
Sticky Menu & Sticky Header Security & Risk Analysis
wordpress.org/plugins/sticky-menu-or-anything-on-scrollSticky Menu or Sticky Header sticks elements at the top of the screen when you scroll, or create a floating sticky menu or fixed widget.
Is Sticky Menu & Sticky Header Safe to Use in 2026?
Generally Safe
Score 100/100Sticky Menu & Sticky Header has a strong security track record. Known vulnerabilities have been patched promptly.
The 'sticky-menu-or-anything-on-scroll' plugin version 2.34 demonstrates a generally good security posture based on the static analysis. The plugin has a minimal attack surface, with only one AJAX handler and no REST API routes, shortcodes, or cron events. Notably, all identified entry points have authentication checks. The code signals further support this, with no dangerous functions, all SQL queries using prepared statements, and a high percentage of properly escaped output. The presence of nonce and capability checks indicates an awareness of common WordPress security practices. Taint analysis shows no identified vulnerabilities in this regard.
However, the plugin's vulnerability history is a point of concern. It has a recorded CVE, albeit an older one from 2020. While currently unpatched vulnerabilities are zero, the presence of a past medium-severity vulnerability, specifically Cross-site Scripting, suggests that the plugin is not immune to certain attack vectors. The fact that this vulnerability was a medium severity XSS is a notable weakness, even if it has since been patched. This history warrants a degree of caution, as past issues can sometimes indicate recurring development practices or overlooked edge cases.
In conclusion, version 2.34 of 'sticky-menu-or-anything-on-scroll' shows significant improvements and adherence to secure coding practices, particularly regarding its limited attack surface and proper handling of database queries and output. Nevertheless, the historical medium-severity XSS vulnerability, even if resolved, means users should remain vigilant and ensure they are always on the latest version to benefit from any further security enhancements and fixes.
Key Concerns
- Past medium severity vulnerability (XSS)
Sticky Menu & Sticky Header Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Sticky Menu & Sticky Header <= 2.20 - Reflected Cross-Site Scripting
Sticky Menu & Sticky Header Code Analysis
Output Escaping
Sticky Menu & Sticky Header Attack Surface
AJAX Handlers 1
WordPress Hooks 16
Maintenance & Trust
Sticky Menu & Sticky Header Maintenance & Trust
Maintenance Signals
Community Trust
Sticky Menu & Sticky Header Alternatives
Stick My Header for Astra
stick-my-header-for-astra
Improve your website's header design and make it stick to the top once Stick My Header For Astra is activated.
WP Stickit – Sticky Header, Menu, Sidebar & More
wp-stickit
Make any element sticky with customizable positioning, responsive breakpoints, and z-index control.
My Sticky Bar – Floating Notification Bar & Sticky Header (formerly myStickymenu)
mystickymenu
Create a welcome notification bar for your website. Also, My Sticky Bar plugin can make your menu or header sticky to the top when scrolled 📌
Float menu – awesome floating side menu
float-menu
Easily create floating menus of varying complexity. Use its capabilities to place unique navigation on the site.
All-in-One Sticky Anything – Fixed Widget, Sticky Header, Menu, Sidebar, Social Icons & Cookie Consent
all-in-one-wp-sticky-anything
All-in-One Sticky Anything easily creates fixed widgets, sticky elements, sticky header, menu, sidebar, social icons & cookie consent on your website.
Sticky Menu & Sticky Header Developer Profile
28 plugins · 3.5M total installs
How We Detect Sticky Menu & Sticky Header
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sticky-menu-or-anything-on-scroll/assets/js/jq-sticky-anything.min.js/wp-content/plugins/sticky-menu-or-anything-on-scroll/assets/js/jq-sticky-anything.js/wp-content/plugins/sticky-menu-or-anything-on-scroll/assets/js/stickThis.jsassets/js/jq-sticky-anything.jsassets/js/stickThis.jssticky-menu-or-anything-on-scroll/assets/js/jq-sticky-anything.js?ver=sticky-menu-or-anything-on-scroll/assets/js/stickThis.js?ver=HTML / DOM Fingerprints
sticky-menu-anythingsticky-menu-anything-sticky-wrapper<!-- START: sticky-menu-anything --><!-- END: sticky-menu-anything --><!-- sticky-menu-anything : PHP -->data-sticky-iddata-sticky-elementdata-sticky-topspacedata-sticky-minscreenwidthdata-sticky-maxscreenwidthdata-sticky-zindex+5 moresticky_anything_engage