Sticky Buttons – Floating Buttons Builder Security & Risk Analysis

wordpress.org/plugins/sticky-buttons

Increase user engagement by incorporating sticky buttons that highlight relevant information on your website.

10K active installs v4.3.5 PHP 7.4+ WP 5.5+ Updated Mar 7, 2026
action-buttonfloating-menumobile-menusocial-iconssticky-buttons
98
A · Safe
CVEs total3
Unpatched0
Last CVEJan 24, 2025
Safety Verdict

Is Sticky Buttons – Floating Buttons Builder Safe to Use in 2026?

Generally Safe

Score 98/100

Sticky Buttons – Floating Buttons Builder has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

3 known CVEsLast CVE: Jan 24, 2025Updated 2mo ago
Risk Assessment

The 'sticky-buttons' plugin version 4.3.5 exhibits a generally good security posture, with a low attack surface and strong adherence to secure coding practices. The plugin demonstrates high percentages of prepared SQL statements and properly escaped output, which are crucial for preventing common web vulnerabilities. Additionally, the presence of nonce and capability checks on its limited entry points is a positive indicator. The absence of external HTTP requests and bundled libraries further reduces potential attack vectors.

However, the static analysis did reveal three high-severity taint flows. While these did not result in critical severity, they still represent potential risks that warrant attention. The vulnerability history shows a past pattern of Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) vulnerabilities, with the most recent one being in January 2025. Although there are currently no unpatched vulnerabilities, this history suggests a recurring need for rigorous security auditing and testing for this plugin to address these types of issues proactively.

In conclusion, the 'sticky-buttons' plugin has several strengths, including a small attack surface and good output sanitization. The presence of high-severity taint flows and past vulnerability trends are the primary areas of concern. While the plugin is currently free of unpatched CVEs, the identified taint flows and historical vulnerability types suggest that ongoing vigilance and potentially a more thorough review of input sanitization for certain data paths are advisable to maintain a robust security profile.

Key Concerns

  • High severity taint flows
  • Past CSRF and XSS vulnerability history
Vulnerabilities
3 published

Sticky Buttons – Floating Buttons Builder Security Vulnerabilities

CVEs by Year

2 CVEs in 2024
2024
1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
3

3 total CVEs

CVE-2025-24720medium · 4.3Cross-Site Request Forgery (CSRF)

Sticky Buttons <= 4.1.1 - Cross-Site Request Forgery to Settings Update

Jan 24, 2025 Patched in 4.1.2 (5d)
CVE-2024-3475medium · 4.3Cross-Site Request Forgery (CSRF)

Sticky Buttons – floating buttons builder <= 3.2.3 - Cross-Site Request Forgery

Apr 11, 2024 Patched in 3.2.4 (27d)
CVE-2024-0703medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Sticky Buttons <= 3.2.2 - Authenticated (Admin+) Stored Cross-Site Scripting

Jan 22, 2024 Patched in 3.2.3 (190d)
Version History

Sticky Buttons – Floating Buttons Builder Release Timeline

v4.3.5Current
v4.3.4
v4.3.3
v4.3.2
v4.3.1
v4.3
v4.2.2
v4.2.1
v4.2
v4.1.5
v4.1.4
v4.1.3
v4.1.2
v4.1.11 CVE
v4.11 CVE
v4.0.21 CVE
v4.0.11 CVE
v4.01 CVE
v3.2.41 CVE
Code Analysis
Analyzed Mar 16, 2026

Sticky Buttons – Floating Buttons Builder Code Analysis

Dangerous Functions
0
Raw SQL Queries
6
20 prepared
Unescaped Output
9
315 escaped
Nonce Checks
4
Capability Checks
4
File Operations
1
External Requests
0
Bundled Libraries
0

SQL Query Safety

77% prepared26 total queries

Output Escaping

97% escaped324 total outputs
Data Flows · Security
10 unsanitized

Data Flow Analysis

10 flows10 with unsanitized paths
menu (classes\Admin\Dashboard.php:161)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Sticky Buttons – Floating Buttons Builder Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionadmin_initclasses\Admin\AdminActions.php:25
actionadmin_noticesclasses\Admin\AdminNotices.php:26
filterplugin_action_linksclasses\Admin\Dashboard.php:21
filteradmin_footer_textclasses\Admin\Dashboard.php:22
actionadmin_enqueue_scriptsclasses\Admin\Dashboard.php:23
actionadmin_menuclasses\Admin\Dashboard.php:24
actionadmin_menuincludes\class-wow-company.php:22
actionadmin_enqueue_scriptsincludes\class-wow-company.php:23
actionwp_enqueue_scriptspublic\class-wowp-public.php:36
actionwp_footerpublic\class-wowp-public.php:37
actionplugins_loadedsticky-buttons.php:70
Maintenance & Trust

Sticky Buttons – Floating Buttons Builder Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 7, 2026
PHP min version7.4
Downloads151K

Community Trust

Rating74/100
Number of ratings6
Active installs10K
Developer Profile

Sticky Buttons – Floating Buttons Builder Developer Profile

Wow-Company

26 plugins · 98K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
236 days
View full developer profile
Detection Fingerprints

How We Detect Sticky Buttons – Floating Buttons Builder

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sticky-buttons/public/assets/css/main.css/wp-content/plugins/sticky-buttons/public/assets/js/main.js/wp-content/plugins/sticky-buttons/public/assets/js/editor.js
Version Parameters
sticky-buttons/public/assets/css/main.css?ver=sticky-buttons/public/assets/js/main.js?ver=sticky-buttons/public/assets/js/editor.js?ver=

HTML / DOM Fingerprints

CSS Classes
wowp-link-changewowp-link-ratingwowp-link-prowowp-link-docswowp-link-demowpie-linkswpie-links-divider
Data Attributes
data-wowp-slug="sticky-buttons"
JS Globals
WOWP_Plugin_Public
REST Endpoints
/wp-json/sticky-buttons/v1/save-settings
Shortcode Output
[Sticky-Buttons]
FAQ

Frequently Asked Questions about Sticky Buttons – Floating Buttons Builder