Anchor smooth scroll Security & Risk Analysis

wordpress.org/plugins/anchor-smooth-scroll

Аdds a smooth scroll to the anchors.

100 active installs v1.0.2 PHP 5.6+ WP 4.8+ Updated May 31, 2019
%d0%b0nchorlightweightscrollscroll-by-idsmooth-scroll
61
C · Use Caution
CVEs total1
Unpatched1
Last CVEJul 29, 2025
Safety Verdict

Is Anchor smooth scroll Safe to Use in 2026?

Use With Caution

Score 61/100

Anchor smooth scroll has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Jul 29, 2025Updated 6yr ago
Risk Assessment

The "anchor-smooth-scroll" plugin v1.0.2 exhibits a mixed security posture. On the positive side, the static analysis reveals no dangerous functions, all SQL queries utilize prepared statements, and there are no file operations or external HTTP requests. The attack surface is minimal, with only one shortcode and no AJAX or REST API entry points that are exposed without authentication. Taint analysis also shows no critical or high severity flows. However, the plugin has a history of vulnerabilities, specifically a high-severity "PHP Remote File Inclusion" issue. The fact that a known vulnerability remains unpatched in this version is a significant concern, despite the generally good coding practices observed in other areas. The presence of a known, high-severity, unpatched vulnerability heavily outweighs the positive aspects of the static code analysis, indicating a critical need for an update or remediation.

Key Concerns

  • Unpatched high severity CVE
  • Inconsistent output escaping
  • Bundled outdated library (TinyMCE)
Vulnerabilities
1 published

Anchor smooth scroll Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

High
1

1 total CVE

CVE-2025-60072high · 8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

Anchor smooth scroll <= 1.0.2 - Unauthenticated Local File Inclusion

Jul 29, 2025Unpatched
Version History

Anchor smooth scroll Release Timeline

v1.0.2Current1 CVE
Code Analysis
Analyzed Mar 16, 2026

Anchor smooth scroll Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
7 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

TinyMCE

Output Escaping

64% escaped11 total outputs
Attack Surface

Anchor smooth scroll Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[anchor] src\Frontend\Frontend.php:66
WordPress Hooks 11
actionadmin_enqueue_scriptssrc\Admin\Admin.php:48
actionadmin_menusrc\Admin\Admin.php:49
actionadmin_initsrc\Admin\Admin.php:50
actionadmin_enqueue_scriptssrc\Admin\Admin.php:52
filtermce_external_pluginssrc\Admin\Admin.php:53
filtermce_buttonssrc\Admin\Admin.php:54
filtermce_external_languagessrc\Admin\Admin.php:55
actionwp_enqueue_scriptssrc\Frontend\Frontend.php:57
filterwp_nav_menu_argssrc\Frontend\Frontend.php:58
actioninitsrc\Frontend\Frontend.php:59
actionplugins_loadedsrc\SmoothScrollPlugin.php:34
Maintenance & Trust

Anchor smooth scroll Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedMay 31, 2019
PHP min version5.6
Downloads5K

Community Trust

Rating100/100
Number of ratings1
Active installs100
Developer Profile

Anchor smooth scroll Developer Profile

Processby

8 plugins · 21K total installs

77
trust score
Avg Security Score
76/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Anchor smooth scroll

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/anchor-smooth-scroll/admin/css/admin-style.css/wp-content/plugins/anchor-smooth-scroll/admin/js/anchor-tinymce-button.js/wp-content/plugins/anchor-smooth-scroll/frontend/js/xpage_anchor_refactor1.js
Script Paths
/wp-content/plugins/anchor-smooth-scroll/admin/js/anchor-tinymce-button.js/wp-content/plugins/anchor-smooth-scroll/frontend/js/xpage_anchor_refactor1.js
Version Parameters
anchor-smooth-scroll/admin/css/admin-style.css?ver=anchor-smooth-scroll/admin/js/anchor-tinymce-button.js?ver=anchor-smooth-scroll/frontend/js/xpage_anchor_refactor1.js?ver=

HTML / DOM Fingerprints

CSS Classes
smooth-scroll-menu
JS Globals
window.xspage_anchor_plugin_options
Shortcode Output
[anchor[/anchor]
FAQ

Frequently Asked Questions about Anchor smooth scroll