Parallax Scrolling Enllax.js Security & Risk Analysis

wordpress.org/plugins/parallax-scrolling-enllax-js

Parallax Scrolling Effect on your page.

300 active installs v0.0.6 PHP + WP 4.0+ Updated Mar 18, 2019
parallaxparallax-imageresponsiveresponsive-parallaxscroll
42
D · High Risk
CVEs total2
Unpatched2
Last CVESep 5, 2025
Safety Verdict

Is Parallax Scrolling Enllax.js Safe to Use in 2026?

High Risk

Score 42/100

Parallax Scrolling Enllax.js carries significant security risk with 2 known CVEs, 2 still unpatched. Consider switching to a maintained alternative.

2 known CVEs 2 unpatched Last CVE: Sep 5, 2025Updated 7yr ago
Risk Assessment

The 'parallax-scrolling-enllax-js' v0.0.6 plugin presents a mixed security posture. While it exhibits strengths such as the absence of dangerous functions, a complete reliance on prepared statements for SQL queries, and no external HTTP requests or file operations, significant concerns are raised by its output escaping and vulnerability history. The fact that 100% of its 24 output operations are not properly escaped creates a high risk for Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data could be injected directly into the page without sanitization. The lack of nonce checks and capability checks on its entry points, although currently presenting 0 unprotected entry points, is a concerning oversight that could be exploited if future code modifications expose these without proper authentication.

The plugin's vulnerability history is particularly alarming, with two currently unpatched medium severity CVEs. These historical vulnerabilities point towards a pattern of issues related to Cross-Site Request Forgery (CSRF) and XSS, suggesting recurring security weaknesses in how the plugin handles user input and state management. The presence of unpatched vulnerabilities indicates a lack of active maintenance and a failure to address known security flaws, leaving active installations vulnerable to exploitation. While the static analysis shows no critical taint flows and a limited direct attack surface, the combination of widespread unescaped output and a history of unpatched vulnerabilities warrants significant caution.

Key Concerns

  • 2 unpatched medium severity CVEs
  • 100% of outputs unescaped
  • 0 nonce checks on entry points
  • 0 capability checks on entry points
Vulnerabilities
2

Parallax Scrolling Enllax.js Security Vulnerabilities

CVEs by Year

2 CVEs in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2025-58830medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Parallax Scrolling Enllax.js <= 0.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

Sep 5, 2025Unpatched
CVE-2025-58831medium · 4.3Cross-Site Request Forgery (CSRF)

Parallax Scrolling Enllax.js <= 0.0.6 - Cross-Site Request Forgery

Sep 5, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Parallax Scrolling Enllax.js Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
24
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped24 total outputs
Attack Surface

Parallax Scrolling Enllax.js Attack Surface

Entry Points3
Unprotected0

Shortcodes 3

[enllax] parallax-scrolling-enllax-js.php:127
[enllaxend] parallax-scrolling-enllax-js.php:133
[enllax_post] parallax-scrolling-enllax-js.php:160
WordPress Hooks 9
actionplugins_loadedparallax-scrolling-enllax-js.php:17
actionadmin_menuparallax-scrolling-enllax-js.php:36
actionadmin_initparallax-scrolling-enllax-js.php:37
actionwp_headparallax-scrolling-enllax-js.php:114
filtermanage_posts_columnsparallax-scrolling-enllax-js.php:136
actionmanage_posts_custom_columnparallax-scrolling-enllax-js.php:137
actionwp_footerparallax-scrolling-enllax-js.php:169
filtermce_external_pluginsparallax-scrolling-enllax-js.php:177
filtermce_buttonsparallax-scrolling-enllax-js.php:183
Maintenance & Trust

Parallax Scrolling Enllax.js Maintenance & Trust

Maintenance Signals

WordPress version tested5.1.22
Last updatedMar 18, 2019
PHP min version
Downloads75K

Community Trust

Rating100/100
Number of ratings3
Active installs300
Developer Profile

Parallax Scrolling Enllax.js Developer Profile

snagysandor

2 plugins · 310 total installs

69
trust score
Avg Security Score
64/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Parallax Scrolling Enllax.js

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/parallax-scrolling-enllax-js/demo.jpg

HTML / DOM Fingerprints

CSS Classes
enllax
Data Attributes
data-enllax-bgoffsetdata-enllax-ratiodata-enllax-direction
Shortcode Output
[enllax [enllaxend][enllax_post
FAQ

Frequently Asked Questions about Parallax Scrolling Enllax.js