
Sticky Custom Post Types Security & Risk Analysis
wordpress.org/plugins/sticky-custom-post-typesEnables support for sticky custom post types.
Is Sticky Custom Post Types Safe to Use in 2026?
Generally Safe
Score 85/100Sticky Custom Post Types has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'sticky-custom-post-types' plugin v1.2.3 exhibits a generally strong security posture based on the provided static analysis. The absence of detected dangerous functions, raw SQL queries, file operations, and external HTTP requests is commendable. Furthermore, the plugin demonstrates good practices in handling SQL queries with prepared statements and a high percentage of properly escaped outputs, which helps mitigate Cross-Site Scripting (XSS) risks.
The analysis reveals a remarkably small attack surface, with no identified AJAX handlers, REST API routes, shortcodes, or cron events. This significantly limits potential entry points for attackers. The presence of a capability check, although only one, is a positive sign, indicating some awareness of access control.
The plugin's vulnerability history is exceptionally clean, with no known CVEs recorded. This, combined with the lack of critical or high severity taint flows, suggests a well-maintained and secure codebase. Overall, this plugin appears to be a low-risk option. However, the complete absence of nonce checks across all potential entry points (even though there are none detected) could become a concern if the attack surface were to expand in future versions without corresponding security updates.
Key Concerns
- No nonce checks detected
- Lower output escaping percentage (80%)
Sticky Custom Post Types Security Vulnerabilities
Sticky Custom Post Types Code Analysis
Output Escaping
Sticky Custom Post Types Attack Surface
WordPress Hooks 3
Maintenance & Trust
Sticky Custom Post Types Maintenance & Trust
Maintenance Signals
Community Trust
Sticky Custom Post Types Alternatives
Ultimate Posts Widget
ultimate-posts-widget
The ultimate widget for displaying posts, custom post types or sticky posts with an array of options.
Post Type Spotlight
post-type-spotlight
x-release-please-start-version Stable tag: 3.0.3 x-release-please-end License: GPLv2 or later License URI: http://www.gnu.org/licenses/gpl-2.0.
Custom Post Type UI
custom-post-type-ui
Admin UI for creating custom content types like post types and taxonomies
Meta Box
meta-box
Meta Box plugin is a powerful, professional developer toolkit to create custom meta boxes and custom fields for your custom post types in WordPress.
Sticky Header Effects for Elementor
sticky-header-effects-for-elementor
Create advanced Sticky Headers in Elementor Free or Pro with scroll effects, blur, shrink, hide on scroll & full responsive controls.
Sticky Custom Post Types Developer Profile
3 plugins · 670 total installs
How We Detect Sticky Custom Post Types
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
selectitname="sticky"name="sticky_custom_post_types[]"name="sticky_custom_post_types_filters[]"id="super-sticky"id="sticky_custom_post_types_filters_home"id="post_type_post"