
Sticky Posts – Switch Security & Risk Analysis
wordpress.org/plugins/sticky-posts-switchThis plugin adds a sticky post switch functionality to the admin list post/custom post type pages.
Is Sticky Posts – Switch Safe to Use in 2026?
Generally Safe
Score 85/100Sticky Posts – Switch has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "sticky-posts-switch" v2.1.3 exhibits a generally strong security posture based on the provided static analysis. The absence of known CVEs, raw SQL queries, file operations, and external HTTP requests are positive indicators. The presence of capability checks and nonces on its single AJAX handler suggests a good understanding of WordPress security best practices for entry points. However, a significant concern is the low percentage of properly escaped output (27%). This indicates a potential risk for Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data or dynamic content could be rendered without proper sanitization, allowing attackers to inject malicious scripts into the user's browser.
While taint analysis shows no current issues, the limited output escaping is a weakness that could be exploited. The vulnerability history being clean is reassuring, but it doesn't negate the risks identified in the code analysis. In conclusion, the plugin is well-designed in terms of core security features like authentication and SQL handling. The primary area for improvement and the main security risk lies in the insufficient output escaping, which could lead to XSS vulnerabilities if not addressed.
Key Concerns
- Low output escaping percentage
Sticky Posts – Switch Security Vulnerabilities
Sticky Posts – Switch Code Analysis
Output Escaping
Sticky Posts – Switch Attack Surface
AJAX Handlers 1
WordPress Hooks 12
Maintenance & Trust
Sticky Posts – Switch Maintenance & Trust
Maintenance Signals
Community Trust
Sticky Posts – Switch Alternatives
Brozzme Switch and Duplicate
brozzme-switch-duplicate
A set of tools dedicated to post type, Post-type Switcher and Post Duplicate (works with any custom post-type).
Custom Post Type Sticky
custom-post-type-sticky
Extends sticky post functionality to custom post types in a way that is identical to default posts.
AStickyPostOrderER Show Sticky
astickypostorderer-show-sticky
Adds a new column to the posts table in the admin to display if a post is sticky or not.
Better WP-Admin Search
better-wp-admin-search
Add essential search functionality to your WP Admin.
CPT Toggle – Disable Custom Post Types
cpt-toggle-disable-custom-post-types
Enable or disable any post type. Tabs group post types by source (Core, theme, plugin) for a tidy WordPress admin.
Sticky Posts – Switch Developer Profile
3 plugins · 10K total installs
How We Detect Sticky Posts – Switch
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sticky-posts-switch/assets/css/admin-sticky-posts.css/wp-content/plugins/sticky-posts-switch/assets/jquery/jquery.ajaxQueue.min.js/wp-content/plugins/sticky-posts-switch/assets/js/admin-sticky-posts.js/wp-content/plugins/sticky-posts-switch/assets/js/admin-quick-edit.js/wp-content/plugins/sticky-posts-switch/assets/js/admin-sticky-posts.js/wp-content/plugins/sticky-posts-switch/assets/js/admin-quick-edit.jssticky-posts-switch/assets/css/admin-sticky-posts.css?ver=sticky-posts-switch/assets/jquery/jquery.ajaxQueue.min.js?ver=sticky-posts-switch/assets/js/admin-sticky-posts.js?ver=sticky-posts-switch/assets/js/admin-quick-edit.js?ver=HTML / DOM Fingerprints
dashicons-sticky<!-- Sticky Post Switch -->data-original-sticky-valuestickyPostObject