Oceanwp sticky header Security & Risk Analysis

wordpress.org/plugins/sticky-header-oceanwp

Easy Sticky header installation

10K active installs v1.0.8 PHP + WP 3.5.0+ Updated Oct 22, 2021
headermenunavigationoceanwpsticky
63
C · Use Caution
CVEs total1
Unpatched1
Last CVESep 27, 2022
Download
Safety Verdict

Is Oceanwp sticky header Safe to Use in 2026?

Use With Caution

Score 63/100

Oceanwp sticky header has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Sep 27, 2022Updated 4yr ago
Risk Assessment

The sticky-header-oceanwp plugin v1.0.8 exhibits a mixed security posture. On the positive side, there are no discovered AJAX handlers, REST API routes, shortcodes, or cron events, resulting in a zero attack surface and no immediately apparent direct entry points for attackers. Additionally, all observed SQL queries are prepared, which is a significant security best practice. However, several critical concerns are highlighted by the static analysis. A significant issue is that 100% of the output found is not properly escaped, presenting a high risk of Cross-Site Scripting (XSS) vulnerabilities if any user-controlled data is ever rendered. The taint analysis reveals two flows with unsanitized paths, which, although not classified as critical or high severity in this specific analysis, warrant attention as they could potentially lead to unexpected behavior or information disclosure.

The vulnerability history for this plugin is a major red flag. The presence of one currently unpatched high-severity vulnerability, which last occurred on 2022-09-27, indicates a recurring security weakness. The common vulnerability type being Cross-Site Request Forgery (CSRF) suggests that the plugin may not be consistently implementing proper protection mechanisms for state-changing actions. While the plugin demonstrates good practices in its limited attack surface and SQL handling, the lack of output escaping and the history of unpatched vulnerabilities, particularly CSRF, significantly elevate the overall risk. Users should exercise caution and prioritize updating or seeking alternatives if a patched version addressing the known high-severity vulnerability is not available.

Key Concerns

  • Currently unpatched high severity vulnerability
  • 100% of output unescaped
  • Flows with unsanitized paths found
  • No nonce checks
  • No capability checks
Vulnerabilities
1

Oceanwp sticky header Security Vulnerabilities

CVEs by Year

1 CVE in 2022 · unpatched
2022
Patched Has unpatched

Severity Breakdown

High
1

1 total CVE

CVE-2022-35730high · 8.8Cross-Site Request Forgery (CSRF)

Oceanwp sticky header <= 1.0.8 - Cross-Site Request Forgery to Plugin Settings Update

Sep 27, 2022Unpatched
Code Analysis
Analyzed Mar 16, 2026

Oceanwp sticky header Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped2 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
settings_page (sticky-header-oceanwp.php:73)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Oceanwp sticky header Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_menusticky-header-oceanwp.php:22
actioninitsticky-header-oceanwp.php:23
actionwp_enqueue_scriptssticky-header-oceanwp.php:33
actionwp_headsticky-header-oceanwp.php:36
Maintenance & Trust

Oceanwp sticky header Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedOct 22, 2021
PHP min version
Downloads342K

Community Trust

Rating82/100
Number of ratings24
Active installs10K
Developer Profile

Oceanwp sticky header Developer Profile

קידום ובניית אתרים

4 plugins · 10K total installs

82
trust score
Avg Security Score
83/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Oceanwp sticky header

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sticky-header-oceanwp/style.css/wp-content/plugins/sticky-header-oceanwp/main.js
Script Paths
/wp-content/plugins/sticky-header-oceanwp/main.js
Version Parameters
sticky-header-oceanwp-stylesticky-header-oceanwp

HTML / DOM Fingerprints

JS Globals
sticky_header_style
FAQ

Frequently Asked Questions about Oceanwp sticky header