
wp scroll posts Security & Risk Analysis
wordpress.org/plugins/wp-scroll-postswp scroll posts is posts scroller plugin
Is wp scroll posts Safe to Use in 2026?
Generally Safe
Score 85/100wp scroll posts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-scroll-posts" plugin v0.6 demonstrates a generally good security posture based on the provided static analysis. It has a very small attack surface, with only one shortcode and no other identified entry points. Critically, there are no AJAX handlers or REST API routes that lack authentication or permission checks. The code also shows good practices in handling SQL queries, with 100% using prepared statements and no dangerous functions detected. File operations and external HTTP requests are also absent, further reducing potential risks.
However, a significant concern lies in the output escaping. With 26 total outputs and only 8% properly escaped, there is a high probability of cross-site scripting (XSS) vulnerabilities. This is a serious weakness that could allow attackers to inject malicious scripts into the user interface. Additionally, the complete absence of nonce checks is a red flag. While there are no AJAX handlers to protect with nonces currently, any future addition of such functionality without implementing nonce checks would be a critical oversight, leaving the plugin open to CSRF attacks.
The plugin's vulnerability history is clean, with no recorded CVEs. This, combined with the absence of taint flows, suggests that its existing codebase might be relatively stable or that the static analysis was limited. Despite its strengths in query handling and limited attack surface, the poor output escaping and lack of nonces are substantial security weaknesses that warrant careful consideration. The plugin's overall security is moderate, with significant risks due to potential XSS.
Key Concerns
- Low percentage of properly escaped output (8%)
- Zero nonce checks implemented
wp scroll posts Security Vulnerabilities
wp scroll posts Release Timeline
wp scroll posts Code Analysis
Output Escaping
wp scroll posts Attack Surface
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
wp scroll posts Maintenance & Trust
Maintenance Signals
Community Trust
wp scroll posts Alternatives
Scroll To Top
wp-scroll-to-top
Scroll To Top plugin does the job with just one click a button appears when a person scrolls to the middle of the page to be clicked on.
WP Scroll To Top
my-wp-scroll-to-top
WP Scroll to top is beautifully designed and supper plugin.Very easy to use and perfect functionality.
Marquee Block
marquee-block
Marquee block is CSS based animation block to display scrolling text, images and any kinds of blocks horizontally and vertically.
Vertical Image Slider
wp-vertical-image-slider
This is a beautiful responsive vertical image slider for wp blogs and sites. Admin can manage any number of images into the responsive vertical slider …
Simple Owl Carousel
simple-owl-carousel
Based on the Owl Carousel, an extremely powerful, robust & responsive customizable plugin.
wp scroll posts Developer Profile
4 plugins · 250 total installs
How We Detect wp scroll posts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-scroll-posts/js/jquery.vticker.js/wp-content/plugins/wp-scroll-posts/css/styles.css/wp-content/plugins/wp-scroll-posts/js/jquery.vticker.jsHTML / DOM Fingerprints
name="wpsp_enable"name="wpsp_thumbnail_enable"name="wpsp_title_enable"name="wpsp_date_enable"name="wpsp_excerpt_enable"name="wpsp_readmore_enable"+10 more[wpsp][wpsp cat='CategoryName']