News Ticker for Elementor Security & Risk Analysis

wordpress.org/plugins/advanced-news-ticker

Advanced News Ticker offers 8 customizable layouts to display news, headlines, and breaking news, fully integrated with Elementor.

20 active installs v1.0.4 PHP + WP 5.9+ Updated Apr 22, 2025
breaking-newsnews-tickerpost-tickerscrolling-newsticker
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is News Ticker for Elementor Safe to Use in 2026?

Generally Safe

Score 100/100

News Ticker for Elementor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

The advanced-news-ticker plugin v1.0.4 exhibits a generally strong security posture based on the provided static analysis. The absence of any dangerous functions, file operations, or external HTTP requests is a positive indicator. Importantly, all SQL queries utilize prepared statements, and the vast majority of output is properly escaped, significantly mitigating common injection and XSS risks. The plugin also implements nonce checks on some of its AJAX handlers, adding a layer of protection. However, the lack of capability checks on any of its AJAX handlers is a notable concern, as it means that any authenticated user, regardless of their role, could potentially trigger these actions. While no critical or high-severity taint flows were detected, and the plugin has no recorded vulnerability history, this absence of capability checks could be exploited in conjunction with other potential, albeit undiscovered, weaknesses. The overall assessment is that the plugin is well-developed from a security perspective for common vulnerabilities, but the missing capability checks on AJAX handlers represent a specific area that warrants attention for improved security.

Key Concerns

  • AJAX handlers lack capability checks
Vulnerabilities
None known

News Ticker for Elementor Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

News Ticker for Elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
5 prepared
Unescaped Output
2
57 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

100% prepared5 total queries

Output Escaping

97% escaped59 total outputs
Attack Surface

News Ticker for Elementor Attack Surface

Entry Points4
Unprotected0

AJAX Handlers 4

authwp_ajax_advanced_news_ticker_select2_searchapp\Controllers\ElementorController.php:33
noprivwp_ajax_advanced_news_ticker_select2_searchapp\Controllers\ElementorController.php:34
authwp_ajax_advanced_news_ticker_select2_get_titleapp\Controllers\ElementorController.php:36
noprivwp_ajax_advanced_news_ticker_select2_get_titleapp\Controllers\ElementorController.php:37
WordPress Hooks 9
actionelementor/widgets/registerapp\Controllers\ElementorController.php:28
actionelementor/elements/categories_registeredapp\Controllers\ElementorController.php:29
actionelementor/editor/after_enqueue_stylesapp\Controllers\ElementorController.php:30
actionelementor/controls/registerapp\Controllers\ElementorController.php:31
actionelementor/editor/before_enqueue_scriptsapp\Controllers\ElementorController.php:32
actionadmin_initapp\Controllers\NoticeController.php:32
actionadmin_noticesapp\Controllers\NoticeController.php:40
actionwp_enqueue_scriptsapp\Controllers\ScriptController.php:20
actionsetup_themeapp\Init.php:34
Maintenance & Trust

News Ticker for Elementor Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 22, 2025
PHP min version
Downloads772

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

News Ticker for Elementor Developer Profile

DevofWP

3 plugins · 20 total installs

92
trust score
Avg Security Score
97/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect News Ticker for Elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/advanced-news-ticker/assets/css/news-ticker.css/wp-content/plugins/advanced-news-ticker/assets/js/news-ticker.js/wp-content/plugins/advanced-news-ticker/assets/css/animate.min.css/wp-content/plugins/advanced-news-ticker/assets/js/jquery.slimscroll.js/wp-content/plugins/advanced-news-ticker/assets/js/jquery.ticker.min.js/wp-content/plugins/advanced-news-ticker/assets/js/el-editor.js
Script Paths
/wp-content/plugins/advanced-news-ticker/assets/js/news-ticker.js/wp-content/plugins/advanced-news-ticker/assets/js/jquery.slimscroll.js/wp-content/plugins/advanced-news-ticker/assets/js/jquery.ticker.min.js/wp-content/plugins/advanced-news-ticker/assets/js/el-editor.js
Version Parameters
advanced-news-ticker/assets/css/news-ticker.css?ver=advanced-news-ticker/assets/js/news-ticker.js?ver=advanced-news-ticker/assets/css/animate.min.css?ver=advanced-news-ticker/assets/js/jquery.slimscroll.js?ver=advanced-news-ticker/assets/js/jquery.ticker.min.js?ver=advanced-news-ticker/assets/js/el-editor.js?ver=

HTML / DOM Fingerprints

CSS Classes
advanced-news-ticker-el-customnews-ticker-wrapntfs-ticker-sliderelementor-news-ticker
HTML Comments
<!-- Start Advanced News Ticker --><!-- End Advanced News Ticker --><!-- /.news-ticker-wrap --><!-- /.ntfs-ticker-slider -->
Data Attributes
data-settings
JS Globals
advanced_news_ticker_select2_nonce
REST Endpoints
/wp-json/advanced-news-ticker-select2-nonce
FAQ

Frequently Asked Questions about News Ticker for Elementor