Scroll Up Security & Risk Analysis

wordpress.org/plugins/scroll-up

Scroll Up plugin is a nice,lightweight and attractive wordpress plugin for 'Scroll to top/Back to top' one click. Happy scrolling....

100 active installs v1.1.0 PHP + WP 3.9+ Updated Sep 21, 2014
jquery-scroll-upscroll-to-topscroll-upwordpress-scroll-up
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Scroll Up Safe to Use in 2026?

Generally Safe

Score 85/100

Scroll Up has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The 'scroll-up' plugin version 1.1.0 exhibits a generally good security posture from the perspective of its attack surface, with no identified AJAX handlers, REST API routes, shortcodes, or cron events. This significantly limits the potential entry points for attackers. Furthermore, the absence of dangerous functions and file operations is a positive indicator. However, the static analysis reveals a critical concern regarding output escaping, as 100% of the identified outputs are not properly escaped. This means that any data displayed by the plugin, if it originates from an untrusted source, could be vulnerable to cross-site scripting (XSS) attacks. The lack of nonce and capability checks also contributes to this risk, as there are no built-in mechanisms to verify user authorization or the integrity of requests before processing data. The plugin's vulnerability history is clean, with no recorded CVEs, which suggests that historically, it has not been a significant target or source of vulnerabilities. However, this clean history, coupled with the identified output escaping issue, could indicate that the plugin has not undergone thorough security auditing or that potential vulnerabilities have simply not been discovered or exploited yet. While the limited attack surface is a strength, the unescaped output presents a tangible risk that should be addressed.

Key Concerns

  • 100% of outputs are not properly escaped
  • No nonce checks present
  • No capability checks present
Vulnerabilities
None known

Scroll Up Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Scroll Up Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped4 total outputs
Attack Surface

Scroll Up Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actioninitscroll_to_top.php:41
actionwp_headscroll_to_top.php:71
actionadmin_menuscroll_to_top.php:78
actionadmin_initscroll_to_top.php:95
Maintenance & Trust

Scroll Up Maintenance & Trust

Maintenance Signals

WordPress version tested4.0.38
Last updatedSep 21, 2014
PHP min version
Downloads5K

Community Trust

Rating96/100
Number of ratings5
Active installs100
Developer Profile

Scroll Up Developer Profile

Babu

1 plugin · 100 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Scroll Up

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/scroll-up/css/style.css/wp-content/plugins/scroll-up/js/jquery.scrollUp.js
Script Paths
/wp-content/plugins/scroll-up/js/jquery.scrollUp.js
Version Parameters
scroll-up/style.css?ver=scroll-up/jquery.scrollUp.js?ver=

HTML / DOM Fingerprints

JS Globals
morshed_scroll_top_options
FAQ

Frequently Asked Questions about Scroll Up