
Mhr Post Ticker Security & Risk Analysis
wordpress.org/plugins/mhr-post-tickerIt is a post ticker plugin and will be scrolling in the headline.
Is Mhr Post Ticker Safe to Use in 2026?
Generally Safe
Score 99/100Mhr Post Ticker has a strong security track record. Known vulnerabilities have been patched promptly.
The 'mhr-post-ticker' plugin version 1.2 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, file operations, external HTTP requests, and the complete proper escaping of all output are significant strengths. Taint analysis showing zero flows with unsanitized paths further indicates a well-sanitized codebase. The plugin's single entry point, a shortcode, is not explicitly flagged as unprotected, suggesting that its implementation likely includes necessary