
Back To Top Pro Security & Risk Analysis
wordpress.org/plugins/back-to-top-proScroll To Top plus 3 more Buttons including Back to Top, Home, Back and Email Buttons. Multiple styles, colors, position, sizes, opacity and more
Is Back To Top Pro Safe to Use in 2026?
Generally Safe
Score 100/100Back To Top Pro has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'back-to-top-pro' plugin v1.1.9 exhibits a generally strong security posture based on the static analysis provided. A significant positive is the absence of any detected dangerous functions, raw SQL queries, file operations, or external HTTP requests. The plugin also correctly implements nonce checks for its AJAX handlers and employs prepared statements for all SQL queries. Furthermore, the vulnerability history is remarkably clean, with no known CVEs recorded, indicating a history of secure development or effective patching by maintainers.
However, there are minor areas for improvement. While the attack surface is small and all entry points appear to have authentication checks, the static analysis shows that 33% of output escapes are not properly handled. This could potentially lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is directly echoed without proper sanitization or escaping in these instances. The absence of capability checks on the AJAX handlers, while mitigated by the presence of nonce checks, could be a minor concern if the AJAX actions themselves are sensitive and should be restricted based on user roles.
In conclusion, 'back-to-top-pro' v1.1.9 is a relatively secure plugin with a commendable lack of critical vulnerabilities in its history and code. The presence of nonce checks and prepared statements are excellent security practices. The primary area of concern is the incomplete output escaping, which, although not flagged as critical by the taint analysis, warrants attention to prevent potential XSS issues. The lack of capability checks on AJAX handlers is a minor consideration in the context of the other security measures in place.
Key Concerns
- Unescaped output detected
Back To Top Pro Security Vulnerabilities
Back To Top Pro Code Analysis
Output Escaping
Data Flow Analysis
Back To Top Pro Attack Surface
AJAX Handlers 2
WordPress Hooks 4
Maintenance & Trust
Back To Top Pro Maintenance & Trust
Maintenance Signals
Community Trust
Back To Top Pro Alternatives
Smooth Scroll Up
smooth-scroll-up
Smooth Scroll Up is a lightweight plugin that creates a customizable back to top feature in your WordPress website.
AMS Page Scroll Back To Top
ams-page-scroll-back-to-top
The button added by the plugin allows users to scroll smoothly to the top of the page.
WPFront Scroll Top
wpfront-scroll-top
Adds a lightweight and smooth "Scroll to Top" button to your WordPress site, improving navigation and user experience with customizable options.
Smooth Back To Top Button
smooth-back-to-top-button
Smooth Back To Top button with scroll progress indicator.
Flexible Scroll Top
flexible-scroll-top
Add a slick, lightweight and customizable scroll to top button that uses SVG icon with no jQuery dependency.
Back To Top Pro Developer Profile
12 plugins · 4K total installs
How We Detect Back To Top Pro
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/back-to-top-pro/assets/css/style.css/wp-content/plugins/back-to-top-pro/assets/js/main.js/wp-content/plugins/back-to-top-pro/assets/js/main.jsback-to-top-pro/assets/js/main.js?v=HTML / DOM Fingerprints
ztb-submit-buttonztb-register-formztb-wrapperztb-logoztb-code-wrapperztb-titleaccount-inputztb-button+2 morezb-pluginZBT_WP_ADMIN_URLZTB_BASE_URL