
Sticky Side Buttons Security & Risk Analysis
wordpress.org/plugins/sticky-side-buttonsFlexible button creator allowing you to stick floating buttons to the side of your site.
Is Sticky Side Buttons Safe to Use in 2026?
Generally Safe
Score 99/100Sticky Side Buttons has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of sticky-side-buttons v2.0.3 reveals a generally strong security posture with excellent adherence to several best practices. The absence of any detected dangerous functions, file operations, or external HTTP requests is highly positive. Furthermore, all SQL queries are properly prepared, and all detected outputs are correctly escaped, significantly mitigating common vulnerabilities like SQL injection and Cross-Site Scripting (XSS) originating from within the analyzed code paths. The limited attack surface with zero entry points that lack authentication checks is also a commendable aspect. However, the presence of two capability checks without any identified nonce checks or explicit authentication controls on potential entry points (even though there are none reported) warrants careful consideration. This suggests that while the code might be clean, the framework around it might rely on other security mechanisms for protection, which could be a point of weakness if those mechanisms are misconfigured or bypassed.
The vulnerability history shows a past medium severity vulnerability, specifically an XSS issue, which was patched. The fact that there are no currently unpatched CVEs is reassuring. However, the past occurrence of XSS, even if medium and patched, indicates that the plugin is not entirely immune to such issues, and ongoing vigilance is necessary. The complete absence of taint analysis findings is positive, suggesting no unsanitized paths were identified in the flows that were analyzed. Overall, the plugin demonstrates good coding hygiene in its current version, but the historical vulnerability and the presence of capability checks without clear nonce implementation on potential (though currently non-existent) entry points suggest a minor area for review, especially concerning the overall defense-in-depth strategy.
Key Concerns
- Past medium severity XSS vulnerability
- Capability checks present, but no nonce checks indicated
Sticky Side Buttons Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Sticky Side Buttons < 2.0.0 - Authenticated (Administrator+) Stored Cross-Site Scripting
Sticky Side Buttons Code Analysis
Output Escaping
Sticky Side Buttons Attack Surface
WordPress Hooks 9
Maintenance & Trust
Sticky Side Buttons Maintenance & Trust
Maintenance Signals
Community Trust
Sticky Side Buttons Alternatives
LiveChapter Sticky Side CTA
livechapter-sticky-side-cta
Create stunning sticky side tab buttons with call-to-action features by LiveChapter. Perfect for contact, social media, and conversion buttons.
Sticky Floating Button (Book Now, Contact, Call To Action…)
sticky-button
The button can be centered at the bottom of the page or placed on the left/right sides. Display the button on the entire website or on specific pages.
Sticky Mobile Buttons
sticky-mobile-buttons
Adds customizable sticky buttons on mobile for quick contact and cart access. Boost Your Mobile Conversions with Floating Action Buttons!
HansAndFriends Sticky Contact Sidebar
hansandfriends-sticky-contact-sidebar
Adds a configurable sticky contact sidebar with editable links, maps, colors, and Google Fonts support.
SticklyUI
sticklyui
Create customizable floating service buttons, a sticky header, and a dedicated contact button with a popup form for your WordPress site.
Sticky Side Buttons Developer Profile
6 plugins · 11K total installs
How We Detect Sticky Side Buttons
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sticky-side-buttons/assets/css/ssb-admin-style.css/wp-content/plugins/sticky-side-buttons/assets/css/fontawesome-iconpicker.css/wp-content/plugins/sticky-side-buttons/assets/js/fontawesome-iconpicker.js/wp-content/plugins/sticky-side-buttons/assets/js/ssb-admin-js.js/wp-content/plugins/sticky-side-buttons/assets/css/ssb-ui-style.css/wp-content/plugins/sticky-side-buttons/assets/js/ssb-ui-js.js/wp-content/plugins/sticky-side-buttons/assets/css/ssb-admin-style.css?ver=/wp-content/plugins/sticky-side-buttons/assets/css/fontawesome-iconpicker.css?ver=/wp-content/plugins/sticky-side-buttons/assets/js/fontawesome-iconpicker.js?ver=/wp-content/plugins/sticky-side-buttons/assets/js/ssb-admin-js.js?ver=/wp-content/plugins/sticky-side-buttons/assets/css/ssb-ui-style.css?ver=/wp-content/plugins/sticky-side-buttons/assets/js/ssb-ui-js.js?ver=HTML / DOM Fingerprints
ssb-icon-button<!-- Sticky Side Buttons -->data-ssb-iddata-ssb-configssb_ui_data