Scrollbar Designer Security & Risk Analysis

wordpress.org/plugins/scrollbar-designer

Get rid of boring scrollbar and make your own Custom Scrollbar for your website.

100 active installs v2.1 PHP + WP 3.0+ Updated Oct 27, 2015
adminappearancecustom-scrollcustom-scroll-barcustom-scroll-bars
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Scrollbar Designer Safe to Use in 2026?

Generally Safe

Score 85/100

Scrollbar Designer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The security posture of the scrollbar-designer plugin v2.1 appears to be generally strong based on the provided static analysis. The plugin demonstrates good practices by having zero identified entry points, meaning it does not expose AJAX handlers, REST API routes, shortcodes, or cron events directly to user interaction. The absence of dangerous functions and file operations, coupled with the exclusive use of prepared statements for SQL queries, further indicates a commitment to secure coding. However, a significant concern arises from the low rate of properly escaped output (6%). This suggests that a substantial amount of data rendered by the plugin might be vulnerable to Cross-Site Scripting (XSS) attacks if user-supplied or dynamically generated content is not adequately sanitized before display. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive indicator of past security diligence. Despite the absence of known vulnerabilities, the output escaping issue presents a tangible risk that should be addressed. In conclusion, while the plugin has a solid foundation in terms of attack surface and core security features, the inadequate output escaping is a critical weakness that lowers its overall security rating.

Key Concerns

  • Low output escaping (6%)
Vulnerabilities
None known

Scrollbar Designer Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Scrollbar Designer Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
15
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

6% escaped16 total outputs
Attack Surface

Scrollbar Designer Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionwp_headscrollbar-action.php:2
actionadmin_menuscrollbar-designer-settings-page.php:3
actionadmin_initscrollbar-designer-settings-page.php:7
actionwp_enqueue_scriptsscrollbar-designer-settings-page.php:38
actionadmin_enqueue_scriptsscrollbar-designer-settings-page.php:46
filterplugin_action_linksscrollbar-designer-settings-page.php:635
Maintenance & Trust

Scrollbar Designer Maintenance & Trust

Maintenance Signals

WordPress version tested4.3.34
Last updatedOct 27, 2015
PHP min version
Downloads13K

Community Trust

Rating92/100
Number of ratings8
Active installs100
Developer Profile

Scrollbar Designer Developer Profile

Zia Imtiaz

2 plugins · 3K total installs

73
trust score
Avg Security Score
91/100
Avg Patch Time
94 days
View full developer profile
Detection Fingerprints

How We Detect Scrollbar Designer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/scrollbar-designer/js/jquery.nicescroll.min.js/wp-content/plugins/scrollbar-designer/js/color-picker.js

HTML / DOM Fingerprints

CSS Classes
onoffswitchonoffswitch-checkboxonoffswitch-labelonoffswitch-inneronoffswitch-switch
Data Attributes
data-nice-scroll
JS Globals
nice
FAQ

Frequently Asked Questions about Scrollbar Designer