
Sticky Posts Expire Security & Risk Analysis
wordpress.org/plugins/sticky-posts-expireA simple plugin that allows you to set an expiration date on posts. Once a post is expired, it will no longer be sticky.
Is Sticky Posts Expire Safe to Use in 2026?
Generally Safe
Score 85/100Sticky Posts Expire has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "sticky-posts-expire" v1.0 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface. Furthermore, the code demonstrates good security practices by exclusively using prepared statements for SQL queries and implementing a nonce check and a capability check. This suggests a conscious effort by the developers to prevent common web vulnerabilities.
However, the static analysis does reveal a potential area of concern: output escaping. With 63% of outputs properly escaped out of a total of 8, there is a remaining 37% that might be unescaped. This could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is directly outputted without proper sanitization. The taint analysis showing zero flows with unsanitized paths is a positive indicator, suggesting that despite the imperfect escaping, no critical or high-severity taint flows were detected, which is a significant mitigating factor.
The plugin's vulnerability history is clean, with zero known CVEs. This, combined with the lack of detected vulnerabilities in the static analysis, indicates a stable and well-maintained codebase. While the imperfect output escaping is a weakness, the overall security profile is good due to the limited attack surface and the absence of exploitable vulnerabilities in the current version. Developers should prioritize addressing the remaining unescaped outputs to further strengthen the plugin's security.
Key Concerns
- Unescaped output detected
Sticky Posts Expire Security Vulnerabilities
Sticky Posts Expire Code Analysis
Output Escaping
Sticky Posts Expire Attack Surface
WordPress Hooks 10
Maintenance & Trust
Sticky Posts Expire Maintenance & Trust
Maintenance Signals
Community Trust
Sticky Posts Expire Alternatives
Ultimate Posts Widget
ultimate-posts-widget
The ultimate widget for displaying posts, custom post types or sticky posts with an array of options.
Expire Sticky Posts
expire-sticky-posts
A simple plugin that allows you to set an expiration date on posts. Once a post is expired, it will no longer be sticky.
Ultimate Sticky Posts Widget
ultimate-sticky-posts
This Widget works well to display sticky/posts or both.
WP Category Sticky Posts
category-sticky-posts
Allows you to set Sticky posts for individual category archives.
Post Glue
post-glue
Sticky posts for WordPress, improved.
Sticky Posts Expire Developer Profile
3 plugins · 130 total installs
How We Detect Sticky Posts Expire
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sticky-posts-expire/assets/css//wp-content/plugins/sticky-posts-expire/assets/js//wp-content/plugins/sticky-posts-expire/assets/js/mk-sticky-posts-expire.jssticky-posts-expire/sticky-posts-expire.php?ver=HTML / DOM Fingerprints
mk-sep-expiration-wrapMK Sticky Posts Expire Editor class.Here we are adding plugin final classSticky Posts Expire versionSticky Posts Expire text domain+15 moredata-idMK_SPE_OPTIONS