Sticky Floating Forms Lite Security & Risk Analysis

wordpress.org/plugins/sticky-floating-forms-lite

Sticky Floating Forms WordPress plugin allows you to add CTA buttons on your website and when the user clicks on that buttons it will display contact …

1K active installs v1.1.1 PHP 7.4+ WP 5.6+ Updated Sep 17, 2025
contact-form-7floating-formssticky-contactsticky-floating-formssticky-forms
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Sticky Floating Forms Lite Safe to Use in 2026?

Generally Safe

Score 100/100

Sticky Floating Forms Lite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The "sticky-floating-forms-lite" v1.1.1 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of any known vulnerabilities in its history, coupled with good coding practices like 100% use of prepared statements for SQL queries and a high percentage of properly escaped output, suggests a well-maintained and secure codebase. The plugin also demonstrates awareness of security by implementing four nonce checks and one capability check, and importantly, all identified entry points (AJAX handlers) appear to be protected.

However, the static analysis does reveal a few areas that, while not indicating immediate critical vulnerabilities, warrant careful consideration. With one AJAX handler present, even if protected, it represents a potential attack vector that requires continuous monitoring. The taint analysis, while showing no critical or high-severity unsanitized flows, is limited in scope (analyzing only 5 flows). This small sample size means there's a possibility of undiscovered vulnerabilities that a more extensive taint analysis might reveal.

In conclusion, the plugin appears to be secure with no known vulnerabilities and good defensive coding practices observed. The primary strength lies in its clean history and robust output escaping. The main area for potential improvement and cautious oversight would be the limited scope of the taint analysis and the inherent nature of having any AJAX endpoints. Overall, this plugin presents a low-risk profile.

Key Concerns

  • 1 AJAX handler (even if protected)
  • Limited taint analysis scope (5 flows)
  • Minor output escaping concern (7% unescaped)
Vulnerabilities
None known

Sticky Floating Forms Lite Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Sticky Floating Forms Lite Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
75 escaped
Nonce Checks
4
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

93% escaped81 total outputs
Data Flows
All sanitized

Data Flow Analysis

5 flows
save_settings (admin\settings-main.php:296)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Sticky Floating Forms Lite Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_plugin_ajax_notice_handlersticky-floating-forms-class.php:54
WordPress Hooks 7
actionadmin_menuadmin\settings-main.php:11
actionwp_enqueue_scriptsfrontend\dynamic-styles.php:7
actionwp_footerfrontend\frontend.php:8
actioninitsticky-floating-forms-class.php:48
actionwp_enqueue_scriptssticky-floating-forms-class.php:50
actionadmin_enqueue_scriptssticky-floating-forms-class.php:51
actionadmin_noticessticky-floating-forms-class.php:53
Maintenance & Trust

Sticky Floating Forms Lite Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 17, 2025
PHP min version7.4
Downloads45K

Community Trust

Rating92/100
Number of ratings5
Active installs1K
Developer Profile

Sticky Floating Forms Lite Developer Profile

codeworkweb

12 plugins · 7K total installs

94
trust score
Avg Security Score
92/100
Avg Patch Time
3 days
View full developer profile
Detection Fingerprints

How We Detect Sticky Floating Forms Lite

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sticky-floating-forms-lite/assets/css/frontend.css/wp-content/plugins/sticky-floating-forms-lite/admin/assets/css/admin.css/wp-content/plugins/sticky-floating-forms-lite/admin/assets/spectrum/spectrum.min.css/wp-content/plugins/sticky-floating-forms-lite/admin/assets/js/admin.js/wp-content/plugins/sticky-floating-forms-lite/assets/js/frontend.js
Script Paths
/wp-content/plugins/sticky-floating-forms-lite/assets/js/frontend.js/wp-content/plugins/sticky-floating-forms-lite/admin/assets/js/admin.js
Version Parameters
sticky-floating-forms-lite/assets/css/frontend.css?ver=sticky-floating-forms-lite/admin/assets/css/admin.css?ver=sticky-floating-forms-lite/admin/assets/spectrum/spectrum.min.css?ver=sticky-floating-forms-lite/admin/assets/js/admin.js?ver=sticky-floating-forms-lite/assets/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
cww-ssf-outer-wrappcww-ssf-toggle
JS Globals
sff_data
FAQ

Frequently Asked Questions about Sticky Floating Forms Lite