WP Sticky Button – Click to Chat Security & Risk Analysis

wordpress.org/plugins/wa-sticky-button

Display the beautiful WhatsApp Sticky Button on the WordPress frontend.

10K active installs v1.4.1 PHP 5.6+ WP 4.5+ Updated Aug 14, 2025
button-for-frontendokapi-buttonwhatsapp-buttonwhatsapp-sticky-buttonwp-sticky-button
99
A · Safe
CVEs total2
Unpatched0
Last CVEAug 1, 2022
Safety Verdict

Is WP Sticky Button – Click to Chat Safe to Use in 2026?

Generally Safe

Score 99/100

WP Sticky Button – Click to Chat has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Aug 1, 2022Updated 7mo ago
Risk Assessment

The wa-sticky-button v1.4.1 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for SQL queries, avoiding file operations and external HTTP requests, and performing nonce and capability checks. The taint analysis also shows no critical or high-severity unsanitized flows, indicating a generally safe internal code structure.

However, significant concerns arise from the plugin's attack surface and historical vulnerability data. The presence of one AJAX handler without authentication checks presents a direct entry point for potential exploitation, which is a critical oversight. Furthermore, the plugin has a history of two known CVEs, including a high and a medium severity vulnerability, with the last one occurring in August 2022. The common vulnerability types found in its history, namely Missing Authorization and Cross-site Scripting, align with the observed unprotected AJAX handler, suggesting a pattern of insecure handling of user-supplied input and access control.

In conclusion, while the plugin has made some strides in secure coding practices such as prepared statements and output escaping, the unprotected AJAX endpoint and its historical vulnerability record are significant weaknesses. The lack of authorization on an entry point is a critical flaw that could be exploited. Users should exercise caution and consider the plugin's past issues when deciding to use it.

Key Concerns

  • AJAX handler without authentication
  • High severity vulnerability historically
  • Medium severity vulnerability historically
  • History of Missing Authorization vulnerabilities
  • History of Cross-site Scripting vulnerabilities
Vulnerabilities
2

WP Sticky Button – Click to Chat Security Vulnerabilities

CVEs by Year

2 CVEs in 2022
2022
Patched Has unpatched

Severity Breakdown

High
1
Medium
1

2 total CVEs

CVE-2022-2375medium · 6.3Missing Authorization

WP Sticky Button <= 1.4 - Missing Authorization to Arbitrary Settings Update

Aug 1, 2022 Patched in 1.4.1 (540d)
WF-c80e6f0b-ccca-4755-b64e-cfcebc5cc1fe-wa-sticky-buttonhigh · 7.2Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WP Sticky Button <= 1.3 - Unauthenticated Stored Cross-Site Scripting

Jul 26, 2022 Patched in 1.4.0 (546d)
Code Analysis
Analyzed Mar 16, 2026

WP Sticky Button – Click to Chat Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
12 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

86% escaped14 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<index> (index.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

WP Sticky Button – Click to Chat Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_okapi_wasb_save_settingsindex.php:53
WordPress Hooks 3
actionwp_footerindex.php:26
actionadmin_enqueue_scriptsindex.php:33
actionadmin_menuindex.php:37
Maintenance & Trust

WP Sticky Button – Click to Chat Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedAug 14, 2025
PHP min version5.6
Downloads74K

Community Trust

Rating68/100
Number of ratings5
Active installs10K
Developer Profile

WP Sticky Button – Click to Chat Developer Profile

farazify

2 plugins · 11K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
384 days
View full developer profile
Detection Fingerprints

How We Detect WP Sticky Button – Click to Chat

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
okapi-wasb-chat
FAQ

Frequently Asked Questions about WP Sticky Button – Click to Chat