Scroll To Top or Bottom Security & Risk Analysis

wordpress.org/plugins/scroll-to-top-or-bottom

Easy to use scroll to top and bottom plugin.

70 active installs v1.0.1 PHP + WP 3.9+ Updated Nov 24, 2014
go-to-topscroll-buttonscroll-to-bottomscroll-to-top
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Scroll To Top or Bottom Safe to Use in 2026?

Generally Safe

Score 85/100

Scroll To Top or Bottom has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the "scroll-to-top-or-bottom" plugin version 1.0.1 exhibits an excellent security posture. The absence of any identified entry points (AJAX handlers, REST API routes, shortcodes, cron events) significantly limits the potential attack surface. Furthermore, the code analysis reveals a strong adherence to secure coding practices, with no dangerous functions, all SQL queries utilizing prepared statements, and 100% output escaping. The absence of file operations and external HTTP requests further reduces potential security risks.

The taint analysis shows no identified flows with unsanitized paths, indicating that data processing within the plugin is likely secure. The vulnerability history is also a significant positive, with zero recorded CVEs, meaning there are no known exploits or security flaws associated with this plugin. This suggests a well-developed and maintained plugin.

In conclusion, the "scroll-to-top-or-bottom" plugin version 1.0.1 appears to be highly secure. The lack of any identified vulnerabilities or weaknesses in the static analysis, combined with a clean vulnerability history, indicates a robust security implementation. While the plugin has no apparent security issues, the overall lack of critical security features like nonce or capability checks might be a minor concern in broader contexts, but given the minimal attack surface and absence of exploitable code, it does not represent a significant risk for this specific plugin.

Key Concerns

  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

Scroll To Top or Bottom Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Scroll To Top or Bottom Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Scroll To Top or Bottom Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionwp_enqueue_scriptsTotop.php:44
actionwp_footerTotop.php:53
Maintenance & Trust

Scroll To Top or Bottom Maintenance & Trust

Maintenance Signals

WordPress version tested4.0.38
Last updatedNov 24, 2014
PHP min version
Downloads3K

Community Trust

Rating86/100
Number of ratings3
Active installs70
Developer Profile

Scroll To Top or Bottom Developer Profile

ifte.hsn2013

2 plugins · 100 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Scroll To Top or Bottom

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/scroll-to-top-or-bottom/js/jquery.totop.js/wp-content/plugins/scroll-to-top-or-bottom/js/toTopScript.js/wp-content/plugins/scroll-to-top-or-bottom/css/totop.css
Version Parameters
jquery.totop.js?ver=1.0toTopScript.js?ver=1.0totop.css?ver=1.0.5

HTML / DOM Fingerprints

Shortcode Output
<div id="totopscroller"> </div>
FAQ

Frequently Asked Questions about Scroll To Top or Bottom