
WP-jScrollPane Security & Risk Analysis
wordpress.org/plugins/wp-jscrollpaneThis plugin gives support for the jQuery plugin, jScrollPane.
Is WP-jScrollPane Safe to Use in 2026?
Use With Caution
Score 63/100WP-jScrollPane has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The wp-jscrollpane v2.0.3 plugin exhibits a concerning security posture due to a combination of insecure coding practices and a history of vulnerabilities. While the plugin utilizes prepared statements for SQL queries and includes nonce checks, the complete lack of output escaping and the presence of unprotected AJAX handlers are significant weaknesses. The fact that all analyzed output is unescaped presents a high risk of Cross-Site Scripting (XSS) vulnerabilities. Additionally, the taint analysis identified a flow with an unsanitized path, which, although not classified as critical or high, still warrants attention. The plugin's vulnerability history, including a currently unpatched medium severity CVE for XSS, reinforces these concerns. The presence of an unpatched vulnerability and the demonstrated insecurity in handling output strongly suggest that this plugin poses a considerable risk to WordPress installations.
Key Concerns
- Unpatched CVE (Medium Severity)
- Output escaping: 0% properly escaped
- AJAX handlers without auth checks
- Flows with unsanitized paths
- Dangerous functions: unserialize
- Capability checks: 0
WP-jScrollPane Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WP-jScrollPane <= 2.0.3 - Reflected Cross-Site Scripting
WP-jScrollPane Code Analysis
Dangerous Functions Found
Bundled Libraries
Output Escaping
Data Flow Analysis
WP-jScrollPane Attack Surface
AJAX Handlers 2
WordPress Hooks 3
Maintenance & Trust
WP-jScrollPane Maintenance & Trust
Maintenance Signals
Community Trust
WP-jScrollPane Alternatives
VR jScrollPane Shortcode
vr-jscrollpane-shortcode
A simple short code for inserting jScrollPane content in any WordPress post or page.
Enable jQuery Migrate Helper
enable-jquery-migrate-helper
Get information about calls to deprecated jQuery features in plugins or themes.
Animate It!
animate-it
Add cool CSS3 animations to your content.
jQuery Updater
jquery-updater
This plugin updates jQuery to the latest stable version on your website.
Scroll To Top
scroll-top
Automatically adds a flexible Back to Top button to your WordPress website that allows your visitor to scroll back to the top of your page with one cl …
WP-jScrollPane Developer Profile
1 plugin · 90 total installs
How We Detect WP-jScrollPane
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-jscrollpane/js/admin.js/wp-content/plugins/wp-jscrollpane/css/admin.css/wp-content/plugins/wp-jscrollpane/js/jquery.colorpicker.min.js/wp-content/plugins/wp-jscrollpane/css/jquery.colorpicker.min.css/wp-content/plugins/wp-jscrollpane/js/admin.js/wp-content/plugins/wp-jscrollpane/js/jquery.colorpicker.min.jswp-jscrollpane/js/admin.js?ver=wp-jscrollpane/css/admin.css?ver=wp-jscrollpane/js/jquery.colorpicker.min.js?ver=wp-jscrollpane/css/jquery.colorpicker.min.css?ver=HTML / DOM Fingerprints
wpjsp-wrapwpjsp-errorswpjsp-addwpjsp-tipswpjsp-scrollbars<!-- When testing while logged-in, the Wordpress Admin Bar changes the whole-page behavior. Log-out and it will work fine. --><!-- "H" for Horizontal bar. "V" for Vertical bar. All sizes are in pixels (px) --><!-- I need someone to re-make this form's html to be displayed on normal 1024x768, with the appropriate styles included --><!-- The "WinXP" theme does not work yet. It was included so I could maybe get someone to help with it, and another called "OSX" -->+1 moreid="wpjsp-wrap"id="wpjsp-errors"id="wpjsp-add"id="wpjsp-form"id="wpjsp-tips"id="mousewheel"+5 morewindow.jQuery