Sticky Add To Cart Bar For WooCommerce Security & Risk Analysis

wordpress.org/plugins/sticky-add-to-cart-bar-for-wc

Sticky Add To Cart Bar For WooCommerce is use to add sticky add to cart button on the product page of WooCommerce.

600 active installs v1.4.6 PHP 5.6+ WP 4.8+ Updated May 6, 2023
add-to-cartboost-salessticky-add-to-cartwoocommercewoocommerce-sticky-bar
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Sticky Add To Cart Bar For WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Sticky Add To Cart Bar For WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

This plugin exhibits a concerning security posture primarily due to its unprotected AJAX handler. While the plugin demonstrates good practices by avoiding dangerous functions, raw SQL queries, and file operations, and has no known vulnerabilities, the presence of a single AJAX endpoint without any authentication or authorization checks presents a significant risk. This unprotected entry point could potentially be exploited by unauthenticated users to trigger unintended actions within the WordPress site, leading to various security issues depending on the functionality of that AJAX handler.

The static analysis also highlights a critical weakness in output escaping, with 100% of outputs being unescaped. This means any data processed or displayed by the plugin could be injected with malicious code, leading to cross-site scripting (XSS) vulnerabilities. The lack of nonce checks further exacerbates this risk by making it easier to craft and submit malicious requests.

In conclusion, despite the absence of a vulnerability history and the use of prepared statements for SQL, the combination of an unprotected AJAX handler and universally unescaped output makes this plugin a high-risk component. The strengths in SQL handling and lack of historical CVEs are overshadowed by these critical security flaws that require immediate attention.

Key Concerns

  • Unprotected AJAX handler
  • 100% of outputs unescaped
  • Missing nonce checks on AJAX
Vulnerabilities
None known

Sticky Add To Cart Bar For WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Sticky Add To Cart Bar For WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
15
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped15 total outputs
Attack Surface
1 unprotected

Sticky Add To Cart Bar For WooCommerce Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_dismissed_wsc_notice_handleraddonsplus-wsc.php:95
WordPress Hooks 10
actionadmin_noticesaddonsplus-wsc.php:37
actionadmin_initaddonsplus-wsc.php:63
actionadmin_noticesaddonsplus-wsc.php:68
actionadmin_noticesaddonsplus-wsc.php:88
actionadmin_menuinc\Api\SettingsApi.php:23
actionadmin_initinc\Api\SettingsApi.php:27
actionadmin_enqueue_scriptsinc\Base\Enqueue.php:15
filterplugin_row_metainc\Base\SettingsLinks.php:14
actionwp_headinc\Base\WooCart.php:17
actionwp_enqueue_scriptsinc\Base\WooCart.php:18
Maintenance & Trust

Sticky Add To Cart Bar For WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedMay 6, 2023
PHP min version5.6
Downloads18K

Community Trust

Rating90/100
Number of ratings11
Active installs600
Developer Profile

Sticky Add To Cart Bar For WooCommerce Developer Profile

addonsplus

1 plugin · 600 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Sticky Add To Cart Bar For WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sticky-add-to-cart-bar-for-wc/assets/woocart-admin.js/wp-content/plugins/sticky-add-to-cart-bar-for-wc/assets/woocart-admin.css/wp-content/plugins/sticky-add-to-cart-bar-for-wc/assets/scripts/jquery-ui.min.css/wp-content/plugins/sticky-add-to-cart-bar-for-wc/assets/woocart-main.js/wp-content/plugins/sticky-add-to-cart-bar-for-wc/assets/woocart.css
Script Paths
/wp-content/plugins/sticky-add-to-cart-bar-for-wc/assets/woocart-admin.js/wp-content/plugins/sticky-add-to-cart-bar-for-wc/assets/woocart-main.js
Version Parameters
sticky-add-to-cart-bar-for-wc/assets/woocart-admin.js?ver=sticky-add-to-cart-bar-for-wc/assets/woocart-admin.css?ver=sticky-add-to-cart-bar-for-wc/assets/scripts/jquery-ui.min.css?ver=sticky-add-to-cart-bar-for-wc/assets/woocart-main.js?ver=sticky-add-to-cart-bar-for-wc/assets/woocart.css?ver=

HTML / DOM Fingerprints

CSS Classes
notice-wsc-class
FAQ

Frequently Asked Questions about Sticky Add To Cart Bar For WooCommerce