
Beam me up Scotty – Back to Top Button Security & Risk Analysis
wordpress.org/plugins/beam-me-up-scottyAdd a back to top button to your site quickly and easily with this simple and easy to configure plugin.
Is Beam me up Scotty – Back to Top Button Safe to Use in 2026?
Mostly Safe
Score 70/100Beam me up Scotty – Back to Top Button is generally safe to use though it hasn't been updated recently. 2 past CVEs were resolved. Keep it updated.
The static analysis of 'beam-me-up-scotty' v1.0.23 reveals a plugin with a seemingly small attack surface and generally good practices in some areas. Notably, there are no identified AJAX handlers, REST API routes, shortcodes, or cron events, which are common entry points for vulnerabilities. The plugin also avoids dangerous functions and file operations, and uses prepared statements for all its SQL queries. However, a significant concern arises from the output escaping, where only 67% of outputs are properly escaped, leaving a substantial portion potentially vulnerable to Cross-Site Scripting (XSS) attacks. The lack of nonce and capability checks across all identified entry points is also a serious oversight, as it means any potential entry points could be exploited without proper authorization or validation.
The vulnerability history paints a more concerning picture. With a total of two known CVEs, and one still unpatched, the plugin has a documented track record of security flaws. The common vulnerability type being Cross-Site Scripting aligns with the findings in the static analysis regarding unescaped output. The fact that a medium severity vulnerability was last patched on April 1st, 2025, suggests that the plugin's maintainers are addressing issues, but the existence of an unpatched vulnerability, especially given the XSS findings, poses a direct and immediate risk to users.
In conclusion, while 'beam-me-up-scotty' v1.0.23 demonstrates some positive security attributes like the absence of certain risky functionalities and the use of prepared statements, the high percentage of unescaped output and the critical lack of authorization checks create a significant risk. Combined with the history of known vulnerabilities, one of which remains unpatched, this plugin should be approached with caution. The potential for XSS and unauthorized access, despite the limited attack surface, makes it a moderate to high-risk plugin for deployment.
Key Concerns
- Unpatched CVEs present
- Low output escaping percentage
- Missing nonce checks
- Missing capability checks
Beam me up Scotty – Back to Top Button Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Beam me up Scotty – Back to Top Button <= 1.0.23 - Authenticated (Administrator+) Stored Cross-Site Scripting
Beam me up Scotty – Back to Top Button <= 1.0.21 - Reflected Cross-Site Scripting
Beam me up Scotty – Back to Top Button Code Analysis
Output Escaping
Beam me up Scotty – Back to Top Button Attack Surface
WordPress Hooks 12
Maintenance & Trust
Beam me up Scotty – Back to Top Button Maintenance & Trust
Maintenance Signals
Community Trust
Beam me up Scotty – Back to Top Button Alternatives
LZ Scroll Up
lz-scroll-up
LZ Scroll Up is an awesome, Super lightweight plugin for your wordpress website
LZ Scroll Bar
lz-scroll-bar
LZ Scroll Bar Up is an awesome, Super lightweight plugin for your wordpress website
Smooth Back To Top Button
smooth-back-to-top-button
Smooth Back To Top button with scroll progress indicator.
Scroll To Top
scroll-top
Automatically adds a flexible Back to Top button to your WordPress website that allows your visitor to scroll back to the top of your page with one cl …
Scroll Back To Top
scroll-back-to-top
This plugin will add a button that allows users to scroll smoothly to the top of the page.
Beam me up Scotty – Back to Top Button Developer Profile
10 plugins · 15K total installs
How We Detect Beam me up Scotty – Back to Top Button
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/beam-me-up-scotty/library/css/settings.css/wp-content/plugins/beam-me-up-scotty/library/css/style.css/wp-content/plugins/beam-me-up-scotty/library/js/settings.js/wp-content/plugins/beam-me-up-scotty/library/js/script.js/wp-content/plugins/beam-me-up-scotty/library/js/jscolor.js/wp-content/plugins/beam-me-up-scotty/library/js/settings.js/wp-content/plugins/beam-me-up-scotty/library/js/script.jsbeam-me-up-scotty/library/css/settings.css?ver=beam-me-up-scotty/library/css/style.css?ver=beam-me-up-scotty/library/js/settings.js?ver=beam-me-up-scotty/library/js/script.js?ver=HTML / DOM Fingerprints
otb-beam-me-up-scotty-buttondata-otb-settingsOTB_Beam_Me_Up_Scotty