Sticky Social Buttons – Floating Chat, Call, Contact, SMS, Email & 50+ Social Icons Security & Risk Analysis

wordpress.org/plugins/gp-sticky-buttons

Grow your audience on Facebook, Instagram, Twitter, and more, while engaging customers instantly through WhatsApp, Messenger, Telegram, Viber, and doz …

100 active installs v1.0.4 PHP 5.4+ WP 5.0+ Updated Sep 20, 2025
messengersocialsticky-buttonstelegramwhatsapp
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Sticky Social Buttons – Floating Chat, Call, Contact, SMS, Email & 50+ Social Icons Safe to Use in 2026?

Generally Safe

Score 100/100

Sticky Social Buttons – Floating Chat, Call, Contact, SMS, Email & 50+ Social Icons has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8mo ago
Risk Assessment

The gp-sticky-buttons plugin v1.0.4 exhibits a generally good security posture with several positive indicators. The absence of SQL injection vulnerabilities due to the exclusive use of prepared statements is a significant strength. Furthermore, the plugin demonstrates robust output escaping practices, with a high percentage of outputs being properly sanitized, and a lack of dangerous functions, file operations, or external HTTP requests, all contributing to a reduced attack surface in these areas. The presence of nonces on all AJAX handlers is also a positive security control. However, there is one critical area of concern: one out of five AJAX handlers lacks authentication checks. This means that an attacker could potentially trigger this handler without being logged in, which could lead to unintended actions or information disclosure depending on the handler's functionality.

Key Concerns

  • AJAX handler without authentication check
Vulnerabilities
None known

Sticky Social Buttons – Floating Chat, Call, Contact, SMS, Email & 50+ Social Icons Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Sticky Social Buttons – Floating Chat, Call, Contact, SMS, Email & 50+ Social Icons Release Timeline

v1.0.4Current
v1.0.3
v1.0.2
v1.0.1
Code Analysis
Analyzed Mar 16, 2026

Sticky Social Buttons – Floating Chat, Call, Contact, SMS, Email & 50+ Social Icons Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
66
321 escaped
Nonce Checks
5
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

83% escaped387 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

1 flows
<widgets> (templates\widgets.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Sticky Social Buttons – Floating Chat, Call, Contact, SMS, Email & 50+ Social Icons Attack Surface

Entry Points5
Unprotected1

AJAX Handlers 5

authwp_ajax_gp_sticky_buttons_add_channelincludes\Actions.php:8
authwp_ajax_gsb_save_widget_settingsincludes\Actions.php:9
authwp_ajax_gp_sticky_buttons_change_statusincludes\Actions.php:10
authwp_ajax_gp_sticky_buttons_remove_widgetincludes\Actions.php:11
authwp_ajax_gp_sticky_buttons_clone_widgetincludes\Actions.php:12
WordPress Hooks 11
actioninitincludes\Actions.php:7
actionadmin_initincludes\Actions.php:13
actionadmin_enqueue_scriptsincludes\Assets.php:8
actionadmin_enqueue_scriptsincludes\Assets.php:9
actiongsb_channel_field_labelincludes\Fields.php:8
actiongsb_channel_field_inputincludes\Fields.php:9
actiongsb_display_rules_labelincludes\Fields.php:10
actiongsb_display_rules_inputincludes\Fields.php:11
actionwp_enqueue_scriptsincludes\Init.php:15
actionadmin_menuincludes\Menu.php:9
actionplugins_loadedindex.php:54
Maintenance & Trust

Sticky Social Buttons – Floating Chat, Call, Contact, SMS, Email & 50+ Social Icons Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedSep 20, 2025
PHP min version5.4
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

Sticky Social Buttons – Floating Chat, Call, Contact, SMS, Email & 50+ Social Icons Developer Profile

gingerplugins

3 plugins · 10K total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
28 days
View full developer profile
Detection Fingerprints

How We Detect Sticky Social Buttons – Floating Chat, Call, Contact, SMS, Email & 50+ Social Icons

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gp-sticky-buttons/dist/admin/css/app.css/wp-content/plugins/gp-sticky-buttons/dist/admin/css/upgrade-to-pro.css/wp-content/plugins/gp-sticky-buttons/dist/admin/js/jquery.ajaxsubmit.js/wp-content/plugins/gp-sticky-buttons/dist/admin/js/app.js/wp-content/plugins/gp-sticky-buttons/dist/admin/js/upgrade-to-pro.js/wp-content/plugins/gp-sticky-buttons/dist/front/css/style.css/wp-content/plugins/gp-sticky-buttons/dist/front/js/script.js
Script Paths
dist/admin/js/jquery.ajaxsubmit.jsdist/admin/js/app.jsdist/admin/js/upgrade-to-pro.jsdist/front/js/script.js
Version Parameters
gp-sticky-buttons/dist/admin/css/app.css?time=gp-sticky-buttons/dist/admin/css/upgrade-to-pro.css?time=gp-sticky-buttons/dist/front/css/style.cssgp-sticky-buttons/dist/front/js/script.js

HTML / DOM Fingerprints

CSS Classes
gp-sticky-buttons-admin-wrapgp-sticky-buttons-settings-wrapgp-sticky-buttons-main-wrapgp-sticky-buttons-content-wrapgp-sticky-buttons-icon
Data Attributes
data-gp-sticky-buttons-iddata-gp-sticky-buttons-settings
JS Globals
gp_st_btn_settings
FAQ

Frequently Asked Questions about Sticky Social Buttons – Floating Chat, Call, Contact, SMS, Email & 50+ Social Icons