
MouseWheel Smooth Scroll Security & Risk Analysis
wordpress.org/plugins/mousewheel-smooth-scrollSmooth scrolling experience, with mousewheel, touchpad or keyboard
Is MouseWheel Smooth Scroll Safe to Use in 2026?
Generally Safe
Score 100/100MouseWheel Smooth Scroll has a strong security track record. Known vulnerabilities have been patched promptly.
The mousewheel-smooth-scroll plugin version 6.7.3 exhibits a generally strong security posture with several positive indicators. Notably, the absence of AJAX handlers, REST API routes, shortcodes, and cron events with unprotected entry points significantly limits the potential attack surface. The code also demonstrates good practices by using prepared statements for all SQL queries and including nonce checks. However, the analysis does reveal some areas for concern. A significant portion of output (40%) is not properly escaped, which could lead to Cross-Site Scripting (XSS) vulnerabilities if malicious data is ever processed or rendered. The presence of file operations, even if not flagged as unsanitized paths in the taint analysis, warrants careful review in conjunction with the output escaping issue.
The plugin's vulnerability history, while not indicating any currently unpatched critical or high-severity issues, shows a past CVE for Cross-Site Request Forgery (CSRF) in late 2021. This, combined with the current lack of capability checks and the imperfect output escaping, suggests that while the current version may be clean, the plugin has had historical vulnerabilities that could resurface or be reintroduced. The complete absence of taint analysis flows is also noteworthy; while this could indicate well-written code, it might also mean the analysis was not comprehensive enough to identify subtle data flow issues, especially in conjunction with the unescaped output.
In conclusion, mousewheel-smooth-scroll v6.7.3 has a commendable lack of direct entry points and employs good SQL practices. The main weaknesses lie in the unescaped output, which represents a tangible risk of XSS, and the historical precedent of CSRF. The absence of capability checks on its limited code signals is a minor concern given the small attack surface, but the unescaped output is the most immediate and significant risk identified.
Key Concerns
- Unescaped output identified
- No capability checks on code signals
- Past vulnerability history (CSRF)
MouseWheel Smooth Scroll Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
MouseWheel Smooth Scroll <= 5.6 - Plugin's Setting Update via Cross-Site Request Forgery
MouseWheel Smooth Scroll Code Analysis
Output Escaping
MouseWheel Smooth Scroll Attack Surface
WordPress Hooks 4
Maintenance & Trust
MouseWheel Smooth Scroll Maintenance & Trust
Maintenance Signals
Community Trust
MouseWheel Smooth Scroll Alternatives
Page scroll to id
page-scroll-to-id
Create links that scroll the page smoothly to any id within the document.
Smooth Scrolling
smooth-scrolling
Add sleek smooth scrolling to your site for seamless content navigation, enhancing user interaction.🖱️
Top Smooth Scroll
top-smooth-scroll
A complete plugin to add smooth scroll to your WordPress Website, Smooth Scroll To Top, Smooth Scroll To ID, Page Smooth Scrolling, Mouse Smooth Scrol …
Smoothscroll
smoothscroll
Adds smoothscrolling to your website for better user experience.
Green Life Custom Scrollbar
green-life-custom-scrollbar
Allows you to change browser default scrollbar with a customizable morden scrollbar.
MouseWheel Smooth Scroll Developer Profile
13 plugins · 136K total installs
How We Detect MouseWheel Smooth Scroll
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mousewheel-smooth-scroll/js/lenis.min.js/wp-content/plugins/mousewheel-smooth-scroll/js/SmoothScroll.min.js/wp-content/uploads/wpmss/lenis-init.min.js/wp-content/uploads/wpmss/wpmssab.min.js/wp-content/uploads/wpmss/wpmss.min.jsmousewheel-smooth-scroll/js/lenis.min.js?ver=mousewheel-smooth-scroll/js/SmoothScroll.min.js?ver=mousewheel-smooth-scroll/wpmssab.min.js?ver=mousewheel-smooth-scroll/wpmss.min.js?ver=HTML / DOM Fingerprints
LenislenisInstanceSmoothScroll