
MM Scroll To Top Security & Risk Analysis
wordpress.org/plugins/tap-to-topTap the button and scroll to top immediately.
Is MM Scroll To Top Safe to Use in 2026?
Generally Safe
Score 100/100MM Scroll To Top has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The tap-to-top plugin version 1.7.1 exhibits a strong security posture in several key areas. The static analysis reveals no identifiable attack surface through AJAX handlers, REST API routes, shortcodes, or cron events that are unprotected. Furthermore, the code signals indicate a complete absence of dangerous functions, file operations, and external HTTP requests. SQL queries are consistently handled with prepared statements, which is a critical security best practice. The plugin also has no recorded vulnerability history, suggesting a history of secure development or a lack of past exploitation.
Despite these strengths, a significant concern lies in the complete lack of output escaping. With 5 total outputs and 0% properly escaped, this presents a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data displayed by the plugin without proper sanitization could be exploited by attackers to inject malicious scripts. The absence of nonce and capability checks, while not directly tied to the identified attack surface, also represents a potential weakness if the plugin's functionality were ever to expand to include sensitive operations or data handling. The plugin also has no taint analysis results, which could be due to a very limited scope of the analysis or a lack of complex data flows. The absence of these checks, combined with the unescaped output, warrants caution.
In conclusion, while tap-to-top v1.7.1 benefits from a clean code structure with no known vulnerabilities and robust handling of SQL queries, the critical issue of unescaped output leaves it vulnerable to XSS attacks. Developers should prioritize addressing this immediately. The lack of capability and nonce checks, while not a current demonstrable vulnerability based on the provided data, is a point to monitor for future development.
Key Concerns
- Output is not properly escaped
- No nonce checks
- No capability checks
MM Scroll To Top Security Vulnerabilities
MM Scroll To Top Code Analysis
Output Escaping
MM Scroll To Top Attack Surface
WordPress Hooks 8
Maintenance & Trust
MM Scroll To Top Maintenance & Trust
Maintenance Signals
Community Trust
MM Scroll To Top Alternatives
WPFront Scroll Top
wpfront-scroll-top
Adds a lightweight and smooth "Scroll to Top" button to your WordPress site, improving navigation and user experience with customizable options.
Flexible Scroll Top
flexible-scroll-top
Add a slick, lightweight and customizable scroll to top button that uses SVG icon with no jQuery dependency.
Scroll to top button
wp-scroll-2
Scroll to top button plugin is an simple and nice plugin with the standard settings.
AR Back To Top
ar-back-to-top
AR Back To Top is a standard WordPress plugin for back to top.
BH Scroll Top
bh-scroll-top
This plugin will add a scroll top feature in your site.
MM Scroll To Top Developer Profile
3 plugins · 150 total installs
How We Detect MM Scroll To Top
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tap-to-top/css/taptotop-settings.css/wp-content/plugins/tap-to-top/css/taptotop-style.css/wp-content/plugins/tap-to-top/js/taptotop-script.js/wp-content/plugins/tap-to-top/js/taptotop-script.jstap-to-top/css/taptotop-settings.css?ver=tap-to-top/js/taptotop-script.js?ver=HTML / DOM Fingerprints
taptotop_maintaptotop_bodytaptotop_commontaptotop_asideauthor-cardradiosbtn<!-- Primary Color --><!-- Border Color --><!-- Button Position --><!-- Button Shape -->+3 moretaptotop-primary-colortaptotop-border-colortaptotop-button-positiontaptotop-rounded-cornertaptotop-button-position-notaptotop-button-position-yes+2 morejQuery.scrollUp