Sticky Posts Dashboard Widget Security & Risk Analysis

wordpress.org/plugins/sticky-posts-dashboard-widget

The dashboard widget shows the sticky posts

10 active installs v0.1 PHP + WP 3.0+ Updated Oct 29, 2014
dashboardpostsstickywidgets
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Sticky Posts Dashboard Widget Safe to Use in 2026?

Generally Safe

Score 85/100

Sticky Posts Dashboard Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The plugin 'sticky-posts-dashboard-widget' v0.1 exhibits a generally good security posture based on the provided static analysis. The absence of identified dangerous functions, external HTTP requests, file operations, and SQL queries using prepared statements are strong indicators of secure coding practices. Furthermore, the plugin has no known vulnerabilities or CVEs, suggesting a history of stable and secure development. However, there are areas for improvement. The complete lack of nonce checks and capability checks on entry points, coupled with a concerningly low percentage of properly escaped output (33%), presents potential risks. While the attack surface is currently reported as zero and taint analysis found no issues, these weaknesses could be exploited if an attack vector were to be introduced or discovered. Therefore, while the plugin is not currently flagged with critical vulnerabilities, it is not entirely risk-free and benefits from further hardening, particularly regarding input validation and output sanitization.

Key Concerns

  • Output not properly escaped
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Sticky Posts Dashboard Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Sticky Posts Dashboard Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

33% escaped3 total outputs
Attack Surface

Sticky Posts Dashboard Widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionwp_dashboard_setupclass-sticky-posts-dashboard-widget.php:26
actionplugins_loadedclass-sticky-posts-dashboard-widget.php:27
actiondashboard_glance_itemsclass-sticky-posts-dashboard-widget.php:31
Maintenance & Trust

Sticky Posts Dashboard Widget Maintenance & Trust

Maintenance Signals

WordPress version tested4.5.33
Last updatedOct 29, 2014
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Sticky Posts Dashboard Widget Developer Profile

Frank Neumann-Staude

11 plugins · 8K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Sticky Posts Dashboard Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sticky-posts-dashboard-widget/css/jquery.tablesorter.pager.css/wp-content/plugins/sticky-posts-dashboard-widget/css/sticky-posts.css/wp-content/plugins/sticky-posts-dashboard-widget/js/jquery.tablesorter.min.js/wp-content/plugins/sticky-posts-dashboard-widget/js/jquery.tablesorter.pager.js
Script Paths
/wp-content/plugins/sticky-posts-dashboard-widget/js/jquery.tablesorter.min.js/wp-content/plugins/sticky-posts-dashboard-widget/js/jquery.tablesorter.pager.js

HTML / DOM Fingerprints

CSS Classes
tablesorterpagerdashiconssticky-posts-tablesorter
Data Attributes
data-code
JS Globals
jQuery
FAQ

Frequently Asked Questions about Sticky Posts Dashboard Widget