
Fixed Menu Anchor Security & Risk Analysis
wordpress.org/plugins/fixed-menu-anchorIf you are using a sticky, fixed menu in your WP theme, this plugin is the best to deal with it overlapping anchored content.
Is Fixed Menu Anchor Safe to Use in 2026?
Generally Safe
Score 85/100Fixed Menu Anchor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "fixed-menu-anchor" plugin v2.3 presents a generally strong security posture based on the static analysis provided. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the attack surface. Furthermore, the code signals indicate a diligent approach to SQL queries, with 100% utilizing prepared statements, and no dangerous functions, file operations, or external HTTP requests were detected. The lack of known vulnerabilities in its history also suggests a mature and well-maintained plugin.
However, a critical concern arises from the output escaping analysis. With 2 total outputs and 0% properly escaped, this indicates a high likelihood of Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data that is displayed on the frontend without proper sanitization is a direct risk. Additionally, the taint analysis revealing one flow with unsanitized paths, even without a critical or high severity classification, warrants attention as it points to potential input validation issues that could be exploited.
While the plugin's limited attack surface and good database practices are commendable strengths, the significant weakness in output escaping represents a tangible and exploitable risk. The absence of nonce and capability checks is less concerning given the lack of entry points, but the output escaping issue remains the primary security concern. It is recommended that the plugin developer prioritize addressing the unescaped output to mitigate the risk of XSS attacks.
Key Concerns
- Unescaped output
- Taint flow with unsanitized path
Fixed Menu Anchor Security Vulnerabilities
Fixed Menu Anchor Code Analysis
Output Escaping
Data Flow Analysis
Fixed Menu Anchor Attack Surface
WordPress Hooks 5
Maintenance & Trust
Fixed Menu Anchor Maintenance & Trust
Maintenance Signals
Community Trust
Fixed Menu Anchor Alternatives
Fixed And Sticky Header
fixed-and-sticky-header
This plugin will made your header or menu fixed and sticky.
Sticky Header by ThematoSoup
sticky-header
Sticky Header by ThematoSoup allows you to add sticky header to any WordPress theme.
Simple Sticky Header Menu
simple-sticky-header-menu
Make website header sticky by using this plugin, very simple way to use, just install plugin and activate it thats all. Also there is an option to sel …
My Sticky Bar – Floating Notification Bar & Sticky Header (formerly myStickymenu)
mystickymenu
Create a welcome notification bar for your website. Also, My Sticky Bar plugin can make your menu or header sticky to the top when scrolled 📌
Sticky Menu & Sticky Header
sticky-menu-or-anything-on-scroll
Sticky Menu or Sticky Header sticks elements at the top of the screen when you scroll, or create a floating sticky menu or fixed widget.
Fixed Menu Anchor Developer Profile
1 plugin · 200 total installs
How We Detect Fixed Menu Anchor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/fixed-menu-anchor/js/fixed-menu-anchor.js/wp-content/plugins/fixed-menu-anchor/js/fixed-menu-anchor.jsfixed-menu-anchor/js/fixed-menu-anchor.js?ver=HTML / DOM Fingerprints
fixedMenuAnchorCssClassesToBeIgnoredfixedMenuAnchorMaximumViewportWidthfixedMenuAnchorMaximumViewportWidthDistancefixedMenuAnchorUserDefinedDistance