
Sticky One-Many Security & Risk Analysis
wordpress.org/plugins/sticky-one-manySticky One to Many Elements in Your Website
Is Sticky One-Many Safe to Use in 2026?
Generally Safe
Score 85/100Sticky One-Many has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The sticky-one-many plugin version 1.0 exhibits a concerning security posture primarily due to its unprotected AJAX endpoints. With two AJAX handlers identified and neither possessing authentication checks, there's a significant risk of unauthorized access and potential exploitation of any functionality exposed through these handlers. The presence of `unserialize` without explicit input validation or context also poses a critical risk, as it can lead to remote code execution if an attacker can control the serialized data being processed. While the plugin demonstrates good practices in its SQL querying, using prepared statements exclusively, and has no recorded vulnerability history, these strengths are overshadowed by the immediate threats posed by the exposed AJAX endpoints and the `unserialize` function. The lack of any taint analysis findings is positive, but this may be attributed to the limited scope or nature of the analyzed code rather than a guarantee of its safety. Overall, the plugin has a high risk profile due to directly exploitable entry points and a dangerous function, despite its clean vulnerability history and database query practices.
Key Concerns
- Unprotected AJAX endpoints
- Dangerous function: unserialize without auth checks
- Missing nonce checks on AJAX handlers
- Missing capability checks on AJAX handlers
Sticky One-Many Security Vulnerabilities
Sticky One-Many Code Analysis
Dangerous Functions Found
Output Escaping
Sticky One-Many Attack Surface
AJAX Handlers 2
WordPress Hooks 18
Maintenance & Trust
Sticky One-Many Maintenance & Trust
Maintenance Signals
Community Trust
Sticky One-Many Alternatives
Simple Sticky Footer
simple-sticky-footer
Simple Sticky Footer is a lightweight plugin, it allows to promote/advertise a WP Page (rich-text document) as a sticky footer (always on top div).
BuildWithGuru Sticky Header & Footer Builder for Elementor
buildwithguru
Create custom headers and footers with Elementor and apply optional sticky behavior on scroll. Lightweight and compatible with most WordPress themes.
Sticky Video for Youtube
yt-sticky-video
Gutenberg block to adjust sticky video on frontend side.
Sticky One-Many Developer Profile
3 plugins · 30 total installs
How We Detect Sticky One-Many
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sticky-one-many/assets/js/jquery.jsticky.js/wp-content/plugins/sticky-one-many/assets/css/style.css/wp-content/plugins/sticky-one-many/assets/js/jquery.jsticky.jssticky-one-many/assets/js/jquery.jsticky.js?ver=sticky-one-many/assets/css/style.css?ver=HTML / DOM Fingerprints
cs-shortcode-textareawindow.jQuery<script type="text/javascript">
jQuery(function(){
jQuery('').sticky({
topSpacing:,
zIndex:,
stopper: "