
Sticky Buttons – Floating Buttons Builder Security & Risk Analysis
wordpress.org/plugins/sticky-buttonsIncrease user engagement by incorporating sticky buttons that highlight relevant information on your website.
Is Sticky Buttons – Floating Buttons Builder Safe to Use in 2026?
Generally Safe
Score 98/100Sticky Buttons – Floating Buttons Builder has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'sticky-buttons' plugin version 4.3.5 exhibits a generally good security posture, with a low attack surface and strong adherence to secure coding practices. The plugin demonstrates high percentages of prepared SQL statements and properly escaped output, which are crucial for preventing common web vulnerabilities. Additionally, the presence of nonce and capability checks on its limited entry points is a positive indicator. The absence of external HTTP requests and bundled libraries further reduces potential attack vectors.
However, the static analysis did reveal three high-severity taint flows. While these did not result in critical severity, they still represent potential risks that warrant attention. The vulnerability history shows a past pattern of Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) vulnerabilities, with the most recent one being in January 2025. Although there are currently no unpatched vulnerabilities, this history suggests a recurring need for rigorous security auditing and testing for this plugin to address these types of issues proactively.
In conclusion, the 'sticky-buttons' plugin has several strengths, including a small attack surface and good output sanitization. The presence of high-severity taint flows and past vulnerability trends are the primary areas of concern. While the plugin is currently free of unpatched CVEs, the identified taint flows and historical vulnerability types suggest that ongoing vigilance and potentially a more thorough review of input sanitization for certain data paths are advisable to maintain a robust security profile.
Key Concerns
- High severity taint flows
- Past CSRF and XSS vulnerability history
Sticky Buttons – Floating Buttons Builder Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Sticky Buttons <= 4.1.1 - Cross-Site Request Forgery to Settings Update
Sticky Buttons – floating buttons builder <= 3.2.3 - Cross-Site Request Forgery
Sticky Buttons <= 3.2.2 - Authenticated (Admin+) Stored Cross-Site Scripting
Sticky Buttons – Floating Buttons Builder Release Timeline
Sticky Buttons – Floating Buttons Builder Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Sticky Buttons – Floating Buttons Builder Attack Surface
WordPress Hooks 11
Maintenance & Trust
Sticky Buttons – Floating Buttons Builder Maintenance & Trust
Maintenance Signals
Community Trust
Sticky Buttons – Floating Buttons Builder Alternatives
GB Quick launch
gb-quick-launch
Hover over an icon to discover clickable icons with information. They can have a URL or a Contact form, a shortcode, or any content you choose.
Max Mega Menu
megamenu
An easy to use mega menu plugin. Written the WordPress way.
Social Icons Widget & Block – Social Media Icons & Share Buttons
social-icons-widget-by-wpzoom
Social media icons plugin for WordPress - Add 400+ social icons and share buttons. Gutenberg block, widget & Elementor support. GDPR compliant.
Sticky Menu & Sticky Header
sticky-menu-or-anything-on-scroll
Sticky Menu or Sticky Header sticks elements at the top of the screen when you scroll, or create a floating sticky menu or fixed widget.
WP Mobile Menu – The Mobile-Friendly Responsive Menu
mobile-menu
Need some help with the mobile website experience? Need an Mobile Menu plugin that keep your mobile visitors engaged?
Sticky Buttons – Floating Buttons Builder Developer Profile
26 plugins · 98K total installs
How We Detect Sticky Buttons – Floating Buttons Builder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sticky-buttons/public/assets/css/main.css/wp-content/plugins/sticky-buttons/public/assets/js/main.js/wp-content/plugins/sticky-buttons/public/assets/js/editor.jssticky-buttons/public/assets/css/main.css?ver=sticky-buttons/public/assets/js/main.js?ver=sticky-buttons/public/assets/js/editor.js?ver=HTML / DOM Fingerprints
wowp-link-changewowp-link-ratingwowp-link-prowowp-link-docswowp-link-demowpie-linkswpie-links-dividerdata-wowp-slug="sticky-buttons"WOWP_Plugin_Public/wp-json/sticky-buttons/v1/save-settings[Sticky-Buttons]