vars