Custom Scrollbar Security & Risk Analysis

wordpress.org/plugins/custom-scrollbar

Adds a custom scrollbar to specified HTML elements.

2K active installs v1.3.8 PHP + WP 3.4+ Updated Jul 9, 2021
scrollscroll-barscroll-barsscrollbarscrollbars
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Custom Scrollbar Safe to Use in 2026?

Generally Safe

Score 85/100

Custom Scrollbar has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The custom-scrollbar plugin v1.3.8 exhibits a generally strong security posture, characterized by a lack of known vulnerabilities and a proactive approach to security best practices in its code. The absence of any recorded CVEs, including critical or high-severity ones, is a significant positive indicator. The code analysis reveals a healthy reliance on prepared statements for SQL queries (64%) and a moderate level of output escaping (58%), suggesting developers have considered common web vulnerabilities. However, there are areas for improvement. Notably, all four analyzed taint flows involve unsanitized paths, and while no critical or high severity issues were flagged, this is a potential area of concern that warrants further investigation. The presence of file operations and external HTTP requests also necessitates careful auditing to ensure these functionalities do not introduce exploitable weaknesses. Overall, the plugin is likely safe for general use due to its clean vulnerability history, but the identified taint flow patterns suggest a need for more robust sanitization practices to achieve an optimal security profile.

Key Concerns

  • Taint flows with unsanitized paths detected
  • Output escaping below 80%
  • SQL queries not fully using prepared statements
Vulnerabilities
None known

Custom Scrollbar Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Custom Scrollbar Code Analysis

Dangerous Functions
0
Raw SQL Queries
4
7 prepared
Unescaped Output
38
52 escaped
Nonce Checks
1
Capability Checks
6
File Operations
11
External Requests
4
Bundled Libraries
0

