Fixed Widget and Sticky Elements for WordPress Security & Risk Analysis

wordpress.org/plugins/q2w3-fixed-widget

More attention and a higher ad performance with fixed sticky widgets.

90K active installs v6.2.3 PHP 7.2+ WP 5.0+ Updated Mar 30, 2023
adsfixed-widgetsidebarsticky-widgetwidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Fixed Widget and Sticky Elements for WordPress Safe to Use in 2026?

Generally Safe

Score 85/100

Fixed Widget and Sticky Elements for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The plugin 'q2w3-fixed-widget' v6.2.3 exhibits a strong security posture in several key areas, particularly with its extremely limited attack surface and the absence of known vulnerabilities in its history. The static analysis reveals no AJAX handlers, REST API routes, shortcodes, or cron events, meaning there are virtually no direct entry points for attackers to exploit. Furthermore, the absence of critical code signals like dangerous functions, file operations, and external HTTP requests, along with no recorded taint flows, indicates a generally well-written and secure codebase concerning these aspects.

However, there are notable areas for improvement. The most significant concern is the presence of SQL queries that are not using prepared statements, which could potentially lead to SQL injection vulnerabilities if the query is constructed with user-supplied data without proper sanitization. The output escaping also falls short of ideal, with only 52% of outputs being properly escaped, leaving a significant portion of output to potential cross-site scripting (XSS) attacks. The lack of nonce checks and capability checks across the entry points, while currently not an issue due to the absence of those entry points, represents a missed opportunity for defense-in-depth if any were to be introduced in future versions.

In conclusion, 'q2w3-fixed-widget' v6.2.3 appears to be a safe plugin primarily due to its minimal attack surface and clean vulnerability history. Nevertheless, the unescaped outputs and the use of non-prepared SQL queries represent tangible security risks that should be addressed to further strengthen its security. The plugin's developers seem to have a good understanding of core WordPress security principles by limiting entry points, but further attention to data handling and output sanitization is recommended.

Key Concerns

  • SQL queries not using prepared statements
  • Low percentage of properly escaped output
  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

Fixed Widget and Sticky Elements for WordPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Fixed Widget and Sticky Elements for WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
15
16 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

52% escaped31 total outputs
Attack Surface

Fixed Widget and Sticky Elements for WordPress Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actioninitq2w3-fixed-widget.php:12
actionin_widget_formq2w3-fixed-widget.php:45
filterwidget_update_callbackq2w3-fixed-widget.php:46
actionadmin_initq2w3-fixed-widget.php:47
actionadmin_menuq2w3-fixed-widget.php:48
actionadmin_enqueue_scriptsq2w3-fixed-widget.php:49
actionadmin_enqueue_scriptsq2w3-fixed-widget.php:52
actionenqueue_block_editor_assetsq2w3-fixed-widget.php:54
actionwp_enqueue_scriptsq2w3-fixed-widget.php:61
filterwidget_display_callbackq2w3-fixed-widget.php:62
Maintenance & Trust

Fixed Widget and Sticky Elements for WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedMar 30, 2023
PHP min version7.2
Downloads2.3M

Community Trust

Rating94/100
Number of ratings261
Active installs90K
Developer Profile

Fixed Widget and Sticky Elements for WordPress Developer Profile

monetizemore

5 plugins · 198K total installs

74
trust score
Avg Security Score
93/100
Avg Patch Time
237 days
View full developer profile
Detection Fingerprints

How We Detect Fixed Widget and Sticky Elements for WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/q2w3-fixed-widget/css/backend.css/wp-content/plugins/q2w3-fixed-widget/js/backend.min.js/wp-content/plugins/q2w3-fixed-widget/js/frontend.min.js
Script Paths
js/backend.min.jsjs/frontend.min.js
Version Parameters
q2w3-fixed-widget/js/frontend.min.js?ver=q2w3-fixed-widget/css/backend.css?ver=

HTML / DOM Fingerprints

Data Attributes
q2w3_fixed_widget
JS Globals
q2w3_sidebar_options
FAQ

Frequently Asked Questions about Fixed Widget and Sticky Elements for WordPress