Stick My Header for Astra Security & Risk Analysis

wordpress.org/plugins/stick-my-header-for-astra

Improve your website's header design and make it stick to the top once Stick My Header For Astra is activated.

200 active installs v1.0 PHP + WP 5.3+ Updated Sep 14, 2025
floating-menuheaderstickysticky-headersticky-menu
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Stick My Header for Astra Safe to Use in 2026?

Generally Safe

Score 100/100

Stick My Header for Astra has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

Based on the static analysis and vulnerability history, the 'stick-my-header-for-astra' plugin v1.0 exhibits a generally good security posture. The absence of any identified entry points like AJAX handlers, REST API routes, or shortcodes significantly limits the plugin's attack surface. Furthermore, the code signals indicate responsible development practices, with all SQL queries utilizing prepared statements and a very high percentage of output being properly escaped. The lack of file operations and external HTTP requests further reduces potential risks.

However, there are a few areas that warrant attention. The presence of a single external HTTP request, while not inherently a vulnerability, could become a risk if the external service is compromised or if the request itself is not handled securely. Crucially, the plugin has zero nonce checks and zero capability checks. This is a significant concern, as it means any function that might be triggered by an authenticated user, or potentially even an unauthenticated one if an entry point is discovered, is not protected against Cross-Site Request Forgery (CSRF) or unauthorized access. The vulnerability history being completely clean is a positive sign, suggesting a lack of previously identified flaws, but this does not negate the identified weaknesses in the current code.

In conclusion, while the plugin benefits from a very small attack surface and good practices in SQL and output handling, the complete absence of nonce and capability checks represents a critical security gap. This makes the plugin vulnerable to various types of attacks if any interaction points are exposed. Addressing these checks should be a priority to strengthen its security.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • External HTTP request with no apparent auth/validation
Vulnerabilities
None known

Stick My Header for Astra Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Stick My Header for Astra Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
98 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

98% escaped100 total outputs
Attack Surface

Stick My Header for Astra Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionadmin_menufunctions.php:113
actionadmin_enqueue_scriptsfunctions.php:115
actionadmin_enqueue_scriptsfunctions.php:117
actionwp_footerfunctions.php:119
actionadmin_noticesfunctions.php:121
actioncustomize_registerfunctions.php:123
actionadmin_enqueue_scriptsfunctions.php:125
actionwp_enqueue_scriptsfunctions.php:127
actioncustomize_preview_initfunctions.php:129
Maintenance & Trust

Stick My Header for Astra Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 14, 2025
PHP min version
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs200
Developer Profile

Stick My Header for Astra Developer Profile

Samir IHADDADENE

1 plugin · 200 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Stick My Header for Astra

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/stick-my-header-for-astra/js/jscode.js/wp-content/plugins/stick-my-header-for-astra/js/stick_header.js/wp-content/plugins/stick-my-header-for-astra/css/dynamic-userview.css/wp-content/plugins/stick-my-header-for-astra/css/adminview.css/wp-content/plugins/stick-my-header-for-astra/view/admn-view.php/wp-content/plugins/stick-my-header-for-astra/view/banner.php/wp-content/plugins/stick-my-header-for-astra/img/sticky-header.gif/wp-content/plugins/stick-my-header-for-astra/img/astra-sticky-header-logo.jpg+5 more
Script Paths
/wp-content/plugins/stick-my-header-for-astra/js/jscode.js/wp-content/plugins/stick-my-header-for-astra/js/stick_header.js
Version Parameters
stick-my-header-for-astra/js/jscode.js?ver=stick-my-header-for-astra/js/stick_header.js?ver=stick-my-header-for-astra/css/adminview.css?ver=stick-my-header-for-astra/css/banner.css?ver=

HTML / DOM Fingerprints

CSS Classes
ash-ajax-script
Data Attributes
ash-ajax-script
JS Globals
ash_ajax_obj
FAQ

Frequently Asked Questions about Stick My Header for Astra