
Scroll to top button Security & Risk Analysis
wordpress.org/plugins/wp-scroll-2Scroll to top button plugin is an simple and nice plugin with the standard settings.
Is Scroll to top button Safe to Use in 2026?
Generally Safe
Score 100/100Scroll to top button has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-scroll-2" v1.1.1 plugin presents a mixed security posture. On the positive side, it demonstrates good practices by having no recorded vulnerabilities (CVEs) and no identified dangerous functions or file operations. The plugin also correctly utilizes prepared statements for all SQL queries and includes a nonce check, which are fundamental security measures.
However, significant concerns arise from the static analysis. The fact that 100% of the outputs are not properly escaped is a critical weakness. This means any data outputted by the plugin, if it originates from an untrusted source, could be vulnerable to Cross-Site Scripting (XSS) attacks. Furthermore, the taint analysis revealed a flow with an unsanitized path, which, while not classified as critical or high severity in this specific analysis, indicates a potential for path traversal or other file-related vulnerabilities if not handled carefully in the future or if the context of the flow is misunderstood.
The absence of any recorded vulnerabilities in its history is a positive indicator, suggesting a history of secure development or that it hasn't been a target. However, this should not be solely relied upon, especially given the identified output escaping and taint flow issues. The plugin's strengths lie in its SQL handling and nonce usage, but its weaknesses in output sanitation and potential unsanitized path flows represent actionable security risks.
Key Concerns
- All outputs are unescaped
- Flow with unsanitized path
- No capability checks on entry points
Scroll to top button Security Vulnerabilities
Scroll to top button Code Analysis
Output Escaping
Data Flow Analysis
Scroll to top button Attack Surface
WordPress Hooks 3
Maintenance & Trust
Scroll to top button Maintenance & Trust
Maintenance Signals
Community Trust
Scroll to top button Alternatives
WPFront Scroll Top
wpfront-scroll-top
Adds a lightweight and smooth "Scroll to Top" button to your WordPress site, improving navigation and user experience with customizable options.
Flexible Scroll Top
flexible-scroll-top
Add a slick, lightweight and customizable scroll to top button that uses SVG icon with no jQuery dependency.
MM Scroll To Top
tap-to-top
Tap the button and scroll to top immediately.
AR Back To Top
ar-back-to-top
AR Back To Top is a standard WordPress plugin for back to top.
BH Scroll Top
bh-scroll-top
This plugin will add a scroll top feature in your site.
Scroll to top button Developer Profile
45 plugins · 52K total installs
How We Detect Scroll to top button
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-scroll-2/css/scroll_to_top.css/wp-content/plugins/wp-scroll-2/js/scroll_to_top.js/wp-content/plugins/wp-scroll-2/js/scroll_to_top.jsHTML / DOM Fingerprints
scroll_to_tablleupload-buttoncont_button_uploaded_imgdata-scroll-to-tophhg_scroll_to_top