Simple Sticky Header on Scroll Security & Risk Analysis

wordpress.org/plugins/simple-sticky-header-on-scroll

Add the modern functionality of a sticky header that appears on scroll to your theme.

900 active installs v1.1 PHP + WP 3.6+ Updated Aug 4, 2022
floatingheaderscrollsticky-header-wordpress
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Simple Sticky Header on Scroll Safe to Use in 2026?

Generally Safe

Score 85/100

Simple Sticky Header on Scroll has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The plugin "simple-sticky-header-on-scroll" v1.1 exhibits a generally positive security posture, with no known vulnerabilities in its history and a clean bill of health from the static analysis regarding dangerous functions, SQL queries, file operations, and external HTTP requests. The absence of any recorded CVEs, especially critical or high severity ones, is a strong indicator of good development practices and a history of responsible coding. The code analysis also shows a complete lack of taint flows, suggesting that potential data manipulation vectors are not present or have been effectively mitigated.

However, there are areas for concern. The most significant is the exceptionally low percentage of properly escaped output (34%). This indicates a high likelihood of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data or dynamic content may be rendered directly into the page without proper sanitization. Furthermore, the complete absence of capability checks and nonce checks, coupled with zero entry points that are protected, suggests that if any vulnerabilities were to be discovered, they could be easily exploited by unauthenticated users. While the attack surface is currently reported as zero, this is likely a reflection of the specific static analysis findings rather than an inherent characteristic of the plugin's functionality, and the lack of protection mechanisms is a significant oversight.

In conclusion, while the plugin benefits from a clean vulnerability history and avoidance of common risky practices like raw SQL queries, the severe lack of output escaping is a critical weakness that significantly elevates the risk profile. The absence of protective measures like capability and nonce checks further exacerbates this risk. Developers should prioritize addressing the output escaping issue to improve the plugin's security.

Key Concerns

  • Poor output escaping
  • No capability checks
  • No nonce checks
Vulnerabilities
None known

Simple Sticky Header on Scroll Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Simple Sticky Header on Scroll Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
19
10 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

34% escaped29 total outputs
Attack Surface

Simple Sticky Header on Scroll Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actioncustomize_registersimple-sticky-header-on-scroll.php:192
actionwp_footersimple-sticky-header-on-scroll.php:293
actionwp_enqueue_scriptssimple-sticky-header-on-scroll.php:311
actionwp_enqueue_scriptssimple-sticky-header-on-scroll.php:320
actionwp_enqueue_scriptssimple-sticky-header-on-scroll.php:336
actionwp_footersimple-sticky-header-on-scroll.php:423
Maintenance & Trust

Simple Sticky Header on Scroll Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedAug 4, 2022
PHP min version
Downloads36K

Community Trust

Rating86/100
Number of ratings6
Active installs900
Developer Profile

Simple Sticky Header on Scroll Developer Profile

BonfireThemes

2 plugins · 2K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Simple Sticky Header on Scroll

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/simple-sticky-header-on-scroll/style.css/wp-content/plugins/simple-sticky-header-on-scroll/customizer.js/wp-content/plugins/simple-sticky-header-on-scroll/sticky.js
Script Paths
/wp-content/plugins/simple-sticky-header-on-scroll/customizer.js/wp-content/plugins/simple-sticky-header-on-scroll/sticky.js
Version Parameters
simple-sticky-header-on-scroll/style.css?ver=simple-sticky-header-on-scroll/customizer.js?ver=simple-sticky-header-on-scroll/sticky.js?ver=

HTML / DOM Fingerprints

CSS Classes
sshos-sticky-header
FAQ

Frequently Asked Questions about Simple Sticky Header on Scroll