
WP Sticky Social Security & Risk Analysis
wordpress.org/plugins/wp-sticky-socialPlugin display sticky bar with icons and links your socials profiles.
Is WP Sticky Social Safe to Use in 2026?
Generally Safe
Score 85/100WP Sticky Social has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The wp-sticky-social plugin v1.0.2 exhibits a mixed security posture. On the positive side, the static analysis reveals no critical code signals like dangerous functions, file operations, or external HTTP requests. SQL queries are all prepared, and there is a single nonce check present, indicating some awareness of security practices. The absence of a large attack surface via AJAX, REST API, or shortcodes is also a strength.
However, a significant concern arises from the vulnerability history. The plugin has one known medium-severity CVE, and while currently unpatched, the fact that it's a past vulnerability (dated 2023-06-19) suggests it might have been addressed in later versions or is no longer actively exploited. The previous vulnerability being CSRF is noteworthy. A more pressing concern from the static analysis is the low rate of output escaping (34%), which could leave the plugin susceptible to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is outputted without proper sanitization.
In conclusion, while the plugin avoids many common pitfalls like raw SQL or large attack surfaces, the low output escaping rate and the history of a CVE are areas requiring attention. Developers should prioritize addressing the output escaping to mitigate potential XSS risks. The plugin's strengths lie in its limited attack surface and secure handling of database operations.
Key Concerns
- Low output escaping rate (34%)
- Past medium severity CVE (CSRF)
WP Sticky Social Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WP Sticky Social <= 1.0.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting
WP Sticky Social Release Timeline
WP Sticky Social Code Analysis
SQL Query Safety
Output Escaping
WP Sticky Social Attack Surface
WordPress Hooks 10
Maintenance & Trust
WP Sticky Social Maintenance & Trust
Maintenance Signals
Community Trust
WP Sticky Social Alternatives
Social Icons Widget & Block – Social Media Icons & Share Buttons
social-icons-widget-by-wpzoom
Social media icons plugin for WordPress - Add 400+ social icons and share buttons. Gutenberg block, widget & Elementor support. GDPR compliant.
Simple Author Box
simple-author-box
Add a responsive author box or guest author box with social icons to any post. Great author box for any site!
Lightweight Social Icons
lightweight-social-icons
Looking to add simple social icons to your widget areas? Choose the size and color of your icons, and then choose from 47 different social profiles.
Easy Social Icons
easy-social-icons
Upload your own social media icons or choose from font-awesome. Use widget|shortcode to place icons anywhere(sidebar, header, footer, page) in theme.
Fuse Social Floating Sidebar
fuse-social-floating-sidebar
This plugin allows you to add social media floating sidebar icons connected with your social media profiles.
WP Sticky Social Developer Profile
2 plugins · 110 total installs
How We Detect WP Sticky Social
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-sticky-social/assets/css/public.css/wp-content/plugins/wp-sticky-social/assets/js/public.js/wp-content/plugins/wp-sticky-social/assets/css/admin.css/wp-content/plugins/wp-sticky-social/assets/js/admin.js/wp-content/plugins/wp-sticky-social/assets/js/public.js/wp-content/plugins/wp-sticky-social/assets/js/admin.jswp-sticky-social/assets/css/public.css?ver=wp-sticky-social/assets/js/public.js?ver=wp-sticky-social/assets/css/admin.css?ver=wp-sticky-social/assets/js/admin.js?ver=HTML / DOM Fingerprints
wp-sticky-social-wrapperwp-sticky-social-contentwp-sticky-social-listwp-sticky-social-itemwp-sticky-social-iconWP_Sticky_Social