
Scroll Highlight – catch the eye of your visitors while they scroll Security & Risk Analysis
wordpress.org/plugins/scroll-highlighterScrollHighlight plugin will make a block of your choose to be highlighted (while background will be blacked out) on scroll.
Is Scroll Highlight – catch the eye of your visitors while they scroll Safe to Use in 2026?
Generally Safe
Score 85/100Scroll Highlight – catch the eye of your visitors while they scroll has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "scroll-highlighter" plugin version 0.1.2 exhibits a strong security posture based on the provided static analysis. The absence of any identified attack surface, including AJAX handlers, REST API routes, shortcodes, or cron events, significantly limits potential entry points for malicious actors. Furthermore, the code demonstrates good practices by exclusively using prepared statements for SQL queries and having no file operations or external HTTP requests, reducing common vulnerability vectors. The substantial percentage of properly escaped output (73%) is also a positive indicator.
However, a notable concern is the complete absence of nonce and capability checks across all analyzed code. While the current attack surface is zero, this lack of fundamental WordPress security mechanisms means that if any new entry points were introduced in future versions, they would likely be unprotected. The taint analysis showing zero flows is excellent but relies on the limited scope of the analysis. The plugin's vulnerability history is clean, with no recorded CVEs, suggesting a history of secure development. Overall, the plugin is currently secure due to its limited functionality and lack of direct user-facing interfaces, but the absence of basic security checks is a weakness that could become a significant risk if the plugin evolves.
Key Concerns
- No nonce checks found
- No capability checks found
- Output not properly escaped (27%)
Scroll Highlight – catch the eye of your visitors while they scroll Security Vulnerabilities
Scroll Highlight – catch the eye of your visitors while they scroll Code Analysis
Output Escaping
Scroll Highlight – catch the eye of your visitors while they scroll Attack Surface
WordPress Hooks 3
Maintenance & Trust
Scroll Highlight – catch the eye of your visitors while they scroll Maintenance & Trust
Maintenance Signals
Community Trust
Scroll Highlight – catch the eye of your visitors while they scroll Alternatives
WPFront Scroll Top
wpfront-scroll-top
Adds a lightweight and smooth "Scroll to Top" button to your WordPress site, improving navigation and user experience with customizable options.
MouseWheel Smooth Scroll
mousewheel-smooth-scroll
Smooth scrolling experience, with mousewheel, touchpad or keyboard
Page scroll to id
page-scroll-to-id
Create links that scroll the page smoothly to any id within the document.
To Top
to-top
To Top is a nifty lightweight plugin. It adds a highly customizable button, which when clicked, scrolls up smoothly to the top of a page.
Ajax Load More – Infinite Scroll, Load More, & Lazy Load
ajax-load-more
Add infinite scroll, lazy loading, and load more buttons to posts, pages, and WooCommerce products — fast and fully customizable for WordPress.
Scroll Highlight – catch the eye of your visitors while they scroll Developer Profile
1 plugin · 10 total installs
How We Detect Scroll Highlight – catch the eye of your visitors while they scroll
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/scroll-highlighter/scrollhighlight.phpHTML / DOM Fingerprints
scrollhighlight-wrapscrollhighlight-innerscrollhighlight-previewscorllheight-preview-elementscorllheight-preview-mainscrollhighlight-position-topscrollhighlight-position-centerscrollhighlight-position-bottom+4 morename="scrollhighlight_selector"name="scrollhighlight_el_color"name="scrollhighlight_color"name="scrollhighlight_opacity"name="scrollhighlight_offset_type"name="scrollhighlight_offset"+3 more