
Back to the Top Security & Risk Analysis
wordpress.org/plugins/back-to-the-topBack to the Top is a WordPress plugin that return to scroll smoothly to the top of the page. You can scroll to the smooth anchor link in the page.
Is Back to the Top Safe to Use in 2026?
Generally Safe
Score 92/100Back to the Top has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'back-to-the-top' plugin v1.2.1 exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of dangerous functions, file operations, external HTTP requests, and raw SQL queries is commendable. The high percentage of properly escaped output further reinforces this positive assessment, minimizing the risk of cross-site scripting vulnerabilities. Furthermore, the complete lack of recorded CVEs and vulnerability history suggests a history of secure development or diligent patching by the developers.
While the attack surface appears minimal with zero AJAX handlers, REST API routes, shortcodes, or cron events, a notable concern is the complete absence of nonce checks and capability checks. This indicates that even if entry points were to be discovered or introduced in future versions, they might not be adequately protected against CSRF or unauthorized access. However, given the current static analysis showing zero entry points, this remains a hypothetical concern for the current version. The taint analysis also reports no issues, which is a very positive sign.
In conclusion, the 'back-to-the-top' plugin v1.2.1 appears to be a secure plugin with no immediate exploitable vulnerabilities identified in the static analysis or vulnerability history. The developers have followed good practices regarding SQL queries and output escaping. The only potential area for improvement lies in incorporating nonce and capability checks as a proactive security measure, even in the absence of apparent entry points.
Key Concerns
- No nonce checks
- No capability checks
Back to the Top Security Vulnerabilities
Back to the Top Code Analysis
Output Escaping
Back to the Top Attack Surface
WordPress Hooks 10
Maintenance & Trust
Back to the Top Maintenance & Trust
Maintenance Signals
Community Trust
Back to the Top Alternatives
WPFront Scroll Top
wpfront-scroll-top
Adds a lightweight and smooth "Scroll to Top" button to your WordPress site, improving navigation and user experience with customizable options.
Smooth Back To Top Button
smooth-back-to-top-button
Smooth Back To Top button with scroll progress indicator.
Smooth Scroll Up
smooth-scroll-up
Smooth Scroll Up is a lightweight plugin that creates a customizable back to top feature in your WordPress website.
Back To Top Pro
back-to-top-pro
Scroll To Top plus 3 more Buttons including Back to Top, Home, Back and Email Buttons. Multiple styles, colors, position, sizes, opacity and more
Flexible Scroll Top
flexible-scroll-top
Add a slick, lightweight and customizable scroll to top button that uses SVG icon with no jQuery dependency.
Back to the Top Developer Profile
11 plugins · 39K total installs
How We Detect Back to the Top
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/back-to-the-top/backtothetop.admin.js/wp-content/plugins/back-to-the-top/backtothetop.js/wp-content/plugins/back-to-the-top/backtothetop.cssback-to-the-top/backtothetop.admin.js?ver=back-to-the-top/backtothetop.js?ver=back-to-the-top/backtothetop.css?ver=HTML / DOM Fingerprints
backtothetop-viewerdata-backtothetop-durationdata-backtothetop-easingdata-backtothetop-offsetdata-backtothetop-fixed-scroll-offsetdata-backtothetop-fixed-fadeindata-backtothetop-fixed-fadeout+10 morebacktothetop