
XL Scroll To Top Security & Risk Analysis
wordpress.org/plugins/xl-scroll-to-topXL Scroll To Top is a free plugin for your wordpress website.
Is XL Scroll To Top Safe to Use in 2026?
Generally Safe
Score 85/100XL Scroll To Top has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'xl-scroll-to-top' v1.1 exhibits a strong security posture based on the provided static analysis. The absence of any identified dangerous functions, raw SQL queries, unescaped output, file operations, external HTTP requests, and successful taint analysis flows indicates a well-written and secure codebase. Furthermore, the complete lack of known CVEs and a clean vulnerability history reinforce this positive assessment, suggesting the developers prioritize security and have not introduced any significant vulnerabilities in previous versions.
While the static analysis reveals an exceptionally low attack surface and robust code practices, the data also points to potential areas of concern. The complete absence of nonce checks and capability checks across all analyzed entry points (AJAX, REST API, shortcodes, cron) is a significant weakness. This means that if any entry points were to be introduced in future versions or were somehow overlooked in this analysis, they would be entirely unprotected against unauthorized access or manipulation. The plugin currently has zero entry points, which mitigates this risk for the existing version, but it's a critical oversight in terms of defensive programming principles.
In conclusion, 'xl-scroll-to-top' v1.1 currently appears very secure due to its clean code and lack of historical vulnerabilities. However, the complete omission of authentication and authorization mechanisms for any potential future entry points represents a substantial inherent risk. The plugin's current minimal attack surface is its primary defense, and any expansion of this surface without implementing proper security checks would immediately create critical vulnerabilities.
Key Concerns
- No nonce checks detected
- No capability checks detected
XL Scroll To Top Security Vulnerabilities
XL Scroll To Top Code Analysis
XL Scroll To Top Attack Surface
WordPress Hooks 1
Maintenance & Trust
XL Scroll To Top Maintenance & Trust
Maintenance Signals
Community Trust
XL Scroll To Top Alternatives
WPFront Scroll Top
wpfront-scroll-top
Adds a lightweight and smooth "Scroll to Top" button to your WordPress site, improving navigation and user experience with customizable options.
Smooth Back To Top Button
smooth-back-to-top-button
Smooth Back To Top button with scroll progress indicator.
Scroll To Top
scroll-top
Automatically adds a flexible Back to Top button to your WordPress website that allows your visitor to scroll back to the top of your page with one cl …
jQuery Smooth Scroll
jquery-smooth-scroll
Activate the plugin for smooth scrolling and smooth "back to top" feature.
Scroll Back To Top
scroll-back-to-top
This plugin will add a button that allows users to scroll smoothly to the top of the page.
XL Scroll To Top Developer Profile
3 plugins · 30 total installs
How We Detect XL Scroll To Top
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/xl-scroll-to-top/js/plugins.js/wp-content/plugins/xl-scroll-to-top/js/custom.js/wp-content/plugins/xl-scroll-to-top/css/plugins.css/wp-content/plugins/xl-scroll-to-top/css/custom.csswp-content/plugins/xl-scroll-to-top/js/plugins.jswp-content/plugins/xl-scroll-to-top/js/custom.jsxl-scroll-to-top/js/plugins.js?ver=xl-scroll-to-top/js/custom.js?ver=xl-scroll-to-top/css/plugins.css?ver=xl-scroll-to-top/css/custom.css?ver=