
Sticky Banner Security & Risk Analysis
wordpress.org/plugins/sticky-bannerCreate eye-catching announcement banners that stick to the top or bottom of your site. Perfect for promotions, alerts, and important updates.
Is Sticky Banner Safe to Use in 2026?
Generally Safe
Score 99/100Sticky Banner has a strong security track record. Known vulnerabilities have been patched promptly.
The "sticky-banner" plugin v1.5.0 shows a mixed security posture. On one hand, the static analysis reveals a very limited attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events. The code also demonstrates good practices with a high percentage of properly escaped output and no file operations or external HTTP requests. However, there are notable concerns regarding SQL query handling and the lack of comprehensive security checks.
The static analysis indicates one SQL query that is not using prepared statements, which is a significant risk for SQL injection vulnerabilities, especially if user input is involved. While taint analysis found no issues, this is based on zero flows analyzed, meaning the analysis might not have been exhaustive enough to uncover potential vulnerabilities. The plugin also lacks nonce checks on its entry points, which, although currently zero, leaves it vulnerable should any be introduced without proper security measures. The presence of one medium-severity Cross-Site Scripting (XSS) vulnerability historically, even if patched, suggests that input sanitization and output escaping in specific contexts might require more rigorous testing.
Overall, the plugin has strengths in its limited attack surface and output escaping. However, the unescaped SQL query and the historical XSS vulnerability, coupled with a lack of nonce checks, warrant caution. The limited taint analysis coverage is also a point of concern, as it might not be providing a complete picture of potential risks.
Key Concerns
- Raw SQL queries without prepared statements
- Historical medium severity XSS vulnerability
- Lack of nonce checks
- Limited taint flow analysis coverage
Sticky Banner Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Sticky banner <= 1.2.0 - Authenticated (Administrator+) Stored Cross-Site Scripting
Sticky Banner Code Analysis
SQL Query Safety
Output Escaping
Sticky Banner Attack Surface
WordPress Hooks 8
Maintenance & Trust
Sticky Banner Maintenance & Trust
Maintenance Signals
Community Trust
Sticky Banner Alternatives
Notibar – Notification Bar for WordPress
notibar
Customizer for sticky header, notification bar, alert, promo code, marketing campaign, top banner
Simple Alert System
simple-alert-system
Simple Alert System is a FREE responsive and simplified WordPress website notification system..
ConvBoost Sticky Notification Bar
convboost-sticky-notification-bar
Lightweight sticky top/bottom bar for promos & announcements. CTA, scheduling, exclusions, and live admin preview.
Lightweight High Performance Sticky Bar
lightweight-high-performance-sticky-bar
Add a customizable sticky notification bar with countdown functionality to your website with minimal performance impact.
My Sticky Bar – Floating Notification Bar & Sticky Header (formerly myStickymenu)
mystickymenu
Create a welcome notification bar for your website. Also, My Sticky Bar plugin can make your menu or header sticky to the top when scrolled 📌
Sticky Banner Developer Profile
1 plugin · 600 total installs
How We Detect Sticky Banner
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sticky-banner/assets/css/stickybanner-admin.css/wp-content/plugins/sticky-banner/assets/css/stickybanner.css/wp-content/plugins/sticky-banner/assets/js/stickybanner.min.js/wp-content/plugins/sticky-banner/assets/js/stickybanner.min.jssticky-banner/assets/css/stickybanner-admin.css?ver=sticky-banner/assets/css/stickybanner.css?ver=sticky-banner/assets/js/stickybanner.min.js?ver=HTML / DOM Fingerprints
hdsb-stickybannerhdsb-stickybanner-texthdsb-stickybanner-btn