
Stomp Security & Risk Analysis
wordpress.org/plugins/stompStomps the footer element to the bottom of the visible page on short pages.
Is Stomp Safe to Use in 2026?
Generally Safe
Score 100/100Stomp has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "stomp" plugin version 1.0.1 presents a surprisingly secure initial posture based on the static analysis. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits its attack surface. Furthermore, the code analysis reveals no dangerous functions, SQL queries utilizing prepared statements, file operations, external HTTP requests, or bundled libraries, all of which are positive indicators. The vulnerability history is also clear, with zero recorded CVEs, suggesting a consistent track record of security. However, the analysis does highlight a critical weakness: 100% of outputs are not properly escaped. This means any data rendered to the user could potentially be exploited through cross-site scripting (XSS) attacks, even if other entry points are secured. While the plugin appears robust in its input handling and lack of known vulnerabilities, this unescaped output represents a tangible and potentially exploitable risk that needs immediate attention.
Key Concerns
- Output is not properly escaped
Stomp Security Vulnerabilities
Stomp Code Analysis
Output Escaping
Stomp Attack Surface
WordPress Hooks 2
Maintenance & Trust
Stomp Maintenance & Trust
Maintenance Signals
Community Trust
Stomp Alternatives
Content Blocks (Custom Post Widget)
custom-post-widget
This plugin enables you to edit and display Content Blocks in a sidebar widget or using a shortcode.
MAS Static Content
mas-static-content
MAS Static Content is a free plugin that allows you to to create a custom post type static content and use it with shortcode.
Blog Floating Button
blog-floating-button
Blog Floating Button(BFB)は、ブログにフロートボタンを簡単に実装できるプラグインです。フロートボタンでキラーページに簡単に誘導することができるため、商品購入数や問い合わせ数の向上が期待できます。
Advanced Floating Content Lite
advanced-floating-content-lite
Create high-impact floating content that stays visible without annoying visitors. Perfect for announcements, CTAs, and promotions.
Dynamic Month & Year into Posts
dynamic-month-year-into-posts
Automate SEO and content with dynamic shortcodes for dates, years, months, age calculations, seasons and countdowns in content, titles and meta.
Stomp Developer Profile
17 plugins · 21K total installs
How We Detect Stomp
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
stomp