
Sticky Floating Forms Lite Security & Risk Analysis
wordpress.org/plugins/sticky-floating-forms-liteSticky Floating Forms WordPress plugin allows you to add CTA buttons on your website and when the user clicks on that buttons it will display contact …
Is Sticky Floating Forms Lite Safe to Use in 2026?
Generally Safe
Score 100/100Sticky Floating Forms Lite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "sticky-floating-forms-lite" v1.1.1 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of any known vulnerabilities in its history, coupled with good coding practices like 100% use of prepared statements for SQL queries and a high percentage of properly escaped output, suggests a well-maintained and secure codebase. The plugin also demonstrates awareness of security by implementing four nonce checks and one capability check, and importantly, all identified entry points (AJAX handlers) appear to be protected.
However, the static analysis does reveal a few areas that, while not indicating immediate critical vulnerabilities, warrant careful consideration. With one AJAX handler present, even if protected, it represents a potential attack vector that requires continuous monitoring. The taint analysis, while showing no critical or high-severity unsanitized flows, is limited in scope (analyzing only 5 flows). This small sample size means there's a possibility of undiscovered vulnerabilities that a more extensive taint analysis might reveal.
In conclusion, the plugin appears to be secure with no known vulnerabilities and good defensive coding practices observed. The primary strength lies in its clean history and robust output escaping. The main area for potential improvement and cautious oversight would be the limited scope of the taint analysis and the inherent nature of having any AJAX endpoints. Overall, this plugin presents a low-risk profile.
Key Concerns
- 1 AJAX handler (even if protected)
- Limited taint analysis scope (5 flows)
- Minor output escaping concern (7% unescaped)
Sticky Floating Forms Lite Security Vulnerabilities
Sticky Floating Forms Lite Code Analysis
Output Escaping
Data Flow Analysis
Sticky Floating Forms Lite Attack Surface
AJAX Handlers 1
WordPress Hooks 7
Maintenance & Trust
Sticky Floating Forms Lite Maintenance & Trust
Maintenance Signals
Community Trust
Sticky Floating Forms Lite Alternatives
Database Addon for Contact Form 7 – CFDB7
contact-form-cfdb7
Save and manage Contact Form 7 messages. Never lose important data. It is a lightweight contact form 7 database plugin.
ReCaptcha v2 for Contact Form 7
wpcf7-recaptcha
Adds reCaptcha v2 from Contact Form 7 5.0.5 that was dropped on Contact Form 7 5.1
Redirection for Contact Form 7
wpcf7-redirect
Redirect to any page or URL, execute scripts after submission, save data to the database, and unlock additional submission actions for Contact Form 7.
Conditional Fields for Contact Form 7
cf7-conditional-fields
Adds conditional logic to Contact Form 7.
Contact Form 7 – Dynamic Text Extension
contact-form-7-dynamic-text-extension
Extends Contact Form 7 by adding dynamic form fields that accepts shortcodes to prepopulate form fields with default values and dynamic placeholders.
Sticky Floating Forms Lite Developer Profile
12 plugins · 7K total installs
How We Detect Sticky Floating Forms Lite
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sticky-floating-forms-lite/assets/css/frontend.css/wp-content/plugins/sticky-floating-forms-lite/admin/assets/css/admin.css/wp-content/plugins/sticky-floating-forms-lite/admin/assets/spectrum/spectrum.min.css/wp-content/plugins/sticky-floating-forms-lite/admin/assets/js/admin.js/wp-content/plugins/sticky-floating-forms-lite/assets/js/frontend.js/wp-content/plugins/sticky-floating-forms-lite/assets/js/frontend.js/wp-content/plugins/sticky-floating-forms-lite/admin/assets/js/admin.jssticky-floating-forms-lite/assets/css/frontend.css?ver=sticky-floating-forms-lite/admin/assets/css/admin.css?ver=sticky-floating-forms-lite/admin/assets/spectrum/spectrum.min.css?ver=sticky-floating-forms-lite/admin/assets/js/admin.js?ver=sticky-floating-forms-lite/assets/js/frontend.js?ver=HTML / DOM Fingerprints
cww-ssf-outer-wrappcww-ssf-togglesff_data