Advance News Ticker Security & Risk Analysis

wordpress.org/plugins/advance-news-ticker

Provides flexible and advance news ticker. Display it via shortcode and more.

10 active installs v1.0 PHP + WP 4.0+ Updated Jul 9, 2018
advance-news-tickerjquery-news-tickermarqueenews-tickerticker
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Advance News Ticker Safe to Use in 2026?

Generally Safe

Score 85/100

Advance News Ticker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "advance-news-ticker" v1.0 plugin presents a mixed security picture. On the positive side, the plugin has no recorded vulnerabilities, including critical or high severity issues, which suggests a generally stable codebase. Furthermore, it avoids dangerous functions, performs all SQL queries using prepared statements, and has no file operations or external HTTP requests, all of which are strong security practices. However, a significant concern arises from the complete lack of output escaping. With 17 total outputs and 0% properly escaped, this creates a high risk of Cross-Site Scripting (XSS) vulnerabilities. While the attack surface is currently small with only one shortcode and no unprotected entry points identified, the lack of proper output sanitization means any data processed by this shortcode could potentially be injected with malicious scripts. The absence of nonce and capability checks, though not directly tied to entry points in this analysis, is also a weakness that could be exploited if the attack surface were to expand or if other security measures were bypassed.

Key Concerns

  • No output escaping found
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Advance News Ticker Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Advance News Ticker Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
17
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped17 total outputs
Attack Surface

Advance News Ticker Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[advance_newsticker_shortcode] inc\advance-news-ticker-shortcode.php:116
WordPress Hooks 4
actionwp_enqueue_scriptsadvance-news-ticker.php:45
actionadmin_enqueue_scriptsadvance-news-ticker.php:54
actionadmin_menuinc\advance-news-ticker-option-page.php:7
actionadmin_initinc\advance-news-ticker-option-page.php:74
Maintenance & Trust

Advance News Ticker Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedJul 9, 2018
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Advance News Ticker Developer Profile

Md Abunaser Khan

2 plugins · 10 total installs

76
trust score
Avg Security Score
74/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Advance News Ticker

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/advance-news-ticker/assets/css/advance-news-ticker.css/wp-content/plugins/advance-news-ticker/assets/js/advance-news-ticker.js/wp-content/plugins/advance-news-ticker/assets/js/color-script.js
Script Paths
/wp-content/plugins/advance-news-ticker/assets/js/advance-news-ticker.js/wp-content/plugins/advance-news-ticker/assets/js/color-script.js
Version Parameters
advance-news-ticker/assets/js/advance-news-ticker.js?ver=

HTML / DOM Fingerprints

CSS Classes
bn-breaking-newsant-titlebn-labelbn-newsbn-controlsbn-arrowbn-prevbn-action+1 more
Data Attributes
data-effect
JS Globals
breakingNews
Shortcode Output
<div class="bn-breaking-news ant-title<div class="bn-label"><div class="bn-news"><ul><div class="bn-controls">
FAQ

Frequently Asked Questions about Advance News Ticker