
R Scroll Up Security & Risk Analysis
wordpress.org/plugins/r-scroll-upR-Scroll-Up plugin is Simple wordpress plugin for scroll to top one click.
Is R Scroll Up Safe to Use in 2026?
Generally Safe
Score 85/100R Scroll Up has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'r-scroll-up' v1.0 plugin exhibits a strong overall security posture, with no apparent attack surface exposed through common WordPress entry points like AJAX handlers, REST API routes, shortcodes, or cron events. The code also demonstrates good practices by exclusively using prepared statements for its SQL queries and performing no file operations or external HTTP requests. Furthermore, there are no known vulnerabilities or CVEs associated with this plugin, suggesting a history of responsible development and maintenance.
However, a significant concern arises from the complete lack of output escaping. With 22 outputs identified and none properly escaped, this plugin presents a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. Any dynamic content rendered by the plugin could be manipulated by an attacker to inject malicious scripts, which would then be executed in the user's browser. Additionally, the absence of nonce and capability checks, even though the attack surface is currently zero, means that if new entry points were introduced without proper security measures, they would be immediately unprotected. This lack of foundational security checks is a critical weakness.
In conclusion, while the plugin's current attack surface is minimal and its SQL practices are commendable, the pervasive lack of output escaping creates a high-risk environment for XSS attacks. The absence of nonce and capability checks, though not exploitable currently, points to a potential oversight in fundamental security principles. A balanced assessment is that the plugin is well-structured in some areas but has a critical flaw in output handling that must be addressed.
Key Concerns
- No output escaping
- No nonce checks
- No capability checks
R Scroll Up Security Vulnerabilities
R Scroll Up Code Analysis
Output Escaping
R Scroll Up Attack Surface
WordPress Hooks 7
Maintenance & Trust
R Scroll Up Maintenance & Trust
Maintenance Signals
Community Trust
R Scroll Up Alternatives
Scroll Up
scroll-up
Scroll Up plugin is a nice,lightweight and attractive wordpress plugin for 'Scroll to top/Back to top' one click. Happy scrolling....
SINM Scroll To Top
sinm-scroll-to-top
This is First sinm simple scroll to top plugin. When visitor scroll bottom then show a simple scroll up arrow button and click to get top to the pag …
BH Scroll Top
bh-scroll-top
This plugin will add a scroll top feature in your site.
WPFront Scroll Top
wpfront-scroll-top
Adds a lightweight and smooth "Scroll to Top" button to your WordPress site, improving navigation and user experience with customizable options.
Scroll Back To Top Button
scrollup-master
This is just a very simple plugin to have a scroll back to top button throughout your whole blog/site.
R Scroll Up Developer Profile
2 plugins · 40 total installs
How We Detect R Scroll Up
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.