Back to Top Button Security & Risk Analysis

wordpress.org/plugins/back-to-top-button

Over 171 free icons Scroll Back to Top Button and unlimited colors - custom button.

50 active installs v1.5 PHP + WP 4.6+ Updated Oct 5, 2016
back-to-topback-to-top-pluginbuttonto-toptop
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Back to Top Button Safe to Use in 2026?

Generally Safe

Score 85/100

Back to Top Button has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The 'back-to-top-button' plugin v1.5 exhibits a generally strong security posture based on the provided static analysis. There are no identified entry points with significant attack surface, and all SQL queries are properly prepared, mitigating common injection risks. The absence of file operations and external HTTP requests further reduces potential attack vectors. However, a notable concern is the low percentage (6%) of properly escaped output. This indicates a significant risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data or dynamically generated content might not be sufficiently sanitized before being displayed to users. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive indicator. This, combined with the lack of critical taint flows, suggests that historically, the plugin has been developed with security in mind. Despite the positive history and lack of direct entry point vulnerabilities, the widespread unescaped output is a critical weakness that must be addressed to ensure user safety.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

Back to Top Button Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Back to Top Button Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
531
32 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

6% escaped563 total outputs
Attack Surface

Back to Top Button Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 20
actionadmin_menuback-to-top.php:13
actionadmin_initback-to-top.php:18
actionadmin_enqueue_scriptsback-to-top.php:21
actionwp_enqueue_scriptsback-to-top.php:56
actioninitback-to-top.php:1335
actionwp_headback-to-top.php:1349
actionadmin_headback-to-top.php:1360
actionwp_headback-to-top.php:1372
actionwp_headback-to-top.php:1382
actionwp_headback-to-top.php:1393
actionwp_footerback-to-top.php:1398
actionwp_headback-to-top.php:1409
actionwp_footerback-to-top.php:1442
actionwp_headback-to-top.php:1470
actionwp_headback-to-top.php:1481
actionwp_headback-to-top.php:1492
actionwp_headback-to-top.php:1503
actionwp_headback-to-top.php:1514
actionwp_headback-to-top.php:1525
actionwp_headback-to-top.php:1537
Maintenance & Trust

Back to Top Button Maintenance & Trust

Maintenance Signals

WordPress version tested4.6.30
Last updatedOct 5, 2016
PHP min version
Downloads4K

Community Trust

Rating100/100
Number of ratings3
Active installs50
Developer Profile

Back to Top Button Developer Profile

seosbg

74 plugins · 10K total installs

97
trust score
Avg Security Score
95/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect Back to Top Button

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/back-to-top-button/css/style.css/wp-content/plugins/back-to-top-button/js/admin.js/wp-content/plugins/back-to-top-button/css/font-awesome.min.css/wp-content/plugins/back-to-top-button/images/icon.png/wp-content/plugins/back-to-top-button/images/logo.png
Version Parameters
back-to-top-button/css/style.css?ver=back-to-top-button/js/admin.js?ver=back-to-top-button/css/font-awesome.min.css?ver=

HTML / DOM Fingerprints

CSS Classes
back-to-top-bottonss-logo
HTML Comments
Activate SpeedPosition Left:
Data Attributes
data-tabaria-labelledby
JS Globals
jQuery
FAQ

Frequently Asked Questions about Back to Top Button