Sticky Header by ThematoSoup Security & Risk Analysis

wordpress.org/plugins/sticky-header

Sticky Header by ThematoSoup allows you to add sticky header to any WordPress theme.

1K active installs v1.2.2 PHP + WP 4.0+ Updated Nov 28, 2017
fixed-headerheadersticky-headersticky-menu
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Sticky Header by ThematoSoup Safe to Use in 2026?

Generally Safe

Score 85/100

Sticky Header by ThematoSoup has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The sticky-header v1.2.2 plugin exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of any identified entry points like AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the potential attack surface. Furthermore, the code signals indicate good practices with all SQL queries utilizing prepared statements and no dangerous functions, file operations, or external HTTP requests being present. The lack of recorded vulnerabilities in its history is a significant positive indicator.

However, there are areas for improvement. The output escaping is only at 50%, meaning half of the output points might be vulnerable to Cross-Site Scripting (XSS) if dynamic data is not properly sanitized before output. The absence of nonce checks and capability checks across the board, while not directly leading to vulnerabilities in this specific version due to the lack of entry points, represents a potential weakness if the plugin were to evolve and introduce such points without these security measures. The overall conclusion is that the plugin is currently in a secure state due to a limited attack surface and good SQL handling, but the insufficient output escaping and lack of general security checks on potential future entry points present minor risks.

Key Concerns

  • Output escaping is only 50% proper
  • No nonce checks on potential entry points
  • No capability checks on potential entry points
Vulnerabilities
None known

Sticky Header by ThematoSoup Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Sticky Header by ThematoSoup Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
6 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

50% escaped12 total outputs
Attack Surface

Sticky Header by ThematoSoup Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actioninitclass-sticky-header.php:67
actionwp_enqueue_scriptsclass-sticky-header.php:74
actionwp_enqueue_scriptsclass-sticky-header.php:75
actionwp_footerclass-sticky-header.php:79
actionwp_headclass-sticky-header.php:80
actionadmin_enqueue_scriptsclass-sticky-header.php:81
actionadmin_print_footer_scriptsclass-sticky-header.php:214
actioncustomize_registersticky-header-settings.php:12
actionplugins_loadedsticky-header.php:32
Maintenance & Trust

Sticky Header by ThematoSoup Maintenance & Trust

Maintenance Signals

WordPress version tested4.2.39
Last updatedNov 28, 2017
PHP min version
Downloads82K

Community Trust

Rating90/100
Number of ratings31
Active installs1K
Developer Profile

Sticky Header by ThematoSoup Developer Profile

Slobodan Manic

5 plugins · 2K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Sticky Header by ThematoSoup

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sticky-header/css/public.css/wp-content/plugins/sticky-header/js/public.js/wp-content/plugins/sticky-header/js/public.min.js
Script Paths
/wp-content/plugins/sticky-header/js/public.js/wp-content/plugins/sticky-header/js/public.min.js
Version Parameters
plugins/sticky-header/css/public.css?ver=plugins/sticky-header/js/public.js?ver=plugins/sticky-header/js/public.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
thsp-sticky-headerthsp-sticky-header-inner
JS Globals
StickyHeaderParams
FAQ

Frequently Asked Questions about Sticky Header by ThematoSoup