
Scroll Page To Top Security & Risk Analysis
wordpress.org/plugins/scroll-page-to-topScroll Page To Top is a lightweight plugin that helps to add "Scroll to top / Back to top / Scroll Page to Top / Bottom to top" feature in y …
Is Scroll Page To Top Safe to Use in 2026?
Generally Safe
Score 100/100Scroll Page To Top has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "scroll-page-to-top" plugin v1.0.1 presents a mixed security posture. On the positive side, it exhibits a very small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, all SQL queries are properly prepared, and there are no external HTTP requests or file operations, indicating good practices in these areas. However, the static analysis reveals significant concerns, most notably the presence of the `unserialize` function without any apparent sanitization or checks, which is a critical security risk. The low percentage of properly escaped output (8%) suggests a potential for Cross-Site Scripting (XSS) vulnerabilities. The complete absence of nonce and capability checks on any potential entry points (though none were identified in this analysis) is also a weakness, as it leaves the door open for unauthorized actions if any entry points were to be discovered or added in future versions. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive indicator. This suggests either a history of secure development or a lack of scrutiny. In conclusion, while the plugin's current attack surface is minimal and it avoids common pitfalls like raw SQL, the critical `unserialize` function and poor output escaping introduce substantial risks that require immediate attention. The lack of fundamental security checks like nonces and capability checks, even with a small attack surface, should be addressed to improve its overall security resilience.
Key Concerns
- Use of unserialize function
- Low percentage of output escaping
- No nonce checks
- No capability checks
Scroll Page To Top Security Vulnerabilities
Scroll Page To Top Code Analysis
Dangerous Functions Found
Output Escaping
Scroll Page To Top Attack Surface
WordPress Hooks 3
Maintenance & Trust
Scroll Page To Top Maintenance & Trust
Maintenance Signals
Community Trust
Scroll Page To Top Alternatives
WPFront Scroll Top
wpfront-scroll-top
Adds a lightweight and smooth "Scroll to Top" button to your WordPress site, improving navigation and user experience with customizable options.
Smooth Back To Top Button
smooth-back-to-top-button
Smooth Back To Top button with scroll progress indicator.
Scroll To Top
scroll-top
Automatically adds a flexible Back to Top button to your WordPress website that allows your visitor to scroll back to the top of your page with one cl …
jQuery Smooth Scroll
jquery-smooth-scroll
Activate the plugin for smooth scrolling and smooth "back to top" feature.
Scroll Back To Top
scroll-back-to-top
This plugin will add a button that allows users to scroll smoothly to the top of the page.
Scroll Page To Top Developer Profile
2 plugins · 20 total installs
How We Detect Scroll Page To Top
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/scroll-page-to-top/js/jquery.scrollUp.min.js/wp-content/plugins/scroll-page-to-top/js/jquery.scrollUp.min.jsscroll-page-to-top/js/jquery.scrollUp.min.js?ver=HTML / DOM Fingerprints
rps_scroll_page_to_topdata-rps_scroll_page_to_top_settingsrps_scroll_page_to_top