
Tag Sticky Post Security & Risk Analysis
wordpress.org/plugins/tag-sticky-postMark a post to be placed at the top of a specified tag archive. It's sticky posts specifically for tags.
Is Tag Sticky Post Safe to Use in 2026?
Generally Safe
Score 85/100Tag Sticky Post has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'tag-sticky-post' plugin v2.4.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices in several areas. There are no recorded vulnerabilities (CVEs), no dangerous functions identified, and SQL queries are exclusively using prepared statements, which is excellent. File operations are present but not flagged as problematic, and there are no external HTTP requests. A nonce check is implemented, suggesting some awareness of common attack vectors.
However, significant concerns arise from the attack surface analysis. The plugin exposes a single AJAX handler without any authentication or capability checks. This represents a critical entry point that an attacker could potentially exploit to trigger unintended actions or gain unauthorized access. While no critical taint flows were found, the lack of proper output escaping on 50% of identified outputs is also a notable weakness. The absence of capability checks on the AJAX handler further amplifies the risk associated with this unprotected entry point.
Given the clean vulnerability history, the plugin appears to have been developed with security in mind, or has been fortunate to avoid discovery. Nevertheless, the identified unprotected AJAX handler is a serious flaw that requires immediate attention. The plugin's strengths lie in its SQL handling and lack of historical vulnerabilities, but its single unprotected entry point presents a substantial risk that overshadows these positives.
Key Concerns
- AJAX handler without authentication
- 50% of outputs not properly escaped
- AJAX handler without capability checks
Tag Sticky Post Security Vulnerabilities
Tag Sticky Post Code Analysis
Output Escaping
Tag Sticky Post Attack Surface
AJAX Handlers 1
WordPress Hooks 6
Maintenance & Trust
Tag Sticky Post Maintenance & Trust
Maintenance Signals
Community Trust
Tag Sticky Post Alternatives
VK All in One Expansion Unit
vk-all-in-one-expansion-unit
This plug-in is an integrated plug-in with a variety of features that make it powerful your web site.
Essential Widgets
essential-widgets
Essential Widgets is a WordPress plugin for widgets that allows you to create and add amazing widgets with high customization option
Flexible Posts Widget
flexible-posts-widget
An advanced posts display widget with many options. Display posts in your sidebars any way you'd like!
SEO Auto Linker
wpa-seo-auto-linker
SEO Auto Linker assists in creating cornerstone SEO content. This is not a full replacement for SEO plugins.
Automatic Post Tagger
automatic-post-tagger
Adds relevant taxonomy terms to posts using a keyword list provided by the user.
Tag Sticky Post Developer Profile
6 plugins · 6K total installs
How We Detect Tag Sticky Post
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tag-sticky-post/css/admin.css/wp-content/plugins/tag-sticky-post/css/plugin.css/wp-content/plugins/tag-sticky-post/js/editor.min.js/wp-content/plugins/tag-sticky-post/js/admin.min.js/wp-content/plugins/tag-sticky-post/js/editor.min.js/wp-content/plugins/tag-sticky-post/js/admin.min.jstag-sticky-post/css/admin.css?ver=tag-sticky-post/css/plugin.css?ver=tag-sticky-post/js/editor.min.js?ver=tag-sticky-post/js/admin.min.js?ver=HTML / DOM Fingerprints
tag-sticky-post<!-- Tag Sticky Post -->tag_sticky_postpost_is_tag_stickytag_sticky_post