Wow scroll up Security & Risk Analysis

wordpress.org/plugins/wow-scroll-up

This plugin allows you to easily scroll back to the top of the page.

0 active installs v1.2 PHP + WP 4.0+ Updated Mar 29, 2018
animatebuttonscrollscrollupup
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Wow scroll up Safe to Use in 2026?

Generally Safe

Score 85/100

Wow scroll up has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The 'wow-scroll-up' v1.2 plugin appears to have a generally strong security posture based on the provided static analysis. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the lack of dangerous functions, raw SQL queries, file operations, and external HTTP requests are all positive indicators. The plugin also benefits from using prepared statements for its SQL queries, which is a crucial security practice.

However, there are a couple of areas that warrant attention. The output escaping is only properly done on 69% of outputs, meaning a portion of user-generated content or dynamic data displayed by the plugin might be vulnerable to cross-site scripting (XSS) attacks. The absence of nonce checks and capability checks, while not directly indicative of a vulnerability in this specific analysis due to the limited attack surface, is a general good practice that is missing. The plugin also bundles the Select2 library, and while its current version isn't specified, bundled libraries can sometimes become a vector if they are outdated and contain known vulnerabilities.

Given the plugin's history of zero known CVEs and no recorded vulnerabilities, it suggests a good track record of security. However, the findings from the static analysis, particularly the output escaping and the absence of authorization checks, indicate potential areas for improvement to further harden the plugin's security. The lack of taint analysis findings is positive, but the output escaping concern remains.

Key Concerns

  • Output escaping not properly handled
  • Missing nonce checks
  • Missing capability checks
  • Bundled library (Select2) may be outdated
Vulnerabilities
None known

Wow scroll up Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Wow scroll up Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Wow scroll up Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
22 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

69% escaped32 total outputs
Attack Surface

Wow scroll up Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_enqueue_scriptswow-scroll-up.php:31
actionlogin_enqueue_scriptswow-scroll-up.php:44
actionwp_enqueue_scriptswow-scroll-up.php:45
actionadmin_menuwow-scroll-up.php:56
actionadmin_initwow-scroll-up.php:110
actionadmin_initwow-scroll-up.php:280
actionwp_headwow-scroll-up.php:322
Maintenance & Trust

Wow scroll up Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedMar 29, 2018
PHP min version
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

Wow scroll up Developer Profile

veradeveloper

5 plugins · 300 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Wow scroll up

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wow-scroll-up/css/select2.min.css/wp-content/plugins/wow-scroll-up/css/admin.css/wp-content/plugins/wow-scroll-up/js/select2.min.js/wp-content/plugins/wow-scroll-up/js/admin.js/wp-content/plugins/wow-scroll-up/css/style.css/wp-content/plugins/wow-scroll-up/js/jquery.svgInject.js/wp-content/plugins/wow-scroll-up/js/main.js/wp-content/plugins/wow-scroll-up/img/logo-black.svg
Script Paths
/wp-content/plugins/wow-scroll-up/js/select2.min.js/wp-content/plugins/wow-scroll-up/js/admin.js/wp-content/plugins/wow-scroll-up/js/jquery.svgInject.js/wp-content/plugins/wow-scroll-up/js/main.js

HTML / DOM Fingerprints

CSS Classes
wsu_wrapwsu-checkboxwsu-radiowsu-upload-imagewsu-upload-image-previewwsu-upload-image-deletewsu-slect-icnwsu-select-icn
Data Attributes
data-wsu_icon_colordata-wsu_button_visible_fromdata-wsu_speed
JS Globals
wsu_plugin_urlwsu_icon_colorwsu_button_visible_fromwsu_speed
FAQ

Frequently Asked Questions about Wow scroll up