
Scroll to Top Security & Risk Analysis
wordpress.org/plugins/mdc-scroll-to-topScroll to Top button for your WordPress site.
Is Scroll to Top Safe to Use in 2026?
Generally Safe
Score 85/100Scroll to Top has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The mdc-scroll-to-top plugin version 2.0 demonstrates a generally good security posture with no known vulnerabilities or critical taint flows. The complete absence of SQL queries that aren't prepared and the lack of file operations or external HTTP requests are positive indicators. However, the static analysis reveals significant concerns. The presence of the `create_function` dangerous function is a critical red flag, as it can be exploited for code injection if not handled with extreme care and sanitization, which the limited taint analysis doesn't seem to have fully covered or confirmed. Additionally, the low rate of proper output escaping (32%) suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities. The absence of nonce checks and capability checks on its zero entry points, while seemingly benign due to the lack of entry points, is a potential weakness if any new entry points are added in the future without proper security considerations. In conclusion, while the plugin benefits from a clean vulnerability history and no direct exploitable attack surface currently, the identified code signals point to potential security weaknesses that require immediate attention to prevent future exploitation.
Key Concerns
- Dangerous function (create_function)
- Low output escaping rate (32%)
- No capability checks on potential entry points
- No nonce checks on potential entry points
Scroll to Top Security Vulnerabilities
Scroll to Top Code Analysis
Dangerous Functions Found
Output Escaping
Scroll to Top Attack Surface
WordPress Hooks 6
Maintenance & Trust
Scroll to Top Maintenance & Trust
Maintenance Signals
Community Trust
Scroll to Top Alternatives
Top Scroller
top-scroller
Top Scroller plugin allows the visitor to easily and safely scroll back to the top of the page.
Scroll To Top or Bottom
scroll-to-top-or-bottom
Easy to use scroll to top and bottom plugin.
Click to top
click-to-top
A wordpress plugin to create a customisable Click To Top feature.
Ax ScrollTo Top
ax-scrollto-top
Add a Scroll to top button in the website footer.
WP-Smooth-Scroll
wp-smooth-scroll
WP-Smooth-Scroll is a plugin that helps users to scroll smoothly to top of the page.
Scroll to Top Developer Profile
6 plugins · 180 total installs
How We Detect Scroll to Top
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mdc-scroll-to-top/assets/css/style.css/wp-content/plugins/mdc-scroll-to-top/assets/css/admin.css/wp-content/plugins/mdc-scroll-to-top/assets/js/script.js/wp-content/plugins/mdc-scroll-to-top/assets/js/admin.js/wp-content/plugins/mdc-scroll-to-top/assets/icons/arrow23.png/wp-content/plugins/mdc-scroll-to-top/assets/js/script.js/wp-content/plugins/mdc-scroll-to-top/assets/js/admin.jsmdc-scroll-to-top/assets/css/style.css?ver=mdc-scroll-to-top/assets/js/script.js?ver=mdc-scroll-to-top/assets/css/admin.css?ver=mdc-scroll-to-top/assets/js/admin.js?ver=HTML / DOM Fingerprints
scroll-to-toptime_to_scrollshow_after_px