Scroll to top | inventivo Security & Risk Analysis

wordpress.org/plugins/scroll-to-top-inventivo

Display a scroll to top button at page bottom

10 active installs v1.0.5 PHP + WP 3.0+ Updated Aug 22, 2023
scroll-top
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Scroll to top | inventivo Safe to Use in 2026?

Generally Safe

Score 85/100

Scroll to top | inventivo has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "scroll-to-top-inventivo" v1.0.5 plugin exhibits a strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits its attack surface, and all entry points are effectively zero. The code itself shows good practices with no dangerous functions or direct SQL queries, indicating a reliance on secure database operations. A high percentage of output is properly escaped, further reducing the risk of cross-site scripting (XSS) vulnerabilities. Taint analysis reveals no flows with unsanitized paths, which is a positive indicator for preventing code injection and other critical vulnerabilities.

The plugin's vulnerability history is clean, with zero known CVEs and no recorded past issues. This suggests a history of secure development or proactive patching by the developers. While the lack of identified entry points and vulnerability history are significant strengths, the absence of nonce checks and capability checks, though not immediately exploitable due to the lack of attack surface, represents a missed opportunity for defensive programming. If future versions introduce new entry points without these checks, it could create vulnerabilities. Overall, the plugin appears to be very secure in its current state, with the primary areas for improvement being the consistent implementation of security checks for any future expansion of its functionality.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Scroll to top | inventivo Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Scroll to top | inventivo Release Timeline

v1.0.5Current
v1.0.4
v1.0.3
v1.0.2
v1.0.1
v1.0.0
v0.0.5
v0.0.4
Code Analysis
Analyzed Apr 16, 2026

Scroll to top | inventivo Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
22 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

85% escaped26 total outputs
Attack Surface

Scroll to top | inventivo Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 16
actionadmin_enqueue_scriptsinventivo-scroll-to-top.php:40
actionwp_enqueue_scriptsinventivo-scroll-to-top.php:41
actionwp_enqueue_scriptsinventivo-scroll-to-top.php:42
actionplugins_loadedinventivo-scroll-to-top.php:56
actionadmin_menuinventivo-scroll-to-top.php:58
actionadmin_initinventivo-scroll-to-top.php:59
actionadmin_noticesinventivo-scroll-to-top.php:60
actionadmin_enqueue_scriptsinventivo-scroll-to-top.php:61
actionadmin_enqueue_scriptstrunk/inventivo-scroll-to-top.php:40
actionwp_enqueue_scriptstrunk/inventivo-scroll-to-top.php:41
actionwp_enqueue_scriptstrunk/inventivo-scroll-to-top.php:42
actionplugins_loadedtrunk/inventivo-scroll-to-top.php:56
actionadmin_menutrunk/inventivo-scroll-to-top.php:58
actionadmin_inittrunk/inventivo-scroll-to-top.php:59
actionadmin_noticestrunk/inventivo-scroll-to-top.php:60
actionadmin_enqueue_scriptstrunk/inventivo-scroll-to-top.php:61
Maintenance & Trust

Scroll to top | inventivo Maintenance & Trust

Maintenance Signals

WordPress version tested6.3.8
Last updatedAug 22, 2023
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Scroll to top | inventivo Developer Profile

Nils Harder

7 plugins · 290 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Scroll to top | inventivo

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/scroll-to-top-inventivo/public/css/scroll-to-top.css/wp-content/plugins/scroll-to-top-inventivo/public/css/genericons.css/wp-content/plugins/scroll-to-top-inventivo/public/js/scroll-to-top.js
Script Paths
/wp-content/plugins/scroll-to-top-inventivo/public/js/scroll-to-top.js
Version Parameters
scroll-to-top-inventivo/public/css/scroll-to-top.css?ver=scroll-to-top-inventivo/public/css/genericons.css?ver=scroll-to-top-inventivo/public/js/scroll-to-top.js?ver=

HTML / DOM Fingerprints

CSS Classes
inventivo-scroll-to-top-button
Data Attributes
data-background_colordata-icon_colordata-alignment
JS Globals
invscrolltotopoptions
FAQ

Frequently Asked Questions about Scroll to top | inventivo