
sr-scroll-to-top-wp Security & Risk Analysis
wordpress.org/plugins/sr-scroll-to-top-wpEasily create and manage a page scroll to top
Is sr-scroll-to-top-wp Safe to Use in 2026?
Generally Safe
Score 85/100sr-scroll-to-top-wp has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'sr-scroll-to-top-wp' v1.0 plugin exhibits a generally positive security posture with no known vulnerabilities or critical code signals. The static analysis indicates a very small attack surface, with no identified AJAX handlers, REST API routes, shortcodes, or cron events, which significantly reduces the potential for external exploitation. Furthermore, all identified SQL queries utilize prepared statements, and there are no file operations or external HTTP requests, which are good practices for preventing common web vulnerabilities.
However, a significant concern arises from the complete lack of output escaping (0% properly escaped). This indicates that any dynamic content generated by the plugin is likely to be rendered directly to the user's browser without sanitization. This could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data or other dynamic content is incorporated into the plugin's output. Additionally, the absence of nonce and capability checks, while not immediately exploitable due to the limited attack surface, represents a lack of defensive programming that could become a risk if the plugin's functionality or attack surface expands in future versions.
In conclusion, while the plugin currently has no known vulnerabilities and adheres to good practices in areas like SQL handling and attack surface minimization, the critical lack of output escaping presents a clear and present danger for XSS. The absence of capability and nonce checks further reinforces the need for vigilance, especially if the plugin is updated or extended. Users should be aware of the potential for XSS and consider this a significant weakness.
Key Concerns
- No output escaping
- No capability checks
- No nonce checks
sr-scroll-to-top-wp Security Vulnerabilities
sr-scroll-to-top-wp Code Analysis
Output Escaping
sr-scroll-to-top-wp Attack Surface
WordPress Hooks 5
Maintenance & Trust
sr-scroll-to-top-wp Maintenance & Trust
Maintenance Signals
Community Trust
sr-scroll-to-top-wp Alternatives
Scroll To Top
scroll-top
Automatically adds a flexible Back to Top button to your WordPress website that allows your visitor to scroll back to the top of your page with one cl …
Scroll Back To Top
scroll-back-to-top
This plugin will add a button that allows users to scroll smoothly to the top of the page.
Cudazi Scroll to Top
cudazi-scroll-to-top
Adds a smooth scroll to top feature/link in the lower-right corner of long pages.
Flexible Scroll Top
flexible-scroll-top
Add a slick, lightweight and customizable scroll to top button that uses SVG icon with no jQuery dependency.
Classic Scroll to Top
classic-scroll-to-top
The "Classic Scroll to Top" plugin empowers your WordPress website with a simple yet effective Back to Top button functionality.
sr-scroll-to-top-wp Developer Profile
3 plugins · 40 total installs
How We Detect sr-scroll-to-top-wp
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sr-scroll-to-top-wp/js/jquery.scrollUp.js/wp-content/plugins/sr-scroll-to-top-wp/js/jquery.easing.min.js/wp-content/plugins/sr-scroll-to-top-wp/css/bappi.transitions.css/wp-content/plugins/sr-scroll-to-top-wp/css/font-awesome.min.cssjs/jquery.scrollUp.jsjs/jquery.easing.min.jsHTML / DOM Fingerprints
name="bappi_scroll_up_options_default[scroll_Distance]"name="bappi_scroll_up_options_default[scroll_Speed]"name="bappi_scroll_up_options_default[animation_Speed]"name="bappi_scroll_up_options_default[animation_up]"name="bappi_scroll_up_options_default[scroll_up_radio_mode]"