Binary Carpenter Ultimate Scroll To Top Button Security & Risk Analysis

wordpress.org/plugins/ultimate-scroll-to-top-button

This plugin let you create scroll to top button to your site easily. There are no limit of styles you can create.

10 active installs v1.0 PHP 5.3+ WP 3.8+ Updated Oct 17, 2018
scroll-to-top
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Binary Carpenter Ultimate Scroll To Top Button Safe to Use in 2026?

Generally Safe

Score 85/100

Binary Carpenter Ultimate Scroll To Top Button has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "ultimate-scroll-to-top-button" plugin version 1.0 exhibits a generally positive security posture based on the provided static analysis. The absence of identified dangerous functions, SQL queries without prepared statements, file operations, and external HTTP requests are strong indicators of secure coding practices. The presence of nonce and capability checks, coupled with a single analyzed taint flow showing no unsanitized paths, further contributes to a low-risk profile. The plugin's vulnerability history is also a significant strength, with zero recorded CVEs across all severities, suggesting a history of stable and secure development. However, a significant concern arises from the low coverage of output escaping. With 64% of outputs properly escaped, there's still a 36% chance of vulnerable outputs, which could potentially lead to cross-site scripting (XSS) vulnerabilities if not handled carefully in the remaining cases. While the attack surface appears minimal with no apparent entry points requiring immediate attention, this low complexity doesn't negate the risk associated with unescaped outputs.

In conclusion, the plugin appears to be developed with security in mind, demonstrated by its clean history and minimal use of risky functions. The primary area of concern is the less-than-perfect output escaping. While the current data doesn't reveal active exploits or severe vulnerabilities, the potential for XSS exists. Users should be aware of this, and future updates should aim for 100% output escaping coverage to further harden the plugin.

Key Concerns

  • Unescaped output detected
Vulnerabilities
None known

Binary Carpenter Ultimate Scroll To Top Button Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Binary Carpenter Ultimate Scroll To Top Button Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

Binary Carpenter Ultimate Scroll To Top Button Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
7 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

64% escaped11 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

1 flows
<main-ui> (ui\main-ui.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Binary Carpenter Ultimate Scroll To Top Button Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_menufunctions.php:12
actionadmin_enqueue_scriptsfunctions.php:23
actionwp_enqueue_scriptsfunctions.php:50
actionwp_footerfunctions.php:68
Maintenance & Trust

Binary Carpenter Ultimate Scroll To Top Button Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedOct 17, 2018
PHP min version5.3
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Binary Carpenter Ultimate Scroll To Top Button Developer Profile

BinaryCarpenter

8 plugins · 3K total installs

79
trust score
Avg Security Score
79/100
Avg Patch Time
9 days
View full developer profile
Detection Fingerprints

How We Detect Binary Carpenter Ultimate Scroll To Top Button

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ultimate-scroll-to-top-button/bundle/css/backend.css/wp-content/plugins/ultimate-scroll-to-top-button/bundle/js/backend-bundle.js/wp-content/plugins/ultimate-scroll-to-top-button/bundle/css/front.css/wp-content/plugins/ultimate-scroll-to-top-button/bundle/js/frontend-bundle.js
Script Paths
/wp-content/plugins/ultimate-scroll-to-top-button/bundle/js/backend-bundle.js/wp-content/plugins/ultimate-scroll-to-top-button/bundle/js/frontend-bundle.js

HTML / DOM Fingerprints

CSS Classes
bc-scroll-top
FAQ

Frequently Asked Questions about Binary Carpenter Ultimate Scroll To Top Button