Seamless Sticky Custom Post Types Security & Risk Analysis

wordpress.org/plugins/seamless-sticky-custom-post-types

Extends the native sticky post functionality to custom post types in a way that is identical to default posts.

1K active installs v1.4 PHP + WP 3.0.1+ Updated Jan 15, 2015
custom-post-typesticky
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Seamless Sticky Custom Post Types Safe to Use in 2026?

Generally Safe

Score 85/100

Seamless Sticky Custom Post Types has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the "seamless-sticky-custom-post-types" plugin version 1.4 exhibits a strong security posture. The static analysis reveals no exploitable attack surface, meaning there are no directly accessible AJAX handlers, REST API routes, shortcodes, or cron events that could be targeted without authentication. Furthermore, the code signals indicate good security practices, with no dangerous functions, all SQL queries using prepared statements, and all output being properly escaped. The absence of file operations and external HTTP requests also reduces potential attack vectors. The taint analysis shows no unsanitized data flows, further reinforcing its secure design in this version.

The vulnerability history is also clean, with no known CVEs recorded for this plugin. This, combined with the positive static analysis, suggests a well-maintained and secure plugin. The plugin's strengths lie in its minimal attack surface and adherence to secure coding practices like prepared statements and output escaping. While the analysis doesn't explicitly mention nonce checks or capability checks being absent, the lack of any identified attack surface or taint flows implies that any existing handlers are likely protected or not exploitable. Therefore, the overall risk associated with this plugin version appears to be very low.

Vulnerabilities
None known

Seamless Sticky Custom Post Types Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Seamless Sticky Custom Post Types Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries
Attack Surface

Seamless Sticky Custom Post Types Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionadmin_enqueue_scriptsseamless-sticky-custom-post-types.php:27
Maintenance & Trust

Seamless Sticky Custom Post Types Maintenance & Trust

Maintenance Signals

WordPress version tested4.1.42
Last updatedJan 15, 2015
PHP min version
Downloads74K

Community Trust

Rating94/100
Number of ratings20
Active installs1K
Developer Profile

Seamless Sticky Custom Post Types Developer Profile

jaschaephraim

2 plugins · 2K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Seamless Sticky Custom Post Types

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/seamless-sticky-custom-post-types/admin.min.js
Script Paths
admin.min.js

HTML / DOM Fingerprints

JS Globals
sscpt
FAQ

Frequently Asked Questions about Seamless Sticky Custom Post Types