
WX Scroll To Up Security & Risk Analysis
wordpress.org/plugins/wx-scroll-to-upA lightweight, customizable Scroll To Top button plugin for your WordPress site.
Is WX Scroll To Up Safe to Use in 2026?
Generally Safe
Score 100/100WX Scroll To Up has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the provided static analysis, wx-scroll-to-up v1.0.2 exhibits a remarkably strong security posture. The absence of any identified attack surface points like AJAX handlers, REST API routes, shortcodes, or cron events significantly limits potential entry points for malicious actors. Furthermore, the code demonstrates excellent practices by not utilizing dangerous functions, all SQL queries employing prepared statements, and 100% of output being properly escaped. The lack of file operations and external HTTP requests further reduces the plugin's exposure to external manipulation. The vulnerability history is also clean, with no known CVEs recorded, indicating a history of secure development or effective remediation.
However, the complete absence of nonce checks and capability checks is a notable concern. While the current attack surface appears to be zero, this leaves a significant gap if any new entry points were to be introduced in future versions or if the plugin's functionality were to expand. Without these fundamental security mechanisms, any discovered vulnerabilities could be exploited more easily. The taint analysis showing zero flows is positive, but this could be a reflection of the limited attack surface rather than a guarantee of complete taint-free code if more complex interactions were present.
In conclusion, wx-scroll-to-up v1.0.2 is exceptionally secure based on the current data, with excellent coding practices in place for SQL and output handling. The primary weakness lies in the missing authentication and authorization checks (nonces and capabilities), which is a significant oversight despite the current lack of an exploitable attack surface. The plugin's clean vulnerability history is a strong positive, but the missing checks represent a latent risk.
Key Concerns
- Missing nonce checks
- Missing capability checks
WX Scroll To Up Security Vulnerabilities
WX Scroll To Up Code Analysis
Output Escaping
WX Scroll To Up Attack Surface
WordPress Hooks 12
Maintenance & Trust
WX Scroll To Up Maintenance & Trust
Maintenance Signals
Community Trust
WX Scroll To Up Alternatives
WPFront Scroll Top
wpfront-scroll-top
Adds a lightweight and smooth "Scroll to Top" button to your WordPress site, improving navigation and user experience with customizable options.
Scroll Back To Top Button
scrollup-master
This is just a very simple plugin to have a scroll back to top button throughout your whole blog/site.
Click to top
click-to-top
A wordpress plugin to create a customisable Click To Top feature.
X-Scroll To Top – Responsive
x-scroll-to-top-responsive
X-Scroll To Top adds a customizable scroll-up button to your site. Personalize it to seamlessly match your design and enhance functionality.
scrollToTop
scrolltotop
Create your own back to top button or full-height bar and simple customize it as you want.
WX Scroll To Up Developer Profile
1 plugin · 10 total installs
How We Detect WX Scroll To Up
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wx-scroll-to-up/flaticon/flaticon_scrolltoup.css/wp-content/plugins/wx-scroll-to-up/css/setting.css/wp-content/plugins/wx-scroll-to-up/js/setting.js/wp-content/plugins/wx-scroll-to-up/css/style.css/wp-content/plugins/wx-scroll-to-up/js/script.js/wp-content/plugins/wx-scroll-to-up/js/setting.js/wp-content/plugins/wx-scroll-to-up/js/script.jswx-scroll-to-up/flaticon/flaticon_scrolltoup.css?ver=wx-scroll-to-up/css/setting.css?ver=wx-scroll-to-up/js/setting.js?ver=wx-scroll-to-up/css/style.css?ver=wx-scroll-to-up/js/script.js?ver=HTML / DOM Fingerprints
wstp-scroll-updesign-progress-circleprogress-svgprogress-backgroundprogress-barfontcustom_svg_iconid="wstp-scroll-up"