Ultimate Sticky Popup & Widgets Security & Risk Analysis

wordpress.org/plugins/ultimate-sticky-popup-widgets

Ultimate Sticky Popup & Widgets is a simple, easy and fully-customizable WordPress plugin used to add popup on fixed position like bottom left, bo …

70 active installs v1.0.4 PHP 7.4+ WP 6.0+ Updated Apr 25, 2025
popuppopup-and-widgetssticky-popupsticky-popup-and-widgets
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Ultimate Sticky Popup & Widgets Safe to Use in 2026?

Generally Safe

Score 92/100

Ultimate Sticky Popup & Widgets has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "ultimate-sticky-popup-widgets" plugin v1.0.4 exhibits a generally strong security posture, with several key security best practices being followed. The absence of dangerous functions, file operations, and external HTTP requests is a significant positive. Furthermore, the fact that all SQL queries are prepared and a high percentage of output is properly escaped indicates a conscious effort to prevent common web vulnerabilities. The presence of nonce and capability checks, though minimal, is also a good sign. However, the analysis reveals a single shortcode as the sole entry point into the plugin. While there are no currently known CVEs or a history of vulnerabilities, the limited data available provides a small sample size. The plugin's security strength lies in its clean code signals and lack of historical issues, but a comprehensive assessment would benefit from more interaction data or a deeper dive into the shortcode's functionality to ensure it doesn't introduce subtle flaws.

Vulnerabilities
None known

Ultimate Sticky Popup & Widgets Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Ultimate Sticky Popup & Widgets Release Timeline

v1.0.3
v1.0.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

Ultimate Sticky Popup & Widgets Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
76 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

92% escaped83 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
uspaw_update_settings (admin\class-ultimate-sticky-popup-and-widgets-admin.php:137)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Ultimate Sticky Popup & Widgets Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[uspaw_social_share] public\class-ultimate-sticky-popup-and-widgets-public.php:258
WordPress Hooks 12
actionplugins_loadedincludes\class-ultimate-sticky-popup-and-widgets.php:144
actionadmin_enqueue_scriptsincludes\class-ultimate-sticky-popup-and-widgets.php:159
actionadmin_enqueue_scriptsincludes\class-ultimate-sticky-popup-and-widgets.php:160
actionadmin_menuincludes\class-ultimate-sticky-popup-and-widgets.php:162
actionadmin_post_save_uspaw_update_settingsincludes\class-ultimate-sticky-popup-and-widgets.php:163
actionwp_enqueue_scriptsincludes\class-ultimate-sticky-popup-and-widgets.php:179
actionwp_enqueue_scriptsincludes\class-ultimate-sticky-popup-and-widgets.php:180
actionwpincludes\class-ultimate-sticky-popup-and-widgets.php:181
actionwp_headincludes\class-ultimate-sticky-popup-and-widgets.php:185
filterwp_footerincludes\class-ultimate-sticky-popup-and-widgets.php:186
actionwp_footerincludes\class-ultimate-sticky-popup-and-widgets.php:187
actioninitincludes\class-ultimate-sticky-popup-and-widgets.php:190
Maintenance & Trust

Ultimate Sticky Popup & Widgets Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 25, 2025
PHP min version7.4
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs70
Developer Profile

Ultimate Sticky Popup & Widgets Developer Profile

IT Path Solutions

13 plugins · 11K total installs

80
trust score
Avg Security Score
89/100
Avg Patch Time
77 days
View full developer profile
Detection Fingerprints

How We Detect Ultimate Sticky Popup & Widgets

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ultimate-sticky-popup-widgets/admin/css/admin.css/wp-content/plugins/ultimate-sticky-popup-widgets/admin/js/admin.js/wp-content/plugins/ultimate-sticky-popup-widgets/admin/css/ultimate-sticky-popup-and-widgets-admin.css/wp-content/plugins/ultimate-sticky-popup-widgets/admin/js/ultimate-sticky-popup-and-widgets-admin.js
Version Parameters
ultimate-sticky-popup-and-widgets/admin/css/ultimate-sticky-popup-and-widgets-admin.css?ver=ultimate-sticky-popup-and-widgets/admin/js/ultimate-sticky-popup-and-widgets-admin.js?ver=ultimate-sticky-popup-and-widgets/admin/css/admin.css?ver=ultimate-sticky-popup-and-widgets/admin/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
uspaw_button_layout
Data Attributes
save_uspaw_popup
JS Globals
wp_color_picker
FAQ

Frequently Asked Questions about Ultimate Sticky Popup & Widgets