Plugin Name: GMO Go to Top Security & Risk Analysis

wordpress.org/plugins/gmo-go-to-top

This plugin let you place a link button to go back to top of the page from the bottom of the screen. You can place a button either bottom left or rig …

10 active installs v1.4 PHP + WP 3.8+ Updated Jan 29, 2016
click-to-topgo-topgo-to-toplinklinks
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Plugin Name: GMO Go to Top Safe to Use in 2026?

Generally Safe

Score 85/100

Plugin Name: GMO Go to Top has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The 'gmo-go-to-top' plugin version 1.4 exhibits a generally good security posture based on the provided static analysis. The absence of reported CVEs and common vulnerability types suggests a history of secure development or prompt patching. Notably, there are no AJAX handlers, REST API routes, shortcodes, or cron events, significantly reducing the attack surface. All SQL queries are properly prepared, and file operations and external HTTP requests are absent. This indicates a conscientious effort to avoid common web application vulnerabilities.

However, the static analysis does reveal some areas for concern. While the total number of outputs is low, 74% properly escaped is not ideal, meaning 26% of outputs are potentially vulnerable to XSS attacks. Furthermore, the taint analysis shows two flows with unsanitized paths, which, despite not being classified as critical or high severity, warrant attention as they represent potential injection vectors. The lack of nonce and capability checks on any entry points, though the entry points are zero, is a theoretical weakness that could become a problem if the plugin were to evolve and add new entry points without proper security measures.

In conclusion, 'gmo-go-to-top' v1.4 appears to be a relatively safe plugin due to its minimal attack surface and secure handling of database operations. The absence of past vulnerabilities is a strong positive indicator. The primary weaknesses lie in the less-than-perfect output escaping and the presence of unsanitized taint flows, which, while not currently critical, should be addressed to maintain a robust security profile.

Key Concerns

  • Unsanitized Taint Flows (2)
  • Output Escaping (26% not properly escaped)
Vulnerabilities
None known

Plugin Name: GMO Go to Top Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Plugin Name: GMO Go to Top Release Timeline

v1.1
v1.0
Code Analysis
Analyzed Apr 16, 2026

Plugin Name: GMO Go to Top Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
14 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

74% escaped19 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
admin_init (gmo-go-to-top.php:34)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Plugin Name: GMO Go to Top Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionwp_footergmo-go-to-top.php:28
actionadmin_menugmo-go-to-top.php:29
actionwp_enqueue_scriptsgmo-go-to-top.php:30
actionadmin_initgmo-go-to-top.php:31
Maintenance & Trust

Plugin Name: GMO Go to Top Maintenance & Trust

Maintenance Signals

WordPress version tested4.4.34
Last updatedJan 29, 2016
PHP min version
Downloads5K

Community Trust

Rating60/100
Number of ratings1
Active installs10
Developer Profile

Plugin Name: GMO Go to Top Developer Profile

Z.com byGMO

9 plugins · 280 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Plugin Name: GMO Go to Top

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gmo-go-to-top/css/gmo-admin-plugin.css/wp-content/plugins/gmo-go-to-top/css/go-to-top-style.css/wp-content/plugins/gmo-go-to-top/iconvault/iconvault-preview.css/wp-content/plugins/gmo-go-to-top/genericons/genericons.css/wp-content/plugins/gmo-go-to-top/script.js/wp-content/plugins/gmo-go-to-top/uploader.js/wp-content/plugins/gmo-go-to-top/colorpic.js
Script Paths
/wp-content/plugins/gmo-go-to-top/script.js/wp-content/plugins/gmo-go-to-top/uploader.js/wp-content/plugins/gmo-go-to-top/colorpic.js
Version Parameters
gmo-go-to-top/script.js?ver=go-to-top-gmo-admin-plugin?ver=go-to-top-style?ver=iconvault-preview?ver=gene?ver=

HTML / DOM Fingerprints

CSS Classes
gmo_go_toptype_selectselect_iconicon_selectimages_selecticon_font
Data Attributes
id="gmo_go_top"id="gmoplugins"id="gmoplugLeft"id="icon_table"id="color_picker"id="images_table"+2 more
JS Globals
gmo_go_to_top
FAQ

Frequently Asked Questions about Plugin Name: GMO Go to Top