
Plugin Name: GMO Go to Top Security & Risk Analysis
wordpress.org/plugins/gmo-go-to-topThis plugin let you place a link button to go back to top of the page from the bottom of the screen. You can place a button either bottom left or rig …
Is Plugin Name: GMO Go to Top Safe to Use in 2026?
Generally Safe
Score 85/100Plugin Name: GMO Go to Top has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'gmo-go-to-top' plugin version 1.4 exhibits a generally good security posture based on the provided static analysis. The absence of reported CVEs and common vulnerability types suggests a history of secure development or prompt patching. Notably, there are no AJAX handlers, REST API routes, shortcodes, or cron events, significantly reducing the attack surface. All SQL queries are properly prepared, and file operations and external HTTP requests are absent. This indicates a conscientious effort to avoid common web application vulnerabilities.
However, the static analysis does reveal some areas for concern. While the total number of outputs is low, 74% properly escaped is not ideal, meaning 26% of outputs are potentially vulnerable to XSS attacks. Furthermore, the taint analysis shows two flows with unsanitized paths, which, despite not being classified as critical or high severity, warrant attention as they represent potential injection vectors. The lack of nonce and capability checks on any entry points, though the entry points are zero, is a theoretical weakness that could become a problem if the plugin were to evolve and add new entry points without proper security measures.
In conclusion, 'gmo-go-to-top' v1.4 appears to be a relatively safe plugin due to its minimal attack surface and secure handling of database operations. The absence of past vulnerabilities is a strong positive indicator. The primary weaknesses lie in the less-than-perfect output escaping and the presence of unsanitized taint flows, which, while not currently critical, should be addressed to maintain a robust security profile.
Key Concerns
- Unsanitized Taint Flows (2)
- Output Escaping (26% not properly escaped)
Plugin Name: GMO Go to Top Security Vulnerabilities
Plugin Name: GMO Go to Top Release Timeline
Plugin Name: GMO Go to Top Code Analysis
Output Escaping
Data Flow Analysis
Plugin Name: GMO Go to Top Attack Surface
WordPress Hooks 4
Maintenance & Trust
Plugin Name: GMO Go to Top Maintenance & Trust
Maintenance Signals
Community Trust
Plugin Name: GMO Go to Top Alternatives
Broken Link Checker
broken-link-checker
Broken Link Checker helps you catch broken links & images fast, before they hurt your SEO or UX. Scan and bulk-fix issues from one easy dashboard.
Broken Link Checker by AIOSEO – Easily Fix/Monitor Internal and External links
broken-link-checker-seo
Broken Link Checker by AIOSEO ensures all links on your website are working. Check your site for broken links and easily fix them to improve SEO.
PrettyLinks – Affiliate Links, Link Branding, Link Tracking, Marketing and Stripe Payments Plugin
pretty-link
🌠 The best WordPress link management, branding, tracking, sharing and payments plugin. Easily make pretty & trackable shortlinks. 🔗
LuckyWP Table of Contents
luckywp-table-of-contents
Creates SEO-friendly table of contents for your posts/pages. Works automatically or manually (via shortcode, Gutenberg block or widget).
Nginx Helper
nginx-helper
Cleans nginx's fastcgi/proxy cache or redis-cache whenever a post is edited/published. Also does a few more things.
Plugin Name: GMO Go to Top Developer Profile
9 plugins · 280 total installs
How We Detect Plugin Name: GMO Go to Top
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gmo-go-to-top/css/gmo-admin-plugin.css/wp-content/plugins/gmo-go-to-top/css/go-to-top-style.css/wp-content/plugins/gmo-go-to-top/iconvault/iconvault-preview.css/wp-content/plugins/gmo-go-to-top/genericons/genericons.css/wp-content/plugins/gmo-go-to-top/script.js/wp-content/plugins/gmo-go-to-top/uploader.js/wp-content/plugins/gmo-go-to-top/colorpic.js/wp-content/plugins/gmo-go-to-top/script.js/wp-content/plugins/gmo-go-to-top/uploader.js/wp-content/plugins/gmo-go-to-top/colorpic.jsgmo-go-to-top/script.js?ver=go-to-top-gmo-admin-plugin?ver=go-to-top-style?ver=iconvault-preview?ver=gene?ver=HTML / DOM Fingerprints
gmo_go_toptype_selectselect_iconicon_selectimages_selecticon_fontid="gmo_go_top"id="gmoplugins"id="gmoplugLeft"id="icon_table"id="color_picker"id="images_table"+2 moregmo_go_to_top