AS Scroll to top Security & Risk Analysis

wordpress.org/plugins/as-scroll-to-top

This plugin will add a nice scroll to top button to your website. It has a nice option panel. you can change button's color button's icon.

10 active installs v1.0 PHP + WP 3.0.1+ Updated Jun 16, 2014
color-full-buttonscustom-cssjquerynice-iconsscroll-to-top
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is AS Scroll to top Safe to Use in 2026?

Generally Safe

Score 85/100

AS Scroll to top has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The "as-scroll-to-top" v1.0 plugin exhibits a generally good security posture from a static analysis perspective, with no identified dangerous functions, SQL queries using prepared statements, file operations, or external HTTP requests. The attack surface is also zero, meaning there are no direct entry points like AJAX handlers, REST API routes, or shortcodes that could be exploited. This indicates careful development in terms of direct code vulnerabilities.

However, a significant concern arises from the "Output escaping" metric, where 100% of the 5 total outputs are not properly escaped. This leaves the plugin vulnerable to Cross-Site Scripting (XSS) attacks. If any user-provided data is displayed without proper sanitization, an attacker could inject malicious scripts into the site, leading to session hijacking, credential theft, or defacement.

The vulnerability history is clean, with no known CVEs or past issues. This, combined with the limited attack surface and prepared SQL statements, suggests a low likelihood of historical exploitable flaws. Despite the lack of critical taint flows and dangerous functions, the unescaped output remains a notable weakness. While the plugin has strengths in avoiding common pitfalls, the unescaped output presents a clear and present risk that needs to be addressed.

Key Concerns

  • Unescaped output
Vulnerabilities
None known

AS Scroll to top Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

AS Scroll to top Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped5 total outputs
Attack Surface

AS Scroll to top Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionwp_enqueue_scriptsplugin-hook.php:20
actionwp_headplugin-hook.php:46
actionwp_footerplugin-hook.php:88
actionadmin_menuplugin-hook.php:165
actionadmin_initplugin-hook.php:171
Maintenance & Trust

AS Scroll to top Maintenance & Trust

Maintenance Signals

WordPress version tested3.9.40
Last updatedJun 16, 2014
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings3
Active installs10
Developer Profile

AS Scroll to top Developer Profile

ashikur11

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect AS Scroll to top

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/as-scroll-to-top/css/font-awesome.min.css

HTML / DOM Fingerprints

CSS Classes
scrollToTopfafa-angle-up
Data Attributes
name='as_plug_options[as_plug_custom_css]'name='as_plug_options[as_plug_button_icon]'
JS Globals
jQuery
FAQ

Frequently Asked Questions about AS Scroll to top