
Parallax Scrolling Enllax.js Security & Risk Analysis
wordpress.org/plugins/parallax-scrolling-enllax-jsParallax Scrolling Effect on your page.
Is Parallax Scrolling Enllax.js Safe to Use in 2026?
High Risk
Score 42/100Parallax Scrolling Enllax.js carries significant security risk with 2 known CVEs, 2 still unpatched. Consider switching to a maintained alternative.
The 'parallax-scrolling-enllax-js' v0.0.6 plugin presents a mixed security posture. While it exhibits strengths such as the absence of dangerous functions, a complete reliance on prepared statements for SQL queries, and no external HTTP requests or file operations, significant concerns are raised by its output escaping and vulnerability history. The fact that 100% of its 24 output operations are not properly escaped creates a high risk for Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data could be injected directly into the page without sanitization. The lack of nonce checks and capability checks on its entry points, although currently presenting 0 unprotected entry points, is a concerning oversight that could be exploited if future code modifications expose these without proper authentication.
The plugin's vulnerability history is particularly alarming, with two currently unpatched medium severity CVEs. These historical vulnerabilities point towards a pattern of issues related to Cross-Site Request Forgery (CSRF) and XSS, suggesting recurring security weaknesses in how the plugin handles user input and state management. The presence of unpatched vulnerabilities indicates a lack of active maintenance and a failure to address known security flaws, leaving active installations vulnerable to exploitation. While the static analysis shows no critical taint flows and a limited direct attack surface, the combination of widespread unescaped output and a history of unpatched vulnerabilities warrants significant caution.
Key Concerns
- 2 unpatched medium severity CVEs
- 100% of outputs unescaped
- 0 nonce checks on entry points
- 0 capability checks on entry points
Parallax Scrolling Enllax.js Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Parallax Scrolling Enllax.js <= 0.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
Parallax Scrolling Enllax.js <= 0.0.6 - Cross-Site Request Forgery
Parallax Scrolling Enllax.js Code Analysis
Output Escaping
Parallax Scrolling Enllax.js Attack Surface
Shortcodes 3
WordPress Hooks 9
Maintenance & Trust
Parallax Scrolling Enllax.js Maintenance & Trust
Maintenance Signals
Community Trust
Parallax Scrolling Enllax.js Alternatives
Parallax Section Block – Add Parallax Scrolling Effects to Sections.
parallax-section
Add Parallax scrolling effects in any section of your website.
Parallax Image
parallax-image
Insert a full width parallax image into your page with this simple shortcode. Parameters allow for setting several key functions like height
Parallax Scroll by adamrob.co.uk
adamrob-parallax-scroll
Create a header, or custom post/page with a scrolling parallax background. All with a simple shortcode.
Parallax Scroll – Parallax Scrolling Backgrounds & Call to Action WordPress Plugin
parallax-scroll-wp
Enhance your WordPress website with dynamic parallax scrolling backgrounds. Parallax Scroll WP offers an easy way to create visually appealing and eng …
Parallaxer for Elementor
parallaxer-for-elementor
Add smooth parallax scrolling effects to any Elementor widget using the lightweight Rellax.js and lenis.js libraries.
Parallax Scrolling Enllax.js Developer Profile
2 plugins · 310 total installs
How We Detect Parallax Scrolling Enllax.js
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/parallax-scrolling-enllax-js/demo.jpgHTML / DOM Fingerprints
enllaxdata-enllax-bgoffsetdata-enllax-ratiodata-enllax-direction[enllax [enllaxend][enllax_post