
SN Scroll To Up Security & Risk Analysis
wordpress.org/plugins/sn-scroll-to-upThis plugin will be able to add a Scroll To Up Button in your Webside easily and so quickly.
Is SN Scroll To Up Safe to Use in 2026?
Generally Safe
Score 85/100SN Scroll To Up has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "sn-scroll-to-up" v1.0 plugin exhibits a generally good security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the complete lack of dangerous functions, file operations, and external HTTP requests is commendable. The use of prepared statements for all SQL queries is a strong indication of secure database interaction. However, a critical concern arises from the fact that 100% of the 27 output operations are not properly escaped. This means that any data displayed by the plugin, if it originates from user input or external sources, could be vulnerable to cross-site scripting (XSS) attacks. The lack of any recorded vulnerability history, while positive, doesn't entirely alleviate this risk as it could simply mean the plugin hasn't been extensively audited or targeted in the past.
Despite the minimal attack surface and secure database practices, the complete lack of output escaping presents a significant potential risk. This oversight could allow attackers to inject malicious scripts into pages where the plugin is active, leading to compromised user sessions, data theft, or defacement. While the plugin doesn't appear to have a history of vulnerabilities or exploit common weaknesses, the unescaped output is a clear and present danger that needs to be addressed. The absence of nonce and capability checks on potential entry points (even though none were found) is also a missed opportunity for defense-in-depth. Overall, the plugin is strong in its limited scope but has a glaring weakness in output handling.
Key Concerns
- All outputs unescaped
- No nonce checks on entry points
- No capability checks on entry points
SN Scroll To Up Security Vulnerabilities
SN Scroll To Up Code Analysis
Output Escaping
SN Scroll To Up Attack Surface
WordPress Hooks 7
Maintenance & Trust
SN Scroll To Up Maintenance & Trust
Maintenance Signals
Community Trust
SN Scroll To Up Alternatives
Scroll Back To Top Button
scrollup-master
This is just a very simple plugin to have a scroll back to top button throughout your whole blog/site.
Scroll UP
scroll-to-up
,bar, custom icon, fixed button scroller, go-to-top, notification bar, one click scroller, plugin, responsive button, responsive scroll to top button …
Ashch-scrollTop
ashch-scroll-top
Scroll Top is a WordPress plugin which make scroll to top customizable button.
SC Scrollup – Lightweight Scroll to Top Button
sc-scrollup
A lightweight, customizable, and GDPR-friendly 'Scroll to Top' button plugin. Enhances UX with smooth scrolling and Font Awesome icons.
WPBatch Scroll to Top
wpbatch-scroll-to-top
The Easiest Scroll to Top Plugin Ever..
SN Scroll To Up Developer Profile
1 plugin · 10 total installs
How We Detect SN Scroll To Up
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sn-scroll-to-up/js/jquery.scrollUp.min.js/wp-content/plugins/sn-scroll-to-up/js/jquery.easing.js/wp-content/plugins/sn-scroll-to-up/css/font-awesome.css/wp-content/plugins/sn-scroll-to-up/css/style.css/wp-content/plugins/sn-scroll-to-up/js/jquery.scrollUp.min.js/wp-content/plugins/sn-scroll-to-up/js/jquery.easing.jsHTML / DOM Fingerprints
color-field<!-- Drank some coffe! you are working with 1960's table --><!-- Add default value array. --><!-- Add setting option by used function. --><!-- Add register setting. -->+5 moreid="scroll_speed"name="sn_scrollup_options_default[scroll_speed]"id="scroll_distance"name="sn_scrollup_options_default[scroll_distance]"id="animation_speed"name="sn_scrollup_options_default[animation_speed]"+17 morevar $sn_scrollup_options_default