Sticky Mobile Buttons Security & Risk Analysis

wordpress.org/plugins/sticky-mobile-buttons

Adds customizable sticky buttons on mobile for quick contact and cart access. Boost Your Mobile Conversions with Floating Action Buttons!

30 active installs v4.0.6 PHP 7.0+ WP 5.0+ Updated Dec 3, 2025
buttonscontactfloatingmobilesticky
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Sticky Mobile Buttons Safe to Use in 2026?

Generally Safe

Score 100/100

Sticky Mobile Buttons has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The "sticky-mobile-buttons" plugin, version 4.0.6, demonstrates a strong security posture with excellent adherence to WordPress security best practices. The static analysis reveals a minimal attack surface, with only one AJAX handler, and importantly, this handler is protected by authentication checks, leaving zero unprotected entry points. The code also shows a commitment to secure coding with 100% of SQL queries using prepared statements and 99% of output properly escaped. The presence of nonce and capability checks further bolsters its security.

The absence of dangerous functions, file operations, and external HTTP requests significantly reduces the potential for common attack vectors. The taint analysis yielding zero flows, especially critical or high severity ones, is a testament to the developers' diligence in sanitizing user input. Furthermore, the plugin has no recorded vulnerability history, including no known CVEs, which indicates a stable and well-maintained codebase over time.

While the plugin exhibits overwhelmingly positive security indicators, the analysis is based on static code and taint flow data, which may not capture all dynamic or logic-based vulnerabilities. However, based on the provided data, this plugin appears to be exceptionally secure. The developers have implemented robust security measures, and the lack of past vulnerabilities suggests a consistent focus on security. It is recommended to maintain this vigilance and continue performing regular security audits.

Vulnerabilities
None known

Sticky Mobile Buttons Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Sticky Mobile Buttons Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
136 escaped
Nonce Checks
2
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

99% escaped138 total outputs
Attack Surface

Sticky Mobile Buttons Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_stmbu_upload_iconincludes\class-stmbu-ajax.php:9
WordPress Hooks 6
actionadmin_menuincludes\class-stmbu-admin.php:38
actionadmin_initincludes\class-stmbu-admin.php:39
actionadmin_enqueue_scriptsincludes\class-stmbu-admin.php:40
actionwp_enqueue_scriptsincludes\class-stmbu-frontend.php:16
actionwp_footerincludes\class-stmbu-frontend.php:17
actionplugins_loadedsticky-mobile-buttons.php:43
Maintenance & Trust

Sticky Mobile Buttons Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 3, 2025
PHP min version7.0
Downloads444

Community Trust

Rating100/100
Number of ratings5
Active installs30
Developer Profile

Sticky Mobile Buttons Developer Profile

webnbpro

1 plugin · 30 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Sticky Mobile Buttons

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sticky-mobile-buttons/assets/css/admin.css/wp-content/plugins/sticky-mobile-buttons/assets/js/admin.js/wp-content/plugins/sticky-mobile-buttons/assets/css/frontend.css
Script Paths
/wp-content/plugins/sticky-mobile-buttons/assets/js/admin.js/wp-content/plugins/sticky-mobile-buttons/assets/js/frontend.js
Version Parameters
sticky-mobile-buttons/assets/css/admin.css?ver=sticky-mobile-buttons/assets/js/admin.js?ver=sticky-mobile-buttons/assets/css/frontend.css?ver=

HTML / DOM Fingerprints

CSS Classes
stmbu-wrapperstmbu-button-containerstmbu-buttonstmbu-button-iconstmbu-button-text
HTML Comments
<!-- Main section --><!-- Section for buttons -->
Data Attributes
data-stmbu-phonedata-stmbu-emaildata-stmbu-whatsappdata-stmbu-urldata-stmbu-custom
JS Globals
stmbu_options
FAQ

Frequently Asked Questions about Sticky Mobile Buttons