
Themeable Sticky Posts Security & Risk Analysis
wordpress.org/plugins/themeable-sticky-postsA widget to display featured sticky posts. The built-in template displays a simple list of links, or you can create a template file in your theme for …
Is Themeable Sticky Posts Safe to Use in 2026?
Generally Safe
Score 85/100Themeable Sticky Posts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "themeable-sticky-posts" v1.0 plugin presents a mixed security posture. On the positive side, the plugin has no recorded vulnerabilities in its history, and the static analysis shows a lack of direct attack surface through AJAX, REST API, shortcodes, or cron events. Furthermore, all SQL queries are properly prepared, and there are no file operations or external HTTP requests, which are common vectors for exploitation.
However, significant concerns are raised by the code signals. The presence of the `create_function` PHP construct is a major red flag, as it is deprecated and can be a source of security vulnerabilities, particularly if user input is involved in its creation, though taint analysis did not reveal any immediate flows. A more concerning finding is the extremely low percentage of properly escaped output (8%). This indicates a high likelihood of Cross-Site Scripting (XSS) vulnerabilities, where untrusted data displayed in the WordPress admin or frontend could be manipulated to execute malicious scripts.
Given the absence of documented vulnerabilities and the secure handling of SQL and network operations, the plugin appears to have a foundational level of security. Nevertheless, the poor output escaping and the use of `create_function` represent critical weaknesses that could be exploited. The lack of any documented vulnerabilities in its history might suggest either a very limited user base, diligent security practices in its development that were not fully reflected in the code analysis, or simply a lack of targeted discovery of its weaknesses. The primary actionable concern is the output escaping, which requires immediate attention to prevent potential XSS attacks.
Key Concerns
- Poor output escaping (8% proper)
- Use of dangerous function: create_function
- Missing nonce checks
- Missing capability checks
Themeable Sticky Posts Security Vulnerabilities
Themeable Sticky Posts Code Analysis
Dangerous Functions Found
Output Escaping
Themeable Sticky Posts Attack Surface
WordPress Hooks 1
Maintenance & Trust
Themeable Sticky Posts Maintenance & Trust
Maintenance Signals
Community Trust
Themeable Sticky Posts Alternatives
Ultimate Posts Widget
ultimate-posts-widget
The ultimate widget for displaying posts, custom post types or sticky posts with an array of options.
Daddy Plus
daddy-plus
Daddy Plus is a useful plugin for WordPress theme by Themes Daddy.
WPFrank Companion
wpfrank-companion
WPFrank Companion is a companion plugin for WP Frank themes.
Avantex Companion
avantex-companion
tested up to 6.8 License: GPLv3 or later License URI: http://www.gnu.org/licenses/gpl-3.0.html Avantex Companion is a companion plugin for Avantex the …
Widget Box Lite
widget-box-lite
A toolbox of great widgets for your daily blogging. Display recent posts, social links, and much more. Designed for Theme4Press themes
Themeable Sticky Posts Developer Profile
16 plugins · 21K total installs
How We Detect Themeable Sticky Posts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/themeable-sticky-posts/widget.css/wp-content/plugins/themeable-sticky-posts/widget.js/wp-content/plugins/themeable-sticky-posts/widget.jsthemeable-sticky-posts/widget.css?ver=themeable-sticky-posts/widget.js?ver=HTML / DOM Fingerprints
widget_themeable_sticky_postsid="themeable-sticky-posts-admin-panel"