SQL Query Safety

64% prepared11 total queries

Output Escaping

58% escaped90 total outputs
Data Flows
4 unsanitized

Data Flow Analysis

4 flows4 with unsanitized paths
___getWPRemotePostStatus (include\library\apf\factory\_common\form\field_type\AdminPageFramework_FieldType_system.php:138)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Custom Scrollbar Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 58
actionadmin_footerinclude\library\apf\custom-field-types\revealer-custom-field-type\RevealerCustomFieldType.php:158
actionwp_footerinclude\library\apf\custom-field-types\revealer-custom-field-type\RevealerCustomFieldType.php:161
actionembed_footerinclude\library\apf\custom-field-types\revealer-custom-field-type\RevealerCustomFieldType.php:162
actionwp_loadedinclude\library\apf\factory\admin_page\AdminPageFramework.php:15
filteradmin_titleinclude\library\apf\factory\admin_page\AdminPageFramework.php:73
actionadmin_headinclude\library\apf\factory\admin_page\_controller\AdminPageFramework_HelpPane_admin_page.php:14
filterplugin_row_metainclude\library\apf\factory\admin_page\_controller\AdminPageFramework_Link_admin_page.php:21
filterwp_mail_content_typeinclude\library\apf\factory\admin_page\_model\AdminPageFramework_FormEmail.php:23
filterwp_mail_frominclude\library\apf\factory\admin_page\_model\AdminPageFramework_FormEmail.php:26
filterwp_mail_from_nameinclude\library\apf\factory\admin_page\_model\AdminPageFramework_FormEmail.php:29
actioncurrent_screeninclude\library\apf\factory\admin_page\_model\delegate\AdminPageFramework_Model_Menu__RegisterMenu.php:106
filterupdate_footerinclude\library\apf\factory\admin_page\_view\AdminPageFramework_PageLoadInfo_admin_page.php:20
actionadmin_headinclude\library\apf\factory\admin_page\_view\AdminPageFramework_View__PageMetaboxEnabler.php:11
actionshutdowninclude\library\apf\factory\_common\form\error\AdminPageFramework_Form___FieldError.php:29
actionshutdowninclude\library\apf\factory\_common\form\error\AdminPageFramework_Form___FieldError.php:48
filtermedia_upload_tabsinclude\library\apf\factory\_common\form\field_type\AdminPageFramework_FieldType_color.php:84
filtergettextinclude\library\apf\factory\_common\form\field_type\AdminPageFramework_FieldType_color.php:94
actionshutdowninclude\library\apf\factory\_common\form\notice\AdminPageFramework_Form___SubmitNotice.php:30
actionshutdowninclude\library\apf\factory\_common\form\_model\AdminPageFramework_Form_Model___LastInput.php:26
actionshutdowninclude\library\apf\factory\_common\form\_model\AdminPageFramework_Form_Model___LastInput.php:51
actionwp_enqueue_scriptsinclude\library\apf\factory\_common\form\_view\resource\AdminPageFramework_Form_View__Resource.php:24
actionwp_enqueue_scriptsinclude\library\apf\factory\_common\form\_view\resource\AdminPageFramework_Form_View__Resource.php:25
actionwp_footerinclude\library\apf\factory\_common\form\_view\resource\AdminPageFramework_Form_View__Resource.php:27
actionwp_footerinclude\library\apf\factory\_common\form\_view\resource\AdminPageFramework_Form_View__Resource.php:28
actionwp_print_footer_scriptsinclude\library\apf\factory\_common\form\_view\resource\AdminPageFramework_Form_View__Resource.php:29
actionwp_print_footer_scriptsinclude\library\apf\factory\_common\form\_view\resource\AdminPageFramework_Form_View__Resource.php:30
actionadmin_enqueue_scriptsinclude\library\apf\factory\_common\form\_view\resource\AdminPageFramework_Form_View__Resource.php:34
actionadmin_enqueue_scriptsinclude\library\apf\factory\_common\form\_view\resource\AdminPageFramework_Form_View__Resource.php:35
actioncustomize_controls_print_footer_scriptsinclude\library\apf\factory\_common\form\_view\resource\AdminPageFramework_Form_View__Resource.php:37
actioncustomize_controls_print_footer_scriptsinclude\library\apf\factory\_common\form\_view\resource\AdminPageFramework_Form_View__Resource.php:38
actionadmin_footerinclude\library\apf\factory\_common\form\_view\resource\AdminPageFramework_Form_View__Resource.php:39
actionadmin_footerinclude\library\apf\factory\_common\form\_view\resource\AdminPageFramework_Form_View__Resource.php:40
actionadmin_print_footer_scriptsinclude\library\apf\factory\_common\form\_view\resource\AdminPageFramework_Form_View__Resource.php:41
actionadmin_print_footer_scriptsinclude\library\apf\factory\_common\form\_view\resource\AdminPageFramework_Form_View__Resource.php:42
actionadmin_headinclude\library\apf\factory\_common\_abstract\_controller\AdminPageFramework_HelpPane_Base.php:12
actionin_admin_footerinclude\library\apf\factory\_common\_abstract\_controller\AdminPageFramework_Link_Base.php:16
filteradmin_footer_textinclude\library\apf\factory\_common\_abstract\_controller\AdminPageFramework_Link_Base.php:65
filterupdate_footerinclude\library\apf\factory\_common\_abstract\_controller\AdminPageFramework_Link_Base.php:66
actionadmin_enqueue_scriptsinclude\library\apf\factory\_common\_abstract\_controller\AdminPageFramework_Resource_Base.php:20
actionadmin_enqueue_scriptsinclude\library\apf\factory\_common\_abstract\_controller\AdminPageFramework_Resource_Base.php:21
actioncustomize_controls_print_footer_scriptsinclude\library\apf\factory\_common\_abstract\_controller\AdminPageFramework_Resource_Base.php:24
actioncustomize_controls_print_footer_scriptsinclude\library\apf\factory\_common\_abstract\_controller\AdminPageFramework_Resource_Base.php:25
actionadmin_footerinclude\library\apf\factory\_common\_abstract\_controller\AdminPageFramework_Resource_Base.php:26
actionadmin_footerinclude\library\apf\factory\_common\_abstract\_controller\AdminPageFramework_Resource_Base.php:27
actionadmin_print_footer_scriptsinclude\library\apf\factory\_common\_abstract\_controller\AdminPageFramework_Resource_Base.php:28
actionadmin_print_footer_scriptsinclude\library\apf\factory\_common\_abstract\_controller\AdminPageFramework_Resource_Base.php:29
filterscript_loader_srcinclude\library\apf\factory\_common\_abstract\_controller\AdminPageFramework_Resource_Base.php:30
filterstyle_loader_srcinclude\library\apf\factory\_common\_abstract\_controller\AdminPageFramework_Resource_Base.php:31
filterclean_urlinclude\library\apf\factory\_common\_abstract\_controller\AdminPageFramework_Resource_Base.php:43
actionwp_enqueue_scriptsinclude\library\apf\factory\_common\_abstract\_view\AdminPageFramework_Factory___Script_Base.php:18
actionin_admin_footerinclude\library\apf\factory\_common\_abstract\_view\AdminPageFramework_PageLoadInfo_Base.php:18
actioninitinclude\library\apf\utility\plugin_bootstrap\AdminPageFramework_PluginBootstrap.php:34
actionadmin_enqueue_scriptsinclude\library\apf\utility\pointer_tool_tip\AdminPageFramework_PointerToolTip.php:32
actionadmin_print_footer_scriptsinclude\library\apf\utility\pointer_tool_tip\AdminPageFramework_PointerToolTip.php:99
actionadmin_noticesinclude\library\apf\utility\requirement\AdminPageFramework_Requirement.php:74
actionadmin_noticesinclude\library\apf\utility\requirement\AdminPageFramework_Requirement.php:92
actionwp_enqueue_scriptsinclude\main\resource\CustomScrollbar_ResourceLoader__Script.php:25
actionwp_print_stylesinclude\main\resource\CustomScrollbar_ResourceLoader__Style.php:25
Maintenance & Trust

Custom Scrollbar Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedJul 9, 2021
PHP min version
Downloads48K

Community Trust

Rating94/100
Number of ratings7
Active installs2K
Developer Profile

Custom Scrollbar Developer Profile

miunosoft

15 plugins · 2K total installs

84
trust score
Avg Security Score
86/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Custom Scrollbar

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/custom-scrollbar/assets/css/custom-scrollbar.css/wp-content/plugins/custom-scrollbar/assets/js/custom-scrollbar.js
Script Paths
/wp-content/plugins/custom-scrollbar/assets/js/custom-scrollbar.js
Version Parameters
custom-scrollbar/assets/css/custom-scrollbar.css?ver=custom-scrollbar/assets/js/custom-scrollbar.js?ver=

HTML / DOM Fingerprints

CSS Classes
mCSB_containermCSB_draggerRailmCSB_draggerWrappermCSB_draggermCSB_dragger_barmCSB_scrollToolsmCSB_draggerContainer
Data Attributes
data-csb-iddata-csb-selectordata-csb-themedata-csb-widthdata-csb-heightdata-csb-position+5 more
JS Globals
jQuery.fn.customScrollbar
FAQ

Frequently Asked Questions about Custom Scrollbar