Stomp Security & Risk Analysis

wordpress.org/plugins/stomp

Stomps the footer element to the bottom of the visible page on short pages.

80 active installs v1.0.1 PHP + WP 4.5+ Updated Jun 23, 2025
contentfixfootershortstatic
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Stomp Safe to Use in 2026?

Generally Safe

Score 100/100

Stomp has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9mo ago
Risk Assessment

The "stomp" plugin version 1.0.1 presents a surprisingly secure initial posture based on the static analysis. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits its attack surface. Furthermore, the code analysis reveals no dangerous functions, SQL queries utilizing prepared statements, file operations, external HTTP requests, or bundled libraries, all of which are positive indicators. The vulnerability history is also clear, with zero recorded CVEs, suggesting a consistent track record of security. However, the analysis does highlight a critical weakness: 100% of outputs are not properly escaped. This means any data rendered to the user could potentially be exploited through cross-site scripting (XSS) attacks, even if other entry points are secured. While the plugin appears robust in its input handling and lack of known vulnerabilities, this unescaped output represents a tangible and potentially exploitable risk that needs immediate attention.

Key Concerns

  • Output is not properly escaped
Vulnerabilities
None known

Stomp Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Stomp Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

Stomp Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
filterplugin_row_metastomp.php:82
actionwp_footerstomp.php:100
Maintenance & Trust

Stomp Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJun 23, 2025
PHP min version
Downloads4K

Community Trust

Rating80/100
Number of ratings2
Active installs80
Developer Profile

Stomp Developer Profile

cubecolour

17 plugins · 21K total installs

99
trust score
Avg Security Score
99/100
Avg Patch Time
7 days
View full developer profile
Detection Fingerprints

How We Detect Stomp

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
stomp
FAQ

Frequently Asked Questions about Stomp