Scroll To Security & Risk Analysis

wordpress.org/plugins/scroll-to

Block element of scroll to top or a specific HTML element.

0 active installs v1.0.2 PHP 7.0+ WP 6.1+ Updated Feb 18, 2024
block-editorgutenbergscroll-to-html-elementscroll-to-top
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Scroll To Safe to Use in 2026?

Generally Safe

Score 85/100

Scroll To has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The 'scroll-to' plugin v1.0.2 exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of any identified dangerous functions, raw SQL queries, unescaped output, file operations, external HTTP requests, or critical taint flows is highly positive. Furthermore, the plugin has no recorded CVEs, indicating a history of secure development or effective patching. The attack surface is effectively zero, with no AJAX handlers, REST API routes, shortcodes, or cron events, meaning there are no direct entry points for attackers to exploit.

However, the analysis also reveals a complete lack of any security checks, including nonce checks and capability checks. While the current implementation has no exploitable entry points and no known vulnerabilities, this lack of authorization and input validation mechanisms represents a significant concern. If the plugin were to be updated in the future to include any of these entry points without proper security controls, it would be highly susceptible to attacks. The plugin's current security relies entirely on its lack of functionality rather than robust security implementations.

In conclusion, while 'scroll-to' v1.0.2 is currently secure due to its minimal attack surface and clean code, its security is fragile. The complete absence of any security checks is a substantial weakness. The plugin demonstrates good practices in avoiding common pitfalls like raw SQL and unescaped output, but the lack of any authorization or input validation mechanisms means it is not inherently secure if its functionality were to expand. This plugin is safe for now, but future development needs to incorporate robust security controls.

Key Concerns

  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

Scroll To Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Scroll To Release Timeline

v1.0.2Current
v1.0.1
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

Scroll To Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Scroll To Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actioninitscroll-to.php:30
Maintenance & Trust

Scroll To Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedFeb 18, 2024
PHP min version7.0
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Scroll To Developer Profile

hcoz

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Scroll To

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/scroll-to/build/index.css/wp-content/plugins/scroll-to/build/index.js
Script Paths
/wp-content/plugins/scroll-to/build/index.js
Version Parameters
scroll-to/build/index.css?ver=scroll-to/build/index.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Scroll To