
My Sticky Bar – Floating Notification Bar & Sticky Header (formerly myStickymenu) Security & Risk Analysis
wordpress.org/plugins/mystickymenuCreate a welcome notification bar for your website. Also, My Sticky Bar plugin can make your menu or header sticky to the top when scrolled 📌
Is My Sticky Bar – Floating Notification Bar & Sticky Header (formerly myStickymenu) Safe to Use in 2026?
Generally Safe
Score 92/100My Sticky Bar – Floating Notification Bar & Sticky Header (formerly myStickymenu) has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin "mystickymenu" v2.8.7 presents a mixed security posture. On the positive side, it demonstrates good practices with a high percentage of SQL queries using prepared statements and a substantial amount of output properly escaped. The absence of critical or high severity taint analysis findings and the fact that all known CVEs are currently patched are also strong indicators of a relatively secure codebase in its current state. The presence of numerous nonce and capability checks further reinforces this.
However, there are notable concerns. The plugin exposes a significant attack surface with 13 AJAX handlers, two of which lack any authentication checks. This is a direct entry point for potential unauthorized actions. While the vulnerability history shows no currently unpatched issues, the plugin has a history of six CVEs, including one high, four medium, and one low severity vulnerability. The types of past vulnerabilities (SQL Injection, CSRF, Missing Authorization, XSS) suggest a pattern of common web security weaknesses that, while addressed, indicate areas where the plugin has historically struggled. The presence of bundled libraries, like Select2, could also introduce risks if not maintained and updated independently.
In conclusion, while the immediate threat from unpatched vulnerabilities is low, the plugin's historical pattern and the presence of unprotected AJAX endpoints warrant caution. Developers should prioritize securing the remaining unauthenticated AJAX handlers and maintain vigilance regarding the security of bundled libraries. The past incidents highlight the need for ongoing security testing and code review.
Key Concerns
- 2 unprotected AJAX handlers
- History of 6 CVEs (1 high, 4 medium)
- Bundled library (Select2)
My Sticky Bar – Floating Notification Bar & Sticky Header (formerly myStickymenu) Security Vulnerabilities
CVEs by Year
Severity Breakdown
6 total CVEs
My Sticky Bar <= 2.8.6 - Unauthenticated SQL Injection via 'stickymenu_contact_lead_form' Action
My Sticky Bar <= 2.7.2 - Authenticated (Admin+) Stored Cross-Site Scripting
My Sticky Bar (formerly myStickymenu) <= 2.7.1 - Authenticated (Admin+) Stored Cross-Site Scripting
My Sticky Bar <= 2.6.6 - Cross-Site Request Forgery to Sensitive Information Exposure
myStickymenu <= 2.6.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Form Lead Deletion
myStickymenu <= 2.5.1 - Authenticated Stored Cross-Site Scripting
My Sticky Bar – Floating Notification Bar & Sticky Header (formerly myStickymenu) Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
My Sticky Bar – Floating Notification Bar & Sticky Header (formerly myStickymenu) Attack Surface
AJAX Handlers 13
WordPress Hooks 21
Maintenance & Trust
My Sticky Bar – Floating Notification Bar & Sticky Header (formerly myStickymenu) Maintenance & Trust
Maintenance Signals
Community Trust
My Sticky Bar – Floating Notification Bar & Sticky Header (formerly myStickymenu) Alternatives
Oh My Bar
oh-my-bar
Oh My Bar is a WordPress plugin that creates a reading progress bar on top/bottom of the site that helps users to understand that how far they're …
Sticky Menu & Sticky Header
sticky-menu-or-anything-on-scroll
Sticky Menu or Sticky Header sticks elements at the top of the screen when you scroll, or create a floating sticky menu or fixed widget.
Announcer – Sticky Message Banner & Notification Bar
announcer
Add customizable WordPress notification bar to display announcements, promotions, coupons, or news at the top or bottom of your website.
Advanced Floating Content Lite
advanced-floating-content-lite
Create high-impact floating content that stays visible without annoying visitors. Perfect for announcements, CTAs, and promotions.
All-in-One Sticky Anything – Fixed Widget, Sticky Header, Menu, Sidebar, Social Icons & Cookie Consent
all-in-one-wp-sticky-anything
All-in-One Sticky Anything easily creates fixed widgets, sticky elements, sticky header, menu, sidebar, social icons & cookie consent on your website.
My Sticky Bar – Floating Notification Bar & Sticky Header (formerly myStickymenu) Developer Profile
9 plugins · 651K total installs
How We Detect My Sticky Bar – Floating Notification Bar & Sticky Header (formerly myStickymenu)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mystickymenu/admin/css/mystickymenu-backend.css/wp-content/plugins/mystickymenu/admin/css/mystickymenu-welcomebar.css/wp-content/plugins/mystickymenu/admin/js/mystickymenu-backend.js/wp-content/plugins/mystickymenu/admin/js/mystickymenu-welcomebar.js/wp-content/plugins/mystickymenu/admin/js/mystickymenu-backend.js/wp-content/plugins/mystickymenu/admin/js/mystickymenu-welcomebar.jsmystickymenu/admin/css/mystickymenu-backend.css?ver=mystickymenu/admin/css/mystickymenu-welcomebar.css?ver=mystickymenu/admin/js/mystickymenu-backend.js?ver=mystickymenu/admin/js/mystickymenu-welcomebar.js?ver=HTML / DOM Fingerprints
mystickymenu-containermystickymenu-buttonmysticky-menu-element<!-- My Sticky Menu Admin CSS --><!-- My Sticky Menu Admin JS --><!-- My Sticky Menu Welcome Bar CSS --><!-- My Sticky Menu Welcome Bar JS -->data-mystickymenu-iddata-mystickymenu-targetdata-mystickymenu-offsetMyStickyMenuBackendVarsmystickymenu_vars/wp-json/mystickymenu/v1/settings/wp-json/mystickymenu/v1/welcomebar[mysticky_menu][mysticky_welcomebar]