Easy Back to Top Security & Risk Analysis

wordpress.org/plugins/easy-back-to-top

A simple wordpress back to top scroll plugin. It's built by css3 and simple jquery script.

10 active installs v1.0 PHP + WP 3.0.1+ Updated Sep 21, 2016
backback-to-topeasyscrolltop
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Easy Back to Top Safe to Use in 2026?

Generally Safe

Score 85/100

Easy Back to Top has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "easy-back-to-top" v1.0 plugin exhibits a generally good security posture due to a lack of identified vulnerabilities and a small attack surface. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential entry points for attackers. Furthermore, the plugin demonstrates a commitment to secure coding practices by utilizing prepared statements for all SQL queries and avoiding file operations and external HTTP requests. However, a significant concern arises from the complete lack of output escaping. This means that any dynamic data rendered by the plugin is not being sanitized, leaving it vulnerable to cross-site scripting (XSS) attacks if user-supplied data is ever incorporated into the output. The vulnerability history also shows no known past issues, which is a positive indicator, but this should not overshadow the immediate risk posed by unescaped output.

Key Concerns

  • All outputs are unescaped
Vulnerabilities
None known

Easy Back to Top Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Easy Back to Top Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Easy Back to Top Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
14
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped14 total outputs
Attack Surface

Easy Back to Top Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actioniniteasy-back-to-top.php:17
actionadmin_menueasy-back-to-top.php:25
actionadmin_enqueue_scriptseasy-back-to-top.php:28
actionadmin_initeasy-back-to-top.php:53
actionwp_footereasy-back-to-top.php:185
actionwp_footereasy-back-to-top.php:189
Maintenance & Trust

Easy Back to Top Maintenance & Trust

Maintenance Signals

WordPress version tested4.6.30
Last updatedSep 21, 2016
PHP min version
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Easy Back to Top Developer Profile

Sumon Hasan

4 plugins · 100 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Easy Back to Top

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/easy-back-to-top/js/color-pickr.js
Script Paths
/wp-content/plugins/easy-back-to-top/js/color-pickr.js

HTML / DOM Fingerprints

CSS Classes
span-icon
Data Attributes
for="scroll_type"name="easy_btt_options[scroll_type]"for="width_height"name="easy_btt_options[width_height]"class="height-width"for="bdcolor"+14 more
JS Globals
jQuery
FAQ

Frequently Asked Questions about Easy Back to Top