
AR Back To Top Security & Risk Analysis
wordpress.org/plugins/ar-back-to-topAR Back To Top is a standard WordPress plugin for back to top.
Is AR Back To Top Safe to Use in 2026?
Generally Safe
Score 100/100AR Back To Top has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "ar-back-to-top" plugin v2.11.7 exhibits a generally strong security posture based on the provided static analysis. It demonstrates good practices by having no SQL queries that are not using prepared statements, no file operations, and no external HTTP requests. The absence of any known CVEs and a clean vulnerability history further contribute to its positive security profile. However, a potential concern is the presence of a dangerous function (preg_replace with the 'e' modifier), which, if not carefully handled, can lead to remote code execution vulnerabilities. While taint analysis did not reveal any exploitable flows, this specific function warrants attention.
The plugin's attack surface is impressively small, with no direct entry points like AJAX handlers, REST API routes, shortcodes, or cron events that are exposed without authentication or proper permission checks. This significantly limits the opportunities for attackers to interact with the plugin in unintended ways. Despite the lack of explicit nonce checks reported, the overall limited attack surface and the presence of at least one capability check suggest a thoughtful approach to security by the developers. The high percentage of properly escaped output is also a positive indicator, minimizing the risk of cross-site scripting (XSS) vulnerabilities.
Key Concerns
- Dangerous function found (preg_replace(/e))
- No nonce checks reported
AR Back To Top Security Vulnerabilities
AR Back To Top Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
AR Back To Top Attack Surface
WordPress Hooks 14
Maintenance & Trust
AR Back To Top Maintenance & Trust
Maintenance Signals
Community Trust
AR Back To Top Alternatives
WPFront Scroll Top
wpfront-scroll-top
Adds a lightweight and smooth "Scroll to Top" button to your WordPress site, improving navigation and user experience with customizable options.
Flexible Scroll Top
flexible-scroll-top
Add a slick, lightweight and customizable scroll to top button that uses SVG icon with no jQuery dependency.
MM Scroll To Top
tap-to-top
Tap the button and scroll to top immediately.
Scroll to top button
wp-scroll-2
Scroll to top button plugin is an simple and nice plugin with the standard settings.
BH Scroll Top
bh-scroll-top
This plugin will add a scroll top feature in your site.
AR Back To Top Developer Profile
1 plugin · 20 total installs
How We Detect AR Back To Top
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ar-back-to-top/assets/css/style.css/wp-content/plugins/ar-back-to-top/assets/js/script.jsar-back-to-top/style.css?ver=ar-back-to-top/script.js?ver=HTML / DOM Fingerprints
ar-btt-wraparbtt-header-actionsdata-arbtt-settingsarbtt_options