
Scroll to Top Button Security & Risk Analysis
wordpress.org/plugins/scroll-to-top-buttonDisplays a button in the bottom right corner for smooth scrolling to the top of the page.
Is Scroll to Top Button Safe to Use in 2026?
Generally Safe
Score 85/100Scroll to Top Button has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "scroll-to-top-button" v1.1 plugin exhibits a generally positive security posture based on the provided static analysis and vulnerability history. The absence of reported CVEs and the plugin's focus on preventing SQL injection through prepared statements are significant strengths. The static analysis indicates a very small attack surface with no discoverable AJAX handlers, REST API routes, shortcodes, or cron events, and crucially, none of these are unprotected. This lack of entry points significantly reduces the potential for external exploitation.
However, there are areas for improvement. The output escaping is only 50% properly handled, meaning that half of the plugin's outputs are not being sanitized. This could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is directly echoed into the output. The complete absence of nonce and capability checks, while not immediately exploitable due to the limited attack surface, represents a missed opportunity to reinforce security and could become a concern if the plugin were to evolve and introduce new entry points without these fundamental security measures.
In conclusion, while the plugin is currently very low risk due to its minimal attack surface and clean vulnerability history, the unescaped output is a notable weakness that should be addressed. The lack of nonce and capability checks, though not a direct vulnerability in this version, indicates a potential area for future security hardening.
Key Concerns
- Half of outputs are not properly escaped
- No nonce checks implemented
- No capability checks implemented
Scroll to Top Button Security Vulnerabilities
Scroll to Top Button Code Analysis
Output Escaping
Scroll to Top Button Attack Surface
WordPress Hooks 3
Maintenance & Trust
Scroll to Top Button Maintenance & Trust
Maintenance Signals
Community Trust
Scroll to Top Button Alternatives
Simple Scroll Up Button
simple-scroll-up-button
Simple Scroll Up Button is a lightweight plugin which adds a simple scroll up button on the page of your WordPress website.
Easy Back To Top Button
easy-back-to-top-button
Add a customizable, lightweight "Back to Top" button to enhance your website's usability and accessibility.
Jiali Scroll to Top Button
jiali-scroll-to-top-button
A lightweight, customizable "Scroll to Top" button for WordPress. Smooth scrolling, adjustable styles, and easy setup—no coding needed! 🚀
WPFront Scroll Top
wpfront-scroll-top
Adds a lightweight and smooth "Scroll to Top" button to your WordPress site, improving navigation and user experience with customizable options.
Smooth Back To Top Button
smooth-back-to-top-button
Smooth Back To Top button with scroll progress indicator.
Scroll to Top Button Developer Profile
1 plugin · 1K total installs
How We Detect Scroll to Top Button
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/scroll-to-top-button/assets/css/style.css/wp-content/plugins/scroll-to-top-button/assets/js/scroll-to-top.js/wp-content/plugins/scroll-to-top-button/assets/js/scroll-to-top.jsscroll-to-top-button/assets/css/style.css?ver=scroll-to-top-button/assets/js/scroll-to-top.js?ver=HTML / DOM Fingerprints
id="scroll_to_top_button_scheme"name="scroll_to_top_button_option[scheme]"id="scroll_to_top_button_size"name="scroll_to_top_button_option[size]"scrollTopParams