Atelier Scroll Top Security & Risk Analysis

wordpress.org/plugins/atelier-scroll-top

Atelier Scroll Top is a simple plugin that takes you to the very top of your site ...

0 active installs v1.4.3 PHP 7.4+ WP 5.8+ Updated Jun 15, 2025
link-to-topscrollscroll-to-topscroll-toptop
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Atelier Scroll Top Safe to Use in 2026?

Generally Safe

Score 100/100

Atelier Scroll Top has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9mo ago
Risk Assessment

The atelier-scroll-top plugin v1.4.3 exhibits a generally strong security posture with no known vulnerabilities or critical code signals. The absence of any recorded CVEs, along with the complete lack of SQL injection risks due to the use of prepared statements, is a significant positive. The plugin also demonstrates good practices by not performing file operations, making external HTTP requests, or bundling libraries, which are common sources of vulnerabilities.

However, the static analysis reveals areas for improvement. A significant concern is the low percentage of properly escaped output. With 44 total outputs and only 32% properly escaped, there's a substantial risk of cross-site scripting (XSS) vulnerabilities. While there are no specific taint flows identified, this high rate of unescaped output presents a potential avenue for attackers to inject malicious scripts. Furthermore, the complete absence of nonce checks and capability checks, especially if the plugin were to introduce any user-facing functionality or AJAX endpoints in the future, would be a critical oversight.

In conclusion, the plugin is currently safe from known external threats and common injection vulnerabilities. Its strengths lie in its minimal attack surface and secure database interactions. The primary weakness is the insufficient output escaping, which could lead to XSS if not addressed. The lack of nonces and capability checks indicates a potential for future security gaps if the plugin evolves. Overall, it's a relatively low-risk plugin, but the output escaping needs attention.

Key Concerns

  • Low percentage of properly escaped output
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Atelier Scroll Top Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Atelier Scroll Top Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
30
14 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

32% escaped44 total outputs
Attack Surface

Atelier Scroll Top Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionplugins_loadedinc\Scroll.php:22
actionadmin_menuinc\Scroll.php:25
actionadmin_enqueue_scriptsinc\Scroll.php:28
actionwp_enqueue_scriptsinc\Scroll.php:29
actionadmin_initinc\ScrollSettings.php:22
actionwp_footerinc\ScrollSettings.php:25
actionwp_headinc\scrollStyleCss.php:21
Maintenance & Trust

Atelier Scroll Top Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJun 15, 2025
PHP min version7.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Atelier Scroll Top Developer Profile

mariusz88atelierweb

3 plugins · 30 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Atelier Scroll Top

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/atelier-scroll-top/assets/scrolltop.css/wp-content/plugins/atelier-scroll-top/assets/fontello/css/fontello.css/wp-content/plugins/atelier-scroll-top/js/scrolltop.js/wp-content/plugins/atelier-scroll-top/custom-script.js/wp-content/plugins/atelier-scroll-top/assets/scrolltop.js
Script Paths
/wp-content/plugins/atelier-scroll-top/js/scrolltop.js/wp-content/plugins/atelier-scroll-top/custom-script.js/wp-content/plugins/atelier-scroll-top/assets/scrolltop.js

HTML / DOM Fingerprints

CSS Classes
atl-stt-logoatl-stt-titleadmin-wrapperatl-st-all-pagesatl_st_disabled_link
Data Attributes
name="atl_st_all_pages_enabled_api"id="atl_st_all_pages_enabled_api"
FAQ

Frequently Asked Questions about Atelier Scroll Top