
Hash Link Scroll Offset Security & Risk Analysis
wordpress.org/plugins/hash-link-scroll-offsetOffset the scroll position of anchored links. Handy if you have a sticky header that covers linked material.
Is Hash Link Scroll Offset Safe to Use in 2026?
Generally Safe
Score 100/100Hash Link Scroll Offset has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "hash-link-scroll-offset" plugin version 0.4.1 demonstrates a strong security posture based on the provided static analysis and vulnerability history. The code analysis reveals no dangerous functions, all SQL queries utilize prepared statements, and all output is properly escaped. Crucially, there are no identified flows with unsanitized paths, and the plugin has a completely clean vulnerability history with zero known CVEs. The attack surface is also zero, indicating no AJAX handlers, REST API routes, shortcodes, or cron events exposed, which significantly reduces potential entry points for attackers.
However, the analysis does highlight a complete absence of nonce checks and capability checks. While the current attack surface is zero, this lack of authentication and authorization mechanisms on potential entry points, if they were to be introduced in future versions or through interaction with other plugins, represents a latent risk. This is a concerning area as it deviates from best practices for WordPress plugin development, where such checks are vital for preventing unauthorized actions and ensuring secure interactions.
In conclusion, the plugin is currently very secure due to its minimal attack surface and absence of vulnerabilities. The lack of any exploitable code signals or historical issues is a significant strength. The primary weakness lies in the complete omission of nonce and capability checks, which, while not posing an immediate threat in the current version, is a significant oversight that could lead to vulnerabilities if the plugin's functionality expands or interacts with other components in the future. This suggests a developer who is cautious about common vulnerability types but perhaps less familiar with robust WordPress security primitives for handling user interactions.
Key Concerns
- Missing nonce checks
- Missing capability checks
Hash Link Scroll Offset Security Vulnerabilities
Hash Link Scroll Offset Code Analysis
Output Escaping
Data Flow Analysis
Hash Link Scroll Offset Attack Surface
WordPress Hooks 5
Maintenance & Trust
Hash Link Scroll Offset Maintenance & Trust
Maintenance Signals
Community Trust
Hash Link Scroll Offset Alternatives
No alternatives data available yet.
Hash Link Scroll Offset Developer Profile
9 plugins · 1.0M total installs
How We Detect Hash Link Scroll Offset
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/hash-link-scroll-offset/assets/js/hash-link-scroll-offset.js/wp-content/plugins/hash-link-scroll-offset/assets/js/hash-link-scroll-offset.min.jsassets/js/hash-link-scroll-offset.min.asset.phphash-link-scroll-offset/style.css?ver=hash-link-scroll-offset.min.js?ver=HTML / DOM Fingerprints
hash_link_scroll_offset_setting_labelhash_link_scroll_offset_setting_wraphash_link_scroll_offsethlsOffset