
Information Reel Security & Risk Analysis
wordpress.org/plugins/information-reelThis plugin scroll the entered title, image, and description in your word press website. This is best way to announce your messages to user.
Is Information Reel Safe to Use in 2026?
Mostly Safe
Score 84/100Information Reel is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved. Keep it updated.
The information-reel plugin version 10.1 exhibits a mixed security posture. On the positive side, the static analysis reveals a very small attack surface with only one shortcode and no AJAX handlers, REST API routes, or cron events exposed to potential attackers. The plugin also demonstrates good practices regarding SQL queries, with 96% utilizing prepared statements, and includes some nonce checks. The absence of file operations and external HTTP requests further reduces potential risks.
However, a significant concern arises from the very low percentage (18%) of properly escaped output. This indicates a high potential for cross-site scripting (XSS) vulnerabilities, where user-supplied input might be rendered directly in the browser without adequate sanitization. While no critical or high severity taint flows were identified in the static analysis, the lack of output escaping is a fundamental security weakness that could be exploited. The plugin's history of one high-severity SQL injection vulnerability, although currently patched, suggests a past area of weakness that requires continued vigilance.
In conclusion, while the plugin has a limited attack surface and good SQL practices, the prevalent issue with output escaping presents a tangible risk. This, combined with a past SQL injection vulnerability, necessitates careful monitoring and potential code review to ensure that all output is properly sanitized to prevent XSS attacks. The absence of capability checks on any entry points also represents a missed opportunity for robust authorization.
Key Concerns
- Low output escaping percentage
- Past high severity SQL injection vulnerability
- No capability checks on entry points
Information Reel Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Information Reel <= 10.0 - Authenticated (Subscriber+) SQL Injection via Shortcode
Information Reel Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Information Reel Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
Information Reel Maintenance & Trust
Maintenance Signals
Community Trust
Information Reel Alternatives
Effect Maker
effect-maker
Extend Wordpress with this JavaScript web effect creation system.
Announcement ticker highlighter scroller
announcement-ticker-highlighter-scroller
This plugin will display the announcement with highlighter scroller. It gradually reveals each message into view from bottom to top.
ScrollTick
scrolltick
This is the simple way to create scrolling text in your website.
Job manager feed scroller
job-manager-feed-scroller
Get jobs added by plugin Job Manager and display them as scrolling text.
Text Scroller
text-scroller
Set Scrolling Message for website
Information Reel Developer Profile
52 plugins · 19K total installs
How We Detect Information Reel
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/information-reel/information-reel.phpinformation-reel/style.css?ver=10.1HTML / DOM Fingerprints
IR-regimageIR_divid="IRHolder"var IR = new Array()var objIR = ''var IR_scrollPos = ''var IR_numScrolls = ''var IR_heightOfElm = 'var IR_numberOfElm = '+4 more[information-reel group[information-reel group="WIDGET" length[information-reel group="WIDGET" length="125" display[information-reel group="WIDGET" length="125" display="3" height