
Nicescrollr Security & Risk Analysis
wordpress.org/plugins/nicescrollrA wrapper plugin for the Nicescroll library with full customization options for both frontend and backend.
Is Nicescrollr Safe to Use in 2026?
Generally Safe
Score 100/100Nicescrollr has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The nicescrollr plugin v1.0.0 exhibits a mixed security posture, with some positive indicators but notable areas of concern. On the positive side, there are no recorded vulnerabilities (CVEs) for this plugin, which suggests a historically stable codebase. Furthermore, the static analysis shows a lack of dangerous functions, file operations, and external HTTP requests, indicating an absence of common attack vectors. However, the plugin's attack surface is a significant weakness. It exposes two AJAX handlers, with one lacking any authentication checks. This unprotected entry point is a critical vulnerability that could allow unauthenticated users to execute arbitrary code or manipulate plugin functionality. The presence of raw SQL queries without prepared statements, coupled with a less than ideal output escaping rate (62%), further exacerbates the risk, suggesting potential for SQL injection and cross-site scripting (XSS) vulnerabilities, particularly within the unprotected AJAX handler. The taint analysis also revealed a flow with an unsanitized path, further supporting the possibility of exploitation. While the plugin has no known vulnerabilities, the identified code weaknesses, especially the unprotected AJAX handler and raw SQL queries, present a clear and present danger to a WordPress site. The absence of known CVEs may simply mean the plugin hasn't been thoroughly analyzed or targeted yet.
Key Concerns
- Unprotected AJAX handler
- Raw SQL queries without prepared statements
- Low output escaping rate
- Flow with unsanitized paths
- Missing capability checks on AJAX
Nicescrollr Security Vulnerabilities
Nicescrollr Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Nicescrollr Attack Surface
AJAX Handlers 2
WordPress Hooks 23
Maintenance & Trust
Nicescrollr Maintenance & Trust
Maintenance Signals
Community Trust
Nicescrollr Alternatives
Click to top
click-to-top
A wordpress plugin to create a customisable Click To Top feature.
Scroll Bar With Back To Top
scroll-bar-with-back-to-top
License GPLv2 or later License URI: http://www.gnu.org/licenses/gpl-2.0.html Scroll Bar With Back To Top is a Easily Customization Plugin and Very U …
Scrollr
scrollr
Scroll smoothly to a page's section or push it back to the top.
WS Custom Scrollbar
ws-custom-scrollbar
WS Custom Scrollbar plugin will enable change scrollbar styles where you can change scrollbar color, border radius, scroll speed, width.
Green Life Custom Scrollbar
green-life-custom-scrollbar
Allows you to change browser default scrollbar with a customizable morden scrollbar.
Nicescrollr Developer Profile
3 plugins · 150 total installs
How We Detect Nicescrollr
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/nicescrollr/admin/css/admin.css/wp-content/plugins/nicescrollr/admin/js/admin.js/wp-content/plugins/nicescrollr/public/css/nicescrollr.css/wp-content/plugins/nicescrollr/public/js/nicescrollr.jsnicescrollr/admin/css/admin.css?ver=nicescrollr/admin/js/admin.js?ver=nicescrollr/public/css/nicescrollr.css?ver=nicescrollr/public/js/nicescrollr.js?ver=HTML / DOM Fingerprints
nsr-adminnsr-settings-pagensr-form-fieldnsr-settings-groupnsr-backtop-form-fieldnsr-backtop-settings-groupnsr-backtop-optionsnsr-nicescroll-optionsNicescrollrAdminNicescrollr