
Ax ScrollTo Top Security & Risk Analysis
wordpress.org/plugins/ax-scrollto-topAdd a Scroll to top button in the website footer.
Is Ax ScrollTo Top Safe to Use in 2026?
Generally Safe
Score 85/100Ax ScrollTo Top has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'ax-scrollto-top' plugin v1.0.0 exhibits a generally good security posture based on the provided static analysis and vulnerability history. The complete absence of entry points like AJAX handlers, REST API routes, shortcodes, and cron events significantly reduces the potential attack surface. Furthermore, the plugin utilizes prepared statements for all SQL queries, which is a strong defense against SQL injection vulnerabilities. The lack of file operations and external HTTP requests also mitigates common attack vectors.
However, a significant concern arises from the static analysis indicating that 0% of the 34 total outputs are properly escaped. This suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected and executed within the WordPress site, potentially impacting users and administrators. While the plugin has no recorded CVEs or historical vulnerabilities, this positive track record cannot compensate for the identified output escaping deficiency, which is a critical weakness. The absence of nonce checks on potential entry points (though there are none listed) and the limited capability checks (only 1) could also become issues if new entry points were to be added without proper security measures.
In conclusion, while the plugin has a low attack surface and good practices regarding SQL and external requests, the lack of output escaping presents a critical security flaw that requires immediate attention. The absence of historical vulnerabilities is positive but does not negate the risk posed by the identified XSS vulnerability. The plugin's strength lies in its limited functionality and attack surface, but its weakness is a direct and significant risk to site security.
Key Concerns
- 0% of outputs properly escaped
Ax ScrollTo Top Security Vulnerabilities
Ax ScrollTo Top Code Analysis
Output Escaping
Ax ScrollTo Top Attack Surface
WordPress Hooks 5
Maintenance & Trust
Ax ScrollTo Top Maintenance & Trust
Maintenance Signals
Community Trust
Ax ScrollTo Top Alternatives
Cudazi Scroll to Top
cudazi-scroll-to-top
Adds a smooth scroll to top feature/link in the lower-right corner of long pages.
Top Scroller
top-scroller
Top Scroller plugin allows the visitor to easily and safely scroll back to the top of the page.
WP-Smooth-Scroll
wp-smooth-scroll
WP-Smooth-Scroll is a plugin that helps users to scroll smoothly to top of the page.
Scroll To Top or Bottom
scroll-to-top-or-bottom
Easy to use scroll to top and bottom plugin.
Scroll to Top
mdc-scroll-to-top
Scroll to Top button for your WordPress site.
Ax ScrollTo Top Developer Profile
2 plugins · 400 total installs
How We Detect Ax ScrollTo Top
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ax-scrollto-top/ax-scrollto-top-css.php/wp-content/plugins/ax-scrollto-top/ax-scrollto-top.css/wp-content/plugins/ax-scrollto-top/js/ax-scrollto-top.jsax-scrollto-top/js/ax-scrollto-top.js?ver=ax-scrollto-top-css.php?ver=ax-scrollto-top.css?ver=HTML / DOM Fingerprints
axScrollToTopid="axScrollTo"