Simple Sticky Add To Cart For WooCommerce Security & Risk Analysis

wordpress.org/plugins/sticky-add-to-cart-woo

Simple Sticky add to cart for WooCommerce show on product page top and bottom with full color customization and much more option.

1K active installs v1.4.9 PHP 7.0+ WP 5.0+ Updated Jan 21, 2026
stick-bar-for-woocommercesticky-add-to-cartwoocommercewoocommerce-sticky-barwoocommerce-upsells
79
B · Generally Safe
CVEs total1
Unpatched1
Last CVEApr 1, 2025
Safety Verdict

Is Simple Sticky Add To Cart For WooCommerce Safe to Use in 2026?

Mostly Safe

Score 79/100

Simple Sticky Add To Cart For WooCommerce is generally safe to use. 1 past CVE were resolved. Keep it updated.

1 known CVE 1 unpatched Last CVE: Apr 1, 2025Updated 2mo ago
Risk Assessment

The "sticky-add-to-cart-woo" v1.4.9 plugin presents a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and includes a reasonable number of nonce checks. The absence of dangerous functions and file operations is also a strength.

However, significant concerns arise from the attack surface analysis. The plugin exposes seven AJAX handlers, with five of them lacking proper authentication checks. This is a critical vulnerability as it allows unauthenticated users to potentially trigger actions within the plugin, leading to unauthorized behavior or information disclosure.

The vulnerability history indicates a concerning pattern, with one medium-severity CVE already recorded and currently unpatched, specifically related to missing authorization. This reinforces the findings from the static analysis regarding unprotected AJAX handlers. While taint analysis shows no immediate critical or high severity flows, the existing medium vulnerability and the large number of unprotected entry points suggest a higher likelihood of future issues if not addressed. The low percentage of properly escaped output (38%) is also a concern, increasing the risk of cross-site scripting (XSS) vulnerabilities.

In conclusion, while the plugin has some good security foundations, the unprotected AJAX endpoints and the unpatched medium vulnerability significantly elevate its risk profile. The poor output escaping practices further exacerbate these concerns. Immediate attention is required to secure the AJAX handlers and address the existing unpatched vulnerability.

Key Concerns

  • Unpatched CVE (Medium Severity)
  • Large attack surface without auth (5 AJAX handlers)
  • Low percentage of properly escaped output (38%)
  • Missing authorization on AJAX handlers (implied by 5 unprotected)
Vulnerabilities
1

Simple Sticky Add To Cart For WooCommerce Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-31854medium · 4.3Missing Authorization

Simple Sticky Add To Cart For WooCommerce <= 1.4.6 - Missing Authorization

Apr 1, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Simple Sticky Add To Cart For WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
71
43 escaped
Nonce Checks
6
Capability Checks
2
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

38% escaped114 total outputs
Attack Surface
5 unprotected

Simple Sticky Add To Cart For WooCommerce Attack Surface

Entry Points7
Unprotected5

AJAX Handlers 7

authwp_ajax_wsatc_pro_analyticsadmin\reports\class-wsatc-analytics.php:35
noprivwp_ajax_wsatc_pro_analyticsadmin\reports\class-wsatc-analytics.php:36
authwp_ajax_wsatc_save_settingsincludes\class-wsatc.php:169
authwp_ajax_wsatc_reset_settingsincludes\class-wsatc.php:170
authwp_ajax_wsatc_deactivation_feedbackincludes\class-wsatc.php:172
authwp_ajax_wsatc_add_cart_singleincludes\class-wsatc.php:214
noprivwp_ajax_wsatc_add_cart_singleincludes\class-wsatc.php:215
WordPress Hooks 20
actionwsatc_analytics_headeradmin\reports\class-wsatc-analytics.php:38
actionplugins_loadedincludes\class-wsatc.php:152
actionadmin_enqueue_scriptsincludes\class-wsatc.php:166
actionadmin_enqueue_scriptsincludes\class-wsatc.php:167
actionadmin_menuincludes\class-wsatc.php:168
actionplugin_action_linksincludes\class-wsatc.php:171
actionwp_dashboard_setupincludes\class-wsatc.php:173
actionadmin_noticesincludes\class-wsatc.php:174
actionadmin_noticesincludes\class-wsatc.php:175
filterplugin_row_metaincludes\class-wsatc.php:178
filtersolbox_deactivate_feedback_form_pluginsincludes\class-wsatc.php:179
filterwsatc_after_analytics_headerincludes\class-wsatc.php:180
actionwp_enqueue_scriptsincludes\class-wsatc.php:199
actionwp_enqueue_scriptsincludes\class-wsatc.php:200
actionwp_footerincludes\class-wsatc.php:201
actionwp_headincludes\class-wsatc.php:202
filterwsatc_product_hidepublic\class-wsatc-public.php:65
actionplugins_loadedwoo-sticky-add-to-cart.php:78
actionbefore_woocommerce_initwoo-sticky-add-to-cart.php:79
actionadmin_noticeswoo-sticky-add-to-cart.php:100
Maintenance & Trust

Simple Sticky Add To Cart For WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 21, 2026
PHP min version7.0
Downloads40K

Community Trust

Rating84/100
Number of ratings38
Active installs1K
Developer Profile

Simple Sticky Add To Cart For WooCommerce Developer Profile

Sharaz Shahid

5 plugins · 5K total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Simple Sticky Add To Cart For WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sticky-add-to-cart-woo/assets/css/wsatc-admin.css/wp-content/plugins/sticky-add-to-cart-woo/admin/js/wsatc-admin.js/wp-content/plugins/sticky-add-to-cart-woo/assets/js/wsatc-admin.js
Script Paths
/wp-content/plugins/sticky-add-to-cart-woo/admin/js/wsatc-admin.js/wp-content/plugins/sticky-add-to-cart-woo/assets/js/wsatc-admin.js
Version Parameters
/wp-content/plugins/sticky-add-to-cart-woo/assets/css/wsatc-admin.css?ver=/wp-content/plugins/sticky-add-to-cart-woo/admin/js/wsatc-admin.js?ver=/wp-content/plugins/sticky-add-to-cart-woo/assets/js/wsatc-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
wsatc-admin-wrapperwsatc-sticky-add-to-cart
HTML Comments
<!-- START OF THE STICKY ADD TO CART BUTTON --><!-- END OF THE STICKY ADD TO CART BUTTON -->
Data Attributes
data-wsatc-product-iddata-wsatc-quantitydata-wsatc-variation-id
JS Globals
WSATC
FAQ

Frequently Asked Questions about Simple Sticky Add To Cart For WooCommerce