
All in One News Scroll Security & Risk Analysis
wordpress.org/plugins/all-in-one-news-scrollAll in One News Scroll plugin can create vertical scroll news. Using shortcode as well as by Widget in any page or post. Shortcode - [allinone-news], …
Is All in One News Scroll Safe to Use in 2026?
Generally Safe
Score 100/100All in One News Scroll has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'all-in-one-news-scroll' plugin v1.12 exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, file operations, external HTTP requests, and SQL queries using prepared statements are all positive indicators. The plugin also has no recorded vulnerability history, which suggests a track record of security diligence. However, a significant concern arises from the low percentage of properly escaped output (18%). This indicates a potential for Cross-Site Scripting (XSS) vulnerabilities, especially as there are no recorded nonce or capability checks on the identified entry points. While the attack surface is small and currently appears unprotected entry points are zero, the lack of output escaping is a critical weakness that needs immediate attention. The taint analysis showing zero unsanitized flows is encouraging, but it might be limited by the scope of the analysis or the plugin's limited complexity.
Overall, the plugin has strengths in its limited attack surface and its use of prepared statements for SQL. The lack of any known vulnerabilities is also a positive sign. Nevertheless, the poor output escaping practices present a clear and present danger for XSS attacks. Until this is addressed, the plugin remains susceptible to a common and impactful vulnerability. The absence of nonce and capability checks on the shortcodes, while not explicitly flagged as a vulnerability in this specific analysis, is a concerning best practice to overlook, especially in conjunction with the output escaping issues.
Key Concerns
- Low output escaping percentage
- No nonce checks on entry points
- No capability checks on entry points
All in One News Scroll Security Vulnerabilities
All in One News Scroll Code Analysis
SQL Query Safety
Output Escaping
All in One News Scroll Attack Surface
Shortcodes 2
WordPress Hooks 6
Maintenance & Trust
All in One News Scroll Maintenance & Trust
Maintenance Signals
Community Trust
All in One News Scroll Alternatives
News Announcement Scroll
news-announcement-scroll
News Announcement Scroll is a simple vertical scroll news widget for your WordPress website. Easy to use & no coding knowledge required.
ScrollTick
scrolltick
This is the simple way to create scrolling text in your website.
Post Slider and Post Carousel with Post Vertical Scrolling Widget – A Responsive Post Slider
post-slider-and-carousel
Post Slider and Post Carousel display WordPress post in slider and carousel layouts with shortcode and Latest/Recent vertical post scrolling widget.
WP News and Scrolling Widgets
sp-news-and-widget
A quick, easy way to add an News custom post type, News widget, vertical scrolling news widget to WordPress. Also work with Gutenberg shortcode block.
Vertical News Scroller
vertical-news-scroller
Vertical News Scroller is a plugin for display vertical scrolling news for WordPress site. Admin can manage any number of news.
All in One News Scroll Developer Profile
4 plugins · 50 total installs
How We Detect All in One News Scroll
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/all-in-one-news-scroll/js/jquery.easing.min.js/wp-content/plugins/all-in-one-news-scroll/js/jquery.easy-ticker.js/wp-content/plugins/all-in-one-news-scroll/js/jquery.easing.min.js/wp-content/plugins/all-in-one-news-scroll/js/jquery.easy-ticker.jsHTML / DOM Fingerprints
vtickeritem-eventnews-eventnews_titleid="post-jQueryccdd[allinone-news][allinone-news-category]