
Simple Sticky Footer Security & Risk Analysis
wordpress.org/plugins/simple-sticky-footerSimple Sticky Footer is a lightweight plugin, it allows to promote/advertise a WP Page (rich-text document) as a sticky footer (always on top div).
Is Simple Sticky Footer Safe to Use in 2026?
Use With Caution
Score 59/100Simple Sticky Footer has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The 'simple-sticky-footer' plugin, version 1.3.5, exhibits a mixed security posture. On the positive side, it demonstrates good practices by not utilizing dangerous functions, all SQL queries are prepared, and there are no observed file operations or external HTTP requests. The presence of nonce checks and a single shortcode as the sole entry point with no explicit authentication bypasses is also encouraging. However, a significant concern arises from the moderate output escaping, with 61% of outputs not being properly escaped. This leaves the plugin susceptible to Cross-Site Scripting (XSS) vulnerabilities, especially given its history.
The plugin's vulnerability history is a major red flag. With two known CVEs, one of which is still unpatched and classified as high severity, the plugin has a demonstrable track record of security flaws. The common types of past vulnerabilities, XSS and CSRF, align with potential risks stemming from improperly escaped output. The existence of an unpatched high-severity vulnerability indicates a lack of timely security maintenance, posing an immediate risk to users. While the static analysis does not reveal critical taint flows or direct SQL injection vectors, the historical context strongly suggests that potential vulnerabilities are likely related to input handling and output rendering.
In conclusion, 'simple-sticky-footer' v1.3.5 has strengths in its control over dangerous functions and SQL queries. However, the incomplete output escaping and, more critically, the presence of an unpatched high-severity vulnerability and a history of XSS/CSRF issues, present a substantial risk. Users should exercise extreme caution and prioritize updating to a version that addresses the known vulnerability, if available, or consider alternative plugins.
Key Concerns
- Unpatched high severity CVE
- Medium severity CVE (unpatched)
- Insufficient output escaping (39% proper)
- No capability checks
Simple Sticky Footer Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Simple Sticky Footer <= 1.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
Simple Sticky Footer <= 1.3.2 - Cross-Site Request Forgery to Cross-Site Scripting
Simple Sticky Footer Code Analysis
Output Escaping
Data Flow Analysis
Simple Sticky Footer Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
Simple Sticky Footer Maintenance & Trust
Maintenance Signals
Community Trust
Simple Sticky Footer Alternatives
Ads.txt Manager
ads-txt
Create, manage, and validate your ads.txt and app-ads.txt from within WordPress, like any other content asset.
Advanced Popups
advanced-popups
Display high-converting newsletter popups, a cookie notice, or a notification with the light-weight yet feature-rich plugin.
AI Powered Marketing
kliken-marketing-for-google
Kliken's all-in-one marketing helps businesses reach high-intent customers, beat the competition and see sales growth while lowering conversion costs
Website Article Monetization By MageNet
website-article-monetization-by-magenet
Get additional income from your website or blog by placing text ads automatically.
Website Monetization by MageNet
website-monetization-by-magenet
Get additional income from your website or blog by placing text ads automatically.
Simple Sticky Footer Developer Profile
5 plugins · 3K total installs
How We Detect Simple Sticky Footer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/simple-sticky-footer/simple-sticky-footer.css/wp-content/plugins/simple-sticky-footer/simple-sticky-footer.js/wp-content/plugins/simple-sticky-footer/simple-sticky-footer.jssimple-sticky-footer/simple-sticky-footer.css?ver=simple-sticky-footer/simple-sticky-footer.js?ver=HTML / DOM Fingerprints
simple-sf-widthsimple-sf-effectsimple-sf-delaysimple-sf-stylesimple-sf-hidesimple-sf-activate-shortcodeid='simple-sf'name='simple_sf_width'id='simple-sf-width'name='simple_sf_effect'id='simple-sf-effect'name='simple_sf_delay'+7 more