RRF Scroll to top Security & Risk Analysis

wordpress.org/plugins/rrf-scroll-to-top

This plugin will automaticaly add a scroll to top on bottom right.

200 active installs v1.1 PHP + WP 3.3+ Updated May 18, 2013
scrollscroll-to-top
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is RRF Scroll to top Safe to Use in 2026?

Generally Safe

Score 85/100

RRF Scroll to top has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

Based on the static analysis and vulnerability history provided, the 'rrf-scroll-to-top' plugin version 1.1 exhibits a strong security posture. The absence of dangerous functions, raw SQL queries, unescaped output, file operations, external HTTP requests, and the presence of prepared statements for all SQL queries indicate good development practices for secure coding. The zero-count for known CVEs and the lack of any recorded vulnerabilities in its history further suggest a well-maintained and secure plugin.

The analysis reveals no obvious attack vectors through AJAX, REST API, shortcodes, or cron events, and importantly, all identified entry points (of which there are none) are considered protected. The taint analysis also shows no critical or high severity issues, reinforcing the perception of a safe plugin. The plugin's strengths lie in its minimal attack surface and its adherence to secure coding principles in the areas that were analyzed.

While the plugin appears secure based on this snapshot, it's important to note that the static analysis reported zero entry points. If the plugin's core functionality relies on mechanisms not covered by this analysis (e.g., complex client-side JavaScript interactions that might not be fully reflected in server-side code scans), there could be potential blind spots. However, given the data, the overall security risk is assessed as very low.

Vulnerabilities
None known

RRF Scroll to top Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

RRF Scroll to top Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

RRF Scroll to top Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actioninitplugin-hook.php:16
actioninitplugin-hook.php:23
actioninitplugin-hook.php:30
actionwp_enqueue_scriptsplugin-hook.php:37
Maintenance & Trust

RRF Scroll to top Maintenance & Trust

Maintenance Signals

WordPress version tested3.5.2
Last updatedMay 18, 2013
PHP min version
Downloads8K

Community Trust

Rating96/100
Number of ratings34
Active installs200
Developer Profile

RRF Scroll to top Developer Profile

raselahmed7

3 plugins · 310 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect RRF Scroll to top

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/rrf-scroll-to-top/js/jquery.scrollUp.min.js/wp-content/plugins/rrf-scroll-to-top/js/active.js/wp-content/plugins/rrf-scroll-to-top/css/custom.css
Script Paths
/wp-content/plugins/rrf-scroll-to-top/js/jquery.scrollUp.min.js/wp-content/plugins/rrf-scroll-to-top/js/active.js

HTML / DOM Fingerprints

CSS Classes
scrollUp
JS Globals
scrollUp
FAQ

Frequently Asked Questions about RRF Scroll to top