Dewdrop Custom Scrollbar Security & Risk Analysis

wordpress.org/plugins/dewdrop-custom-scrollbar

This is free version of Dewdrop Custom Scrollbar. Try Pro version for more control and feature. This plugin give your WordPress site a customizable, s …

200 active installs v1.4 PHP + WP 3.0.1+ Updated Dec 1, 2017
costomize-scorllbarcustom-scrollscrollbarwordpresswordpress-srollbar-style
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Dewdrop Custom Scrollbar Safe to Use in 2026?

Generally Safe

Score 85/100

Dewdrop Custom Scrollbar has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The dewdrop-custom-scrollbar plugin version 1.4 exhibits a generally strong security posture due to the absence of known vulnerabilities and a seemingly limited attack surface. The static analysis reveals no dangerous functions, SQL queries are exclusively using prepared statements, and there are no identified file operations or external HTTP requests. This indicates a good level of adherence to secure coding practices in these areas.

However, a significant concern arises from the output escaping. With 36 total outputs and 0% properly escaped, this represents a critical weakness. Any data rendered to the user without proper sanitization is susceptible to cross-site scripting (XSS) attacks. The lack of any identified flows in the taint analysis is somewhat contradictory to this, but the explicit reporting of 0% proper output escaping is a clear and actionable security risk. Furthermore, the absence of nonce and capability checks across all entry points, while the entry points themselves are reported as zero, still presents a potential risk if any functionalities were to be added or discovered later that utilize these entry points without proper security measures.

The vulnerability history being completely clear is a positive sign, suggesting the plugin has historically been well-maintained. However, the static analysis findings, particularly the complete lack of output escaping, overshadow this positive history. The plugin's strengths lie in its secure handling of database queries and external interactions. Its primary weakness is the critical failure in output sanitization, which requires immediate attention to prevent potential XSS vulnerabilities.

Key Concerns

  • No output escaping
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Dewdrop Custom Scrollbar Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Dewdrop Custom Scrollbar Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
36
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped36 total outputs
Attack Surface

Dewdrop Custom Scrollbar Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actioninitdewdrop-scrollbar.php:15
actionwp_enqueue_scriptsdewdrop-scrollbar.php:26
actionadmin_menudewdrop-scrollbar.php:33
actionadmin_enqueue_scriptsdewdrop-scrollbar.php:44
actionadmin_initdewdrop-scrollbar.php:65
actionwp_headdewdrop-scrollbar.php:538
Maintenance & Trust

Dewdrop Custom Scrollbar Maintenance & Trust

Maintenance Signals

WordPress version tested
Last updatedDec 1, 2017
PHP min version
Downloads17K

Community Trust

Rating100/100
Number of ratings8
Active installs200
Developer Profile

Dewdrop Custom Scrollbar Developer Profile

ABDUR ROB (SOYON)

1 plugin · 200 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Dewdrop Custom Scrollbar

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/dewdrop-custom-scrollbar/js/jquery.nicescroll.min.js/wp-content/plugins/dewdrop-custom-scrollbar/css/style.css/wp-content/plugins/dewdrop-custom-scrollbar/js/javascript.js
Script Paths
/wp-content/plugins/dewdrop-custom-scrollbar/js/jquery.nicescroll.min.js/wp-content/plugins/dewdrop-custom-scrollbar/js/javascript.js

HTML / DOM Fingerprints

CSS Classes
nice-scroll-wrapnice-scroll-content
HTML Comments
If you think my plugins works helped you some way, buy me a cup of coffee for inspiration ;).Try Pro version to enable this feature.Select a style for your scrollbar or you can use custom style. Default ready style is <strong>Style 1</strong>
Data Attributes
data-colordata-widthdata-sidedata-border-radiusdata-cursor-colordata-cursor-width+4 more
JS Globals
jQuery
FAQ

Frequently Asked Questions about Dewdrop Custom Scrollbar