Sticky CTA Button Security & Risk Analysis

wordpress.org/plugins/sticky-cta-button

A configurable sticky CTA button with back-to-top functionality. Fully customizable through WordPress settings.

10 active installs v1.0.0 PHP 7.4+ WP 5.0+ Updated Aug 28, 2025
back-to-topbuttonctafloatingsticky
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Sticky CTA Button Safe to Use in 2026?

Generally Safe

Score 100/100

Sticky CTA Button has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7mo ago
Risk Assessment

The sticky-cta-button plugin v1.0.0 exhibits a strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points significantly minimizes the potential attack surface. Furthermore, the code demonstrates excellent practices by utilizing prepared statements for all SQL queries and ensuring 100% of output is properly escaped, which are crucial for preventing common vulnerabilities like SQL injection and cross-site scripting.

The static analysis revealed no dangerous functions, file operations, external HTTP requests, or critical taint analysis flows, further reinforcing its secure design. The presence of a capability check, while minimal, is a positive sign of considering user roles. The complete lack of known vulnerabilities in its history is also a significant strength, suggesting a commitment to security or a lack of prior discovery.

However, the complete absence of nonce checks on any potential entry points (even though there are none identified) is a minor oversight. While not immediately exploitable due to the lack of entry points, it's a good practice to include them if any entry points were to be added in the future. Overall, the plugin appears to be very secure, with its strengths far outweighing any minor potential concerns.

Vulnerabilities
None known

Sticky CTA Button Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Sticky CTA Button Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
95 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped95 total outputs
Attack Surface

Sticky CTA Button Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actioninitsticky-cta-button.php:32
actionadmin_menusticky-cta-button.php:38
actionadmin_initsticky-cta-button.php:39
actionadmin_enqueue_scriptssticky-cta-button.php:40
actionwp_enqueue_scriptssticky-cta-button.php:44
actionwp_footersticky-cta-button.php:45
Maintenance & Trust

Sticky CTA Button Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedAug 28, 2025
PHP min version7.4
Downloads256

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Sticky CTA Button Developer Profile

Desk9 Design

4 plugins · 110 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Sticky CTA Button

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sticky-cta-button/assets/admin-style.css/wp-content/plugins/sticky-cta-button/assets/admin-script.js/wp-content/plugins/sticky-cta-button/assets/style.css/wp-content/plugins/sticky-cta-button/assets/script.js
Script Paths
/wp-content/plugins/sticky-cta-button/assets/admin-script.js/wp-content/plugins/sticky-cta-button/assets/script.js
Version Parameters
sticky-cta-button/assets/admin-style.css?ver=sticky-cta-button/assets/admin-script.js?ver=sticky-cta-button/assets/style.css?ver=sticky-cta-button/assets/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
wp-sticky-button-containerwp-sticky-cta-buttonwp-sticky-back-to-top
Data Attributes
data-display-behaviordata-combined-layoutdata-vertical-orderdata-horizontal-orderdata-radius-enableddata-radius-value
FAQ

Frequently Asked Questions about Sticky CTA Button