Latest News Marquee Security & Risk Analysis

wordpress.org/plugins/latest-news-marquee

Plugin for displaying latest news from two famous Bangladeshi news paper Daily Prothom Alo & Daily Star.

20 active installs v1.0 PHP + WP 3.0.1+ Updated Mar 14, 2015
dailystarlatest-newsmarqueenews-tickerprothom-alo
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Latest News Marquee Safe to Use in 2026?

Generally Safe

Score 85/100

Latest News Marquee has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The "latest-news-marquee" plugin v1.0 demonstrates a generally good security posture due to the absence of known vulnerabilities and a clean vulnerability history. The static analysis reveals a small attack surface with no AJAX handlers or REST API routes, which are common entry points for attacks. Furthermore, the plugin utilizes prepared statements for all its SQL queries, indicating a robust defense against SQL injection. The absence of dangerous functions, file operations, and external HTTP requests is also a positive sign. However, there are some areas for improvement. The relatively low percentage of properly escaped output (43%) is a concern, as it could potentially lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not handled carefully before being displayed. Additionally, the lack of nonce checks and capability checks on its single shortcode entry point is a significant weakness. While there are no AJAX or REST API routes to secure, a shortcode is still an entry point that could be leveraged if it handles user-controllable data or performs sensitive actions, and the absence of these basic security measures is a notable oversight.

Key Concerns

  • Unescaped output detected
  • Missing nonce checks on shortcode
  • Missing capability checks on shortcode
Vulnerabilities
None known

Latest News Marquee Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Latest News Marquee Release Timeline

v1.1
Code Analysis
Analyzed Mar 16, 2026

Latest News Marquee Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

43% escaped7 total outputs
Attack Surface

Latest News Marquee Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[news_paper] view\lnm-front.php:8
WordPress Hooks 3
actionadmin_menuadmin\lnm-admin.php:6
actionadmin_initadmin\lnm-admin.php:7
actionwp_enqueue_scriptsinc\lnm.php:13
Maintenance & Trust

Latest News Marquee Maintenance & Trust

Maintenance Signals

WordPress version tested4.1.42
Last updatedMar 14, 2015
PHP min version
Downloads6K

Community Trust

Rating100/100
Number of ratings2
Active installs20
Developer Profile

Latest News Marquee Developer Profile

Hizbul Bahar

2 plugins · 30 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Latest News Marquee

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/latest-news-marquee/assets/js/lnm-js.js/wp-content/plugins/latest-news-marquee/assets/js/jquery.newsTicker.min.js/wp-content/plugins/latest-news-marquee/assets/css/lnm-style.css
Script Paths
/wp-content/plugins/latest-news-marquee/assets/js/lnm-js.js/wp-content/plugins/latest-news-marquee/assets/js/jquery.newsTicker.min.js

HTML / DOM Fingerprints

CSS Classes
display-marqueemarquee-labelnewstickerlatest-news
Data Attributes
data-lnm-label-colordata-lnm-news-color
Shortcode Output
<div class="display-marquee"><label class="marquee-label"<ul class="newsticker latest-news">
FAQ

Frequently Asked Questions about Latest News Marquee