
Simple Sticky Add To Cart For WooCommerce Security & Risk Analysis
wordpress.org/plugins/sticky-add-to-cart-wooSimple Sticky add to cart for WooCommerce show on product page top and bottom with full color customization and much more option.
Is Simple Sticky Add To Cart For WooCommerce Safe to Use in 2026?
Mostly Safe
Score 79/100Simple Sticky Add To Cart For WooCommerce is generally safe to use. 1 past CVE were resolved. Keep it updated.
The "sticky-add-to-cart-woo" v1.4.9 plugin presents a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and includes a reasonable number of nonce checks. The absence of dangerous functions and file operations is also a strength.
However, significant concerns arise from the attack surface analysis. The plugin exposes seven AJAX handlers, with five of them lacking proper authentication checks. This is a critical vulnerability as it allows unauthenticated users to potentially trigger actions within the plugin, leading to unauthorized behavior or information disclosure.
The vulnerability history indicates a concerning pattern, with one medium-severity CVE already recorded and currently unpatched, specifically related to missing authorization. This reinforces the findings from the static analysis regarding unprotected AJAX handlers. While taint analysis shows no immediate critical or high severity flows, the existing medium vulnerability and the large number of unprotected entry points suggest a higher likelihood of future issues if not addressed. The low percentage of properly escaped output (38%) is also a concern, increasing the risk of cross-site scripting (XSS) vulnerabilities.
In conclusion, while the plugin has some good security foundations, the unprotected AJAX endpoints and the unpatched medium vulnerability significantly elevate its risk profile. The poor output escaping practices further exacerbate these concerns. Immediate attention is required to secure the AJAX handlers and address the existing unpatched vulnerability.
Key Concerns
- Unpatched CVE (Medium Severity)
- Large attack surface without auth (5 AJAX handlers)
- Low percentage of properly escaped output (38%)
- Missing authorization on AJAX handlers (implied by 5 unprotected)
Simple Sticky Add To Cart For WooCommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Simple Sticky Add To Cart For WooCommerce <= 1.4.6 - Missing Authorization
Simple Sticky Add To Cart For WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Simple Sticky Add To Cart For WooCommerce Attack Surface
AJAX Handlers 7
WordPress Hooks 20
Maintenance & Trust
Simple Sticky Add To Cart For WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Simple Sticky Add To Cart For WooCommerce Alternatives
Sticky Add To Cart Bar For WooCommerce
sticky-add-to-cart-bar-for-wc
Sticky Add To Cart Bar For WooCommerce is use to add sticky add to cart button on the product page of WooCommerce.
Sticky Add to Cart for WooCommerce
sticky-add-to-cart-for-woocommerce
The WooCommerce Sticky Add to Cart plugin displays a mini content bar at the top of the browser window.
Sticky Product Add to Cart and Checkout Bar for WooCommerce
woo-sticky-product-bar
The WooCommerce Sticky Product Bar is a highly configurable sticky bar that can show product title, price, rating and Add to Cart / Checkout / Pay but …
Offermative – WooCommerce Discount Rules, Upsells & BOGO Powered by AI
offermative-discount-pricing-related-products-upsell-funnels-for-woocommerce
Grow revenue and AOV with targeted and automated WooCommerce discount rules, upsells, cross-sells, order bumps, and dynamic pricing offers.
Add to Cart Button Pro for WooCommerce
add-to-cart-button-for-woocommerce
Customize the Add to Cart button text, color, size, and other styles for different products. Add a floated or sticky Add to Cart button on the screen
Simple Sticky Add To Cart For WooCommerce Developer Profile
5 plugins · 5K total installs
How We Detect Simple Sticky Add To Cart For WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sticky-add-to-cart-woo/assets/css/wsatc-admin.css/wp-content/plugins/sticky-add-to-cart-woo/admin/js/wsatc-admin.js/wp-content/plugins/sticky-add-to-cart-woo/assets/js/wsatc-admin.js/wp-content/plugins/sticky-add-to-cart-woo/admin/js/wsatc-admin.js/wp-content/plugins/sticky-add-to-cart-woo/assets/js/wsatc-admin.js/wp-content/plugins/sticky-add-to-cart-woo/assets/css/wsatc-admin.css?ver=/wp-content/plugins/sticky-add-to-cart-woo/admin/js/wsatc-admin.js?ver=/wp-content/plugins/sticky-add-to-cart-woo/assets/js/wsatc-admin.js?ver=HTML / DOM Fingerprints
wsatc-admin-wrapperwsatc-sticky-add-to-cart<!-- START OF THE STICKY ADD TO CART BUTTON --><!-- END OF THE STICKY ADD TO CART BUTTON -->data-wsatc-product-iddata-wsatc-quantitydata-wsatc-variation-idWSATC