Skysa Scroll-to-Top App Security & Risk Analysis

wordpress.org/plugins/skysa-scroll-to-top-app

Animated scroll-to-top, button floats unobtrusively at the bottom of your site. A great convenience feature for your visitors.

10 active installs v1.4 PHP + WP 2.7+ Updated Sep 8, 2014
scrollscroll-to-topscroll-upskysaskysa-apps
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Skysa Scroll-to-Top App Safe to Use in 2026?

Generally Safe

Score 85/100

Skysa Scroll-to-Top App has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The skysa-scroll-to-top-app v1.4 plugin exhibits a concerning security posture primarily due to its unprotected entry points and lack of robust input sanitization and output escaping. The static analysis reveals two AJAX handlers with no authentication checks, creating a significant attack surface for unauthorized actions. Furthermore, all SQL queries are executed without prepared statements, increasing the risk of SQL injection vulnerabilities. The taint analysis highlights four flows with unsanitized paths, indicating potential for various injection attacks, although these did not reach critical or high severity in the provided analysis.

The plugin's vulnerability history is clean, with no recorded CVEs. While this is a positive sign, it does not negate the inherent risks identified in the code analysis. The absence of vulnerabilities could be due to a lack of rigorous security auditing of the plugin or the fact that discovered flaws were minor and not publicly disclosed. The overall security of this plugin is weakened by the presence of direct, unauthenticated access points and the insecure handling of data, despite its clean historical record.

Key Concerns

  • AJAX handlers without auth checks
  • SQL queries without prepared statements
  • Taint flows with unsanitized paths
  • Low percentage of properly escaped output
  • No nonce checks on AJAX handlers
  • No capability checks on AJAX handlers
Vulnerabilities
None known

Skysa Scroll-to-Top App Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Skysa Scroll-to-Top App Code Analysis

Dangerous Functions
0
Raw SQL Queries
4
0 prepared
Unescaped Output
22
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared4 total queries

Output Escaping

4% escaped23 total outputs
Data Flows
4 unsanitized

Data Flow Analysis

4 flows4 with unsanitized paths
SkysaApps_Admin_DrawTabs (skysa-required\admin.php:168)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Skysa Scroll-to-Top App Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_skysa_apploadskysa-required\index.php:111
noprivwp_ajax_skysa_apploadskysa-required\index.php:112
WordPress Hooks 3
actionwp_print_footer_scriptsskysa-required\index.php:103
actionwp_footerskysa-required\index.php:105
actionadmin_menuskysa-required\index.php:109
Maintenance & Trust

Skysa Scroll-to-Top App Maintenance & Trust

Maintenance Signals

WordPress version tested4.0.38
Last updatedSep 8, 2014
PHP min version
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Skysa Scroll-to-Top App Developer Profile

Skysa

8 plugins · 80 total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Skysa Scroll-to-Top App

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/skysa-scroll-to-top-app/icons/up-icon-wp.png/wp-content/plugins/skysa-scroll-to-top-app/skysa-required/css/skysa-required.css
Script Paths
/wp-content/plugins/skysa-scroll-to-top-app/skysa-required/js/skysa-required.js
Version Parameters
skysa-scroll-to-top-app/style.css?ver=skysa-scroll-to-top-app/skysa-required/js/skysa-required.js?ver=

HTML / DOM Fingerprints

CSS Classes
bar-buttonSKYUI-menuoff
HTML Comments
This app was made using the: Skysa App SDK http://wordpress.org/extend/plugins/skysa-app-sdk/ *************************************************************Skysa App SDK version 2.0 Download the latest version here: http://wordpress.org/extend/plugins/skysa-app-sdk/ ************************************************************* * Direct modification of this file for a production plugin * is not recommended, due to incompatibilites it could * cause for other plugins using this SDK. * Instead it is remmended that you contact and submit your * proposed changes to Skysa's staff at staff@skysa.com. * Your proposed changes can then be reviewed for inclusion * in the next version of the SDK, which will be made * available to you and publically available for use in * creation of new plugins and to update old ones. * * When these core files are included with plugins made * using this SDK, the loader file will choose the most * recent version of the core files to use. So it is very * important that any changes made are updated in a version * change in the core SDK. This will ensure that your plugn, * as well as other plugins, will not be broken by the * installation of any others on the same site. * * Thank you for taking this into consideration, and feel * free to contact staff@sksya.com with any questions. You * may also contact Skysa here: * http://www.skysa.com/page/contact * * Please include these comments with any redistribution. *************************************************************This program is free software; you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation; either version 2 of the License, or (at your option) any later version.This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details.+1 more
Data Attributes
apptitleid="$button_id"class="bar-button SKYUI-menuoff"name="bar_label"id="field-bar_label"size="30|1"+6 more
JS Globals
window.Swindow.YUI2var Svar YUI2
FAQ

Frequently Asked Questions about Skysa Scroll-to-Top App