
scrollToTop Security & Risk Analysis
wordpress.org/plugins/scrolltotopCreate your own back to top button or full-height bar and simple customize it as you want.
Is scrollToTop Safe to Use in 2026?
Generally Safe
Score 85/100scrollToTop has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "scrolltotop" plugin v1.16 exhibits a very strong security posture based on the provided static analysis. The complete absence of exposed entry points like AJAX handlers, REST API routes, shortcodes, and cron events significantly reduces the plugin's attack surface. Furthermore, the code signals indicate robust security practices, with no dangerous functions identified, all SQL queries using prepared statements, and a high percentage of output being properly escaped. The absence of file operations and external HTTP requests also mitigates potential vulnerabilities. Taint analysis revealing no unsanitized paths further reinforces this positive assessment.
The plugin's vulnerability history is equally impressive, with no known CVEs ever recorded. This suggests a consistently secure development approach and a lack of recurring or significant security flaws over time. The combination of a minimal attack surface, diligent coding practices, and a clean vulnerability record points towards a plugin that is likely very safe to use. While the lack of capability checks and nonce checks on potential (though absent) entry points could be a concern in other contexts, given the complete absence of such entry points here, it doesn't represent a current risk.
In conclusion, "scrolltotop" v1.16 appears to be a highly secure plugin. Its strengths lie in its extremely limited attack surface and the evident care taken in its code to prevent common vulnerabilities. The absence of any historical vulnerabilities further bolsters confidence in its security. The only minor area for potential improvement, if entry points were ever to be introduced, would be the inclusion of capability and nonce checks for enhanced defense-in-depth.
scrollToTop Security Vulnerabilities
scrollToTop Code Analysis
Output Escaping
scrollToTop Attack Surface
WordPress Hooks 8
Maintenance & Trust
scrollToTop Maintenance & Trust
Maintenance Signals
Community Trust
scrollToTop Alternatives
WPFront Scroll Top
wpfront-scroll-top
Adds a lightweight and smooth "Scroll to Top" button to your WordPress site, improving navigation and user experience with customizable options.
Scroll Back To Top Button
scrollup-master
This is just a very simple plugin to have a scroll back to top button throughout your whole blog/site.
Click to top
click-to-top
A wordpress plugin to create a customisable Click To Top feature.
X-Scroll To Top – Responsive
x-scroll-to-top-responsive
X-Scroll To Top adds a customizable scroll-up button to your site. Personalize it to seamlessly match your design and enhance functionality.
Flexible Scroll Top
flexible-scroll-top
Add a slick, lightweight and customizable scroll to top button that uses SVG icon with no jQuery dependency.
scrollToTop Developer Profile
1 plugin · 200 total installs
How We Detect scrollToTop
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/scrolltotop/assets/js/scripts.min.js/wp-content/plugins/scrolltotop/assets/css/styles.min.cssassets/js/scripts.min.jsscrolltotop/assets/css/styles.min.css?ver=scrolltotop/assets/js/scripts.min.js?ver=HTML / DOM Fingerprints
stt-barstt-scroll-buttondata-stt-sticky-containerdata-stt-bar-stickydata-stt-advanced-bg-stickydata-stt-scroll-to-valuedata-stt-scroll-to-elementdata-stt-offset+33 morescrolltotop_dynamic_js_config