Back to the Top Security & Risk Analysis

wordpress.org/plugins/back-to-the-top

Back to the Top is a WordPress plugin that return to scroll smoothly to the top of the page. You can scroll to the smooth anchor link in the page.

100 active installs v1.2.1 PHP 5.6+ WP 4.9+ Updated Aug 22, 2024
back-to-the-topscroll-topto-top
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Back to the Top Safe to Use in 2026?

Generally Safe

Score 92/100

Back to the Top has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The 'back-to-the-top' plugin v1.2.1 exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of dangerous functions, file operations, external HTTP requests, and raw SQL queries is commendable. The high percentage of properly escaped output further reinforces this positive assessment, minimizing the risk of cross-site scripting vulnerabilities. Furthermore, the complete lack of recorded CVEs and vulnerability history suggests a history of secure development or diligent patching by the developers.

While the attack surface appears minimal with zero AJAX handlers, REST API routes, shortcodes, or cron events, a notable concern is the complete absence of nonce checks and capability checks. This indicates that even if entry points were to be discovered or introduced in future versions, they might not be adequately protected against CSRF or unauthorized access. However, given the current static analysis showing zero entry points, this remains a hypothetical concern for the current version. The taint analysis also reports no issues, which is a very positive sign.

In conclusion, the 'back-to-the-top' plugin v1.2.1 appears to be a secure plugin with no immediate exploitable vulnerabilities identified in the static analysis or vulnerability history. The developers have followed good practices regarding SQL queries and output escaping. The only potential area for improvement lies in incorporating nonce and capability checks as a proactive security measure, even in the absence of apparent entry points.

Key Concerns

  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Back to the Top Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Back to the Top Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
50 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

94% escaped53 total outputs
Attack Surface

Back to the Top Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionplugins_loadedinc\class-back-to-the-top.php:44
actionplugins_loadedinc\class-back-to-the-top.php:45
actionadmin_initinc\class-back-to-the-top.php:47
actionadmin_menuinc\class-back-to-the-top.php:48
actionwp_enqueue_scriptsinc\class-back-to-the-top.php:61
actionwp_enqueue_scriptsinc\class-back-to-the-top.php:62
actionwp_footerinc\class-back-to-the-top.php:63
filterplugin_row_metainc\class-back-to-the-top.php:67
actionadmin_enqueue_scriptsinc\class-back-to-the-top.php:111
actionadmin_enqueue_scriptsinc\class-back-to-the-top.php:112
Maintenance & Trust

Back to the Top Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedAug 22, 2024
PHP min version5.6
Downloads9K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

Back to the Top Developer Profile

thingsym

11 plugins · 39K total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Back to the Top

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/back-to-the-top/backtothetop.admin.js/wp-content/plugins/back-to-the-top/backtothetop.js/wp-content/plugins/back-to-the-top/backtothetop.css
Version Parameters
back-to-the-top/backtothetop.admin.js?ver=back-to-the-top/backtothetop.js?ver=back-to-the-top/backtothetop.css?ver=

HTML / DOM Fingerprints

CSS Classes
backtothetop-viewer
Data Attributes
data-backtothetop-durationdata-backtothetop-easingdata-backtothetop-offsetdata-backtothetop-fixed-scroll-offsetdata-backtothetop-fixed-fadeindata-backtothetop-fixed-fadeout+10 more
JS Globals
backtothetop
FAQ

Frequently Asked Questions about Back to the Top