WPBatch Scroll to Top Security & Risk Analysis

wordpress.org/plugins/wpbatch-scroll-to-top

The Easiest Scroll to Top Plugin Ever..

10 active installs v1.0 PHP + WP 3.0.1+ Updated Oct 13, 2014
scrollscroll-to-topscrollingscrolltopscrollup
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WPBatch Scroll to Top Safe to Use in 2026?

Generally Safe

Score 85/100

WPBatch Scroll to Top has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The wpbatch-scroll-to-top plugin v1.0 exhibits a generally positive security posture based on the static analysis provided. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits its attack surface. Furthermore, the code signals indicate no dangerous functions, no raw SQL queries (all use prepared statements), no file operations, and no external HTTP requests, all of which are strong security indicators. The lack of any recorded vulnerability history or CVEs further bolsters this assessment, suggesting a well-maintained and secure codebase.

However, a significant concern arises from the output escaping. With one total output and 0% properly escaped, there is a high probability of Cross-Site Scripting (XSS) vulnerabilities if any user-controlled data is ever displayed to the user. The absence of nonce checks and capability checks on any potential entry points (though none were identified, which is good) means that if any were introduced in future versions, they would not be secured. The taint analysis showing zero flows is positive, but this is likely due to the minimal attack surface and lack of data processing, rather than robust sanitization practices.

In conclusion, the plugin is currently very secure due to its extremely limited functionality and attack surface. The primary weakness lies in the complete lack of output escaping, which presents a latent XSS risk should any user-supplied data be outputted in the future. While the current state is good, proactive attention to output sanitization is crucial for long-term security.

Key Concerns

  • Output escaping is completely missing
Vulnerabilities
None known

WPBatch Scroll to Top Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

WPBatch Scroll to Top Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

WPBatch Scroll to Top Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionwp_enqueue_scriptsscroll.php:33
filterwp_headscroll.php:37
Maintenance & Trust

WPBatch Scroll to Top Maintenance & Trust

Maintenance Signals

WordPress version tested4.0.38
Last updatedOct 13, 2014
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings11
Active installs10
Developer Profile

WPBatch Scroll to Top Developer Profile

Md. Toriqul Mowla

5 plugins · 7K total installs

84
trust score
Avg Security Score
86/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WPBatch Scroll to Top

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wpbatch-scroll-to-top/css/scroll.css/wp-content/plugins/wpbatch-scroll-to-top/css/font-awesome.min.css/wp-content/plugins/wpbatch-scroll-to-top/js/jquery.easing.js/wp-content/plugins/wpbatch-scroll-to-top/js/scroll.js
Script Paths
/wp-content/plugins/wpbatch-scroll-to-top/js/jquery.easing.js/wp-content/plugins/wpbatch-scroll-to-top/js/scroll.js
Version Parameters
wpbatch-scroll-to-top/css/scroll.css?ver=wpbatch-scroll-to-top/css/font-awesome.min.css?ver=wpbatch-scroll-to-top/js/jquery.easing.js?ver=wpbatch-scroll-to-top/js/scroll.js?ver=

HTML / DOM Fingerprints

CSS Classes
dream-scroll
FAQ

Frequently Asked Questions about WPBatch Scroll to Top