
Wow scroll up Security & Risk Analysis
wordpress.org/plugins/wow-scroll-upThis plugin allows you to easily scroll back to the top of the page.
Is Wow scroll up Safe to Use in 2026?
Generally Safe
Score 85/100Wow scroll up has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'wow-scroll-up' v1.2 plugin appears to have a generally strong security posture based on the provided static analysis. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the lack of dangerous functions, raw SQL queries, file operations, and external HTTP requests are all positive indicators. The plugin also benefits from using prepared statements for its SQL queries, which is a crucial security practice.
However, there are a couple of areas that warrant attention. The output escaping is only properly done on 69% of outputs, meaning a portion of user-generated content or dynamic data displayed by the plugin might be vulnerable to cross-site scripting (XSS) attacks. The absence of nonce checks and capability checks, while not directly indicative of a vulnerability in this specific analysis due to the limited attack surface, is a general good practice that is missing. The plugin also bundles the Select2 library, and while its current version isn't specified, bundled libraries can sometimes become a vector if they are outdated and contain known vulnerabilities.
Given the plugin's history of zero known CVEs and no recorded vulnerabilities, it suggests a good track record of security. However, the findings from the static analysis, particularly the output escaping and the absence of authorization checks, indicate potential areas for improvement to further harden the plugin's security. The lack of taint analysis findings is positive, but the output escaping concern remains.
Key Concerns
- Output escaping not properly handled
- Missing nonce checks
- Missing capability checks
- Bundled library (Select2) may be outdated
Wow scroll up Security Vulnerabilities
Wow scroll up Release Timeline
Wow scroll up Code Analysis
Bundled Libraries
Output Escaping
Wow scroll up Attack Surface
WordPress Hooks 7
Maintenance & Trust
Wow scroll up Maintenance & Trust
Maintenance Signals
Community Trust
Wow scroll up Alternatives
To Top
to-top
To Top is a nifty lightweight plugin. It adds a highly customizable button, which when clicked, scrolls up smoothly to the top of a page.
Scroll Back To Top Button
scrollup-master
This is just a very simple plugin to have a scroll back to top button throughout your whole blog/site.
Tipu Scroll To Top
tipu-scroll-to-top
License: GPLv2 or later License URI: http://www.gnu.org/licenses/gpl-2.0.html This Plugin adds a scroll to top button in your site
Top Scroller
top-scroller
Top Scroller plugin allows the visitor to easily and safely scroll back to the top of the page.
Ashch-scrollTop
ashch-scroll-top
Scroll Top is a WordPress plugin which make scroll to top customizable button.
Wow scroll up Developer Profile
5 plugins · 300 total installs
How We Detect Wow scroll up
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wow-scroll-up/css/select2.min.css/wp-content/plugins/wow-scroll-up/css/admin.css/wp-content/plugins/wow-scroll-up/js/select2.min.js/wp-content/plugins/wow-scroll-up/js/admin.js/wp-content/plugins/wow-scroll-up/css/style.css/wp-content/plugins/wow-scroll-up/js/jquery.svgInject.js/wp-content/plugins/wow-scroll-up/js/main.js/wp-content/plugins/wow-scroll-up/img/logo-black.svg/wp-content/plugins/wow-scroll-up/js/select2.min.js/wp-content/plugins/wow-scroll-up/js/admin.js/wp-content/plugins/wow-scroll-up/js/jquery.svgInject.js/wp-content/plugins/wow-scroll-up/js/main.jsHTML / DOM Fingerprints
wsu_wrapwsu-checkboxwsu-radiowsu-upload-imagewsu-upload-image-previewwsu-upload-image-deletewsu-slect-icnwsu-select-icndata-wsu_icon_colordata-wsu_button_visible_fromdata-wsu_speedwsu_plugin_urlwsu_icon_colorwsu_button_visible_fromwsu_speed