Sticky Action Buttons – Call, Chat, Navigate and more Security & Risk Analysis

wordpress.org/plugins/sticky-action-buttons-call-chat-navigate-and-more

The ultimate flexible and lightweight responsive sticky floating contact buttons. over 100 different design options.

200 active installs v1.0 PHP 7.0+ WP 5.0+ Updated May 30, 2022
buttonscall-buttonclick-to-actioncontact-buttonfloating-buttons
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Sticky Action Buttons – Call, Chat, Navigate and more Safe to Use in 2026?

Generally Safe

Score 85/100

Sticky Action Buttons – Call, Chat, Navigate and more has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "sticky-action-buttons-call-chat-navigate-and-more" plugin v1.0 exhibits a generally positive security posture, with several good practices in place. The absence of any known CVEs and the consistent use of prepared statements for SQL queries are significant strengths. Furthermore, the static analysis shows all entry points (AJAX handlers) are protected by capability checks, and there are no identified unsanitized paths in the taint analysis.

However, there are a couple of areas that warrant attention. The presence of the `create_function` dangerous function, while not directly exploited in the provided analysis, is a known security risk that can lead to arbitrary code execution if used with user-supplied input. Additionally, a significant portion of the output (29%) is not properly escaped. This could potentially lead to cross-site scripting (XSS) vulnerabilities if the unescaped output contains user-controlled data.

In conclusion, the plugin benefits from robust access control on its entry points and secure database interaction. The primary concerns stem from the use of a deprecated dangerous function and the less-than-ideal output escaping, which collectively represent a moderate risk that should be addressed to further strengthen the plugin's security.

Key Concerns

  • Dangerous function 'create_function' used
  • Significant portion of output not escaped
Vulnerabilities
None known

Sticky Action Buttons – Call, Chat, Navigate and more Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Sticky Action Buttons – Call, Chat, Navigate and more Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
160
398 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

create_functionadd_action('init', create_function('$a', "remove_action( 'init', 'wp_version_check' );"), 2);combar-sab.php:72

Output Escaping

71% escaped558 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
combar_sab_restart_options (inc\admin-functions.php:7)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Sticky Action Buttons – Call, Chat, Navigate and more Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

noprivwp_ajax_combar_sab_restart_optionsinc\admin-functions.php:29
authwp_ajax_combar_sab_restart_optionsinc\admin-functions.php:30
WordPress Hooks 14
actionadmin_menucombar-sab.php:43
actioninitcombar-sab.php:72
filterpre_option_update_corecombar-sab.php:73
filterpre_site_transient_update_corecombar-sab.php:74
actionafter_setup_themecombar-sab.php:77
actionadmin_bar_menucombar-sab.php:215
actionadmin_initcombar-sab.php:242
actionactivated_plugincombar-sab.php:276
actionwp_enqueue_scriptscombar-sab.php:362
actionadmin_enqueue_scriptscombar-sab.php:363
filtershow_admin_barinc\functions.php:34
filterbody_classinc\functions.php:41
actioninitinc\functions.php:45
actionwp_footerinc\functions.php:89
Maintenance & Trust

Sticky Action Buttons – Call, Chat, Navigate and more Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedMay 30, 2022
PHP min version7.0
Downloads6K

Community Trust

Rating80/100
Number of ratings3
Active installs200
Developer Profile

Sticky Action Buttons – Call, Chat, Navigate and more Developer Profile

Combar Digital

3 plugins · 550 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Sticky Action Buttons – Call, Chat, Navigate and more

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sticky-action-buttons-call-chat-navigate-and-more/assets/css/main.css/wp-content/plugins/sticky-action-buttons-call-chat-navigate-and-more/assets/js/main.js
Version Parameters
sticky-action-buttons-call-chat-navigate-and-more/assets/css/main.css?ver=sticky-action-buttons-call-chat-navigate-and-more/assets/js/main.js?ver=

HTML / DOM Fingerprints

CSS Classes
combar-sab-containercombar-sab-desktop-settingscombar-sab-mobile-settingscombar-sab-buttons-managercombar-sab-general-settingscombar-sab-menu-itemcombar-sab-admin-bar-menu
HTML Comments
<!-- If this file is called directly, abort. --><!-- Set plugin version for internal use --><!-- Add plugin to admin panel menu --><!-- Admin pages callback -->+7 more
Data Attributes
data-plugin="combar-sab"data-page="combar-sab-desktop"data-page="combar-sab-mobile"data-page="combar-sab-buttons"data-page="combar-sab-settings"class="combar-sab-desktopView"+2 more
JS Globals
combar_sab_versioncombar_sab_dir
FAQ

Frequently Asked Questions about Sticky Action Buttons – Call, Chat, Navigate and more