XL Scroll To Top Security & Risk Analysis

wordpress.org/plugins/xl-scroll-to-top

XL Scroll To Top is a free plugin for your wordpress website.

10 active installs v1.1 PHP + WP 3.2+ Updated Mar 10, 2018
back-to-topjquery-scroll-to-topscroll-to-topxl-scroll-to-top
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is XL Scroll To Top Safe to Use in 2026?

Generally Safe

Score 85/100

XL Scroll To Top has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The plugin 'xl-scroll-to-top' v1.1 exhibits a strong security posture based on the provided static analysis. The absence of any identified dangerous functions, raw SQL queries, unescaped output, file operations, external HTTP requests, and successful taint analysis flows indicates a well-written and secure codebase. Furthermore, the complete lack of known CVEs and a clean vulnerability history reinforce this positive assessment, suggesting the developers prioritize security and have not introduced any significant vulnerabilities in previous versions.

While the static analysis reveals an exceptionally low attack surface and robust code practices, the data also points to potential areas of concern. The complete absence of nonce checks and capability checks across all analyzed entry points (AJAX, REST API, shortcodes, cron) is a significant weakness. This means that if any entry points were to be introduced in future versions or were somehow overlooked in this analysis, they would be entirely unprotected against unauthorized access or manipulation. The plugin currently has zero entry points, which mitigates this risk for the existing version, but it's a critical oversight in terms of defensive programming principles.

In conclusion, 'xl-scroll-to-top' v1.1 currently appears very secure due to its clean code and lack of historical vulnerabilities. However, the complete omission of authentication and authorization mechanisms for any potential future entry points represents a substantial inherent risk. The plugin's current minimal attack surface is its primary defense, and any expansion of this surface without implementing proper security checks would immediately create critical vulnerabilities.

Key Concerns

  • No nonce checks detected
  • No capability checks detected
Vulnerabilities
None known

XL Scroll To Top Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

XL Scroll To Top Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

XL Scroll To Top Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actioninitfunctions.php:19
Maintenance & Trust

XL Scroll To Top Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedMar 10, 2018
PHP min version
Downloads1K

Community Trust

Rating90/100
Number of ratings2
Active installs10
Developer Profile

XL Scroll To Top Developer Profile

XLTHEME

3 plugins · 30 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect XL Scroll To Top

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/xl-scroll-to-top/js/plugins.js/wp-content/plugins/xl-scroll-to-top/js/custom.js/wp-content/plugins/xl-scroll-to-top/css/plugins.css/wp-content/plugins/xl-scroll-to-top/css/custom.css
Script Paths
wp-content/plugins/xl-scroll-to-top/js/plugins.jswp-content/plugins/xl-scroll-to-top/js/custom.js
Version Parameters
xl-scroll-to-top/js/plugins.js?ver=xl-scroll-to-top/js/custom.js?ver=xl-scroll-to-top/css/plugins.css?ver=xl-scroll-to-top/css/custom.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about XL Scroll To Top