Surbma | Smooth Scroll Security & Risk Analysis

wordpress.org/plugins/surbma-smooth-scroll

A very simple and lightweight smooth scroll plugin.

2K active installs v1.2 PHP 7.0+ WP 5.0+ Updated Nov 26, 2023
ariel-fleslerlocalscrollscrollscrolltosmooth-scroll
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Surbma | Smooth Scroll Safe to Use in 2026?

Generally Safe

Score 85/100

Surbma | Smooth Scroll has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The surbma-smooth-scroll v1.2 plugin exhibits a strong security posture based on the provided static analysis. The absence of any detected dangerous functions, the exclusive use of prepared statements for SQL queries, and the consistent application of output escaping are all excellent security practices. Furthermore, the lack of file operations, external HTTP requests, and the limited attack surface with zero entry points further bolster its security. The plugin also benefits from a clean vulnerability history, with no recorded CVEs, suggesting a history of secure development or effective patching by its maintainers.

While the static analysis reveals no immediate critical vulnerabilities such as unsanitized taint flows or insecure direct object references, the complete absence of nonce and capability checks across all analyzed components (AJAX handlers, REST API routes, shortcodes, cron events) represents a significant concern. This means that any potential future vulnerabilities or unintended exposure of functionality could be easily exploited without proper authorization checks. Although the current code analysis shows no exploitable paths, this lack of defense-in-depth is a notable weakness. In conclusion, the plugin demonstrates good coding practices regarding data handling and query security, but the complete omission of authorization checks across its entry points is a substantial security gap that should be addressed.

Key Concerns

  • No nonce checks detected
  • No capability checks detected
Vulnerabilities
None known

Surbma | Smooth Scroll Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Surbma | Smooth Scroll Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Surbma | Smooth Scroll Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionplugins_loadedsurbma-smooth-scroll.php:23
actionwp_enqueue_scriptssurbma-smooth-scroll.php:27
Maintenance & Trust

Surbma | Smooth Scroll Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedNov 26, 2023
PHP min version7.0
Downloads31K

Community Trust

Rating94/100
Number of ratings14
Active installs2K
Developer Profile

Surbma | Smooth Scroll Developer Profile

Surbma

27 plugins · 30K total installs

71
trust score
Avg Security Score
88/100
Avg Patch Time
127 days
View full developer profile
Detection Fingerprints

How We Detect Surbma | Smooth Scroll

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/surbma-smooth-scroll/js/jquery.scrollTo.min.js/wp-content/plugins/surbma-smooth-scroll/js/jquery.localScroll.min.js/wp-content/plugins/surbma-smooth-scroll/js/surbma-smooth-scroll.js
Script Paths
jquery.scrollTo.min.jsjquery.localScroll.min.jssurbma-smooth-scroll.js
Version Parameters
surbma-smooth-scroll/js/surbma-smooth-scroll.js?ver=1.2

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Surbma | Smooth Scroll