
Sticky Banner Security & Risk Analysis
wordpress.org/plugins/sticky-bannerCreate eye-catching announcement banners that stick to the top or bottom of your site. Perfect for promotions, alerts, and important updates.
Is Sticky Banner Safe to Use in 2026?
Generally Safe
Score 100/100Sticky Banner has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "sticky-banner" plugin v1.5.0 shows a mixed security posture. On one hand, the static analysis reveals a very limited attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events. The code also demonstrates good practices with a high percentage of properly escaped output and no file operations or external HTTP requests. However, there are notable concerns regarding SQL query handling and the lack of comprehensive security checks.
The static analysis indicates one SQL query that is not using prepared statements, which is a significant risk for SQL injection vulnerabilities, especially if user input is involved. While taint analysis found no issues, this is based on zero flows analyzed, meaning the analysis might not have been exhaustive enough to uncover potential vulnerabilities. The plugin also lacks nonce checks on its entry points, which, although currently zero, leaves it vulnerable should any be introduced without proper security measures. The presence of one medium-severity Cross-Site Scripting (XSS) vulnerability historically, even if patched, suggests that input sanitization and output escaping in specific contexts might require more rigorous testing.
Overall, the plugin has strengths in its limited attack surface and output escaping. However, the unescaped SQL query and the historical XSS vulnerability, coupled with a lack of nonce checks, warrant caution. The limited taint analysis coverage is also a point of concern, as it might not be providing a complete picture of potential risks.
Key Concerns
- Raw SQL queries without prepared statements
- Historical medium severity XSS vulnerability
- Lack of nonce checks
- Limited taint flow analysis coverage
Sticky Banner Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Sticky banner <= 1.2.0 - Authenticated (Administrator+) Stored Cross-Site Scripting
Sticky Banner Release Timeline
Sticky Banner Code Analysis
SQL Query Safety
Output Escaping
Sticky Banner Attack Surface
WordPress Hooks 8
Maintenance & Trust
Sticky Banner Maintenance & Trust
Maintenance Signals
Community Trust
Sticky Banner Alternatives
Notibar – Notification Bar for WordPress
notibar
Multiple notification bars with React-powered customizer, live preview, smart scheduling, and per-bar display rules.
Buzzbar – Announcement Bar, Promo Bar & Notification Banner
buzzbar-notification-bar
Add high-converting announcement bars, promo banners, and scrolling notifications to your site—no coding required.
Varsby
varsby
Simple, accessible notification bars for WordPress — for announcements, promos or urgent updates.
Simple Alert System
simple-alert-system
Simple Alert System is a FREE responsive and simplified WordPress website notification system..
AAWEB Announcement Bar
aaweb-announcement-bar
A lightweight announcement bar with scheduling, dismiss button, device visibility and WooCommerce-safe display rules.
Sticky Banner Developer Profile
1 plugin · 700 total installs
How We Detect Sticky Banner
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sticky-banner/assets/css/stickybanner-admin.css/wp-content/plugins/sticky-banner/assets/css/stickybanner.css/wp-content/plugins/sticky-banner/assets/js/stickybanner.min.js/wp-content/plugins/sticky-banner/assets/js/stickybanner.min.jssticky-banner/assets/css/stickybanner-admin.css?ver=sticky-banner/assets/css/stickybanner.css?ver=sticky-banner/assets/js/stickybanner.min.js?ver=HTML / DOM Fingerprints
hdsb-stickybannerhdsb-stickybanner-texthdsb-stickybanner-btn