
WPFront Scroll Top Security & Risk Analysis
wordpress.org/plugins/wpfront-scroll-topAdds a lightweight and smooth "Scroll to Top" button to your WordPress site, improving navigation and user experience with customizable options.
Is WPFront Scroll Top Safe to Use in 2026?
Generally Safe
Score 100/100WPFront Scroll Top has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The wpfront-scroll-top plugin v3.0.1 exhibits a generally good security posture with a small attack surface and a high percentage of properly escaped outputs. The presence of nonce and capability checks on its single AJAX handler suggests an effort to secure entry points. File operations and external HTTP requests are not a concern in this version. However, the presence of a single SQL query that is not using prepared statements is a minor concern, as it could potentially be vulnerable to SQL injection if the input is not meticulously sanitized before being passed to the query. The vulnerability history reveals one medium severity Cross-Site Scripting (XSS) vulnerability, which was patched as of July 2021. While the current version shows no critical or high severity issues and no unpatched CVEs, the past XSS vulnerability, coupled with the un-prepared SQL statement, indicates a need for continued vigilance in code review and testing to prevent future similar issues. Overall, the plugin appears reasonably secure for its current version, but the minor SQL concern and historical vulnerability warrant attention.
Key Concerns
- Raw SQL without prepared statements
WPFront Scroll Top Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WPFront Scroll Top <= 2.0.5 - Authenticated Stored Cross-Site Scripting
WPFront Scroll Top Release Timeline
WPFront Scroll Top Code Analysis
SQL Query Safety
Output Escaping
WPFront Scroll Top Attack Surface
AJAX Handlers 1
WordPress Hooks 8
Maintenance & Trust
WPFront Scroll Top Maintenance & Trust
Maintenance Signals
Community Trust
WPFront Scroll Top Alternatives
Flexible Scroll Top
flexible-scroll-top
Add a slick, lightweight and customizable scroll to top button that uses SVG icon with no jQuery dependency.
MM Scroll To Top
tap-to-top
Tap the button and scroll to top immediately.
Scroll to top button
wp-scroll-2
Scroll to top button plugin is an simple and nice plugin with the standard settings.
AR Back To Top
ar-back-to-top
AR Back To Top is a standard WordPress plugin for back to top.
BH Scroll Top
bh-scroll-top
This plugin will add a scroll top feature in your site.
WPFront Scroll Top Developer Profile
4 plugins · 280K total installs
How We Detect WPFront Scroll Top
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpfront-scroll-top/includes/assets/wpfront-scroll-top.min.js/wp-content/plugins/wpfront-scroll-top/assets/wpfront-scroll-top.jshttps://maxcdn.bootstrapcdn.com/font-awesome/4.7.0/css/font-awesome.min.csswpfront-scroll-top/style.css?ver=wpfront-scroll-top?ver=HTML / DOM Fingerprints
wpfront-scroll-topWPFront Scroll TopCopyright (C) 2013, wpfront.comWebsite: wpfront.comContact: syam@wpfront.com+13 moredata-scroll-durationdata-auto-hide-afterdata-auto-hidedata-button-fade-durationdata-hide-iframedata-scroll-offset+5 morewpfront_scroll_top_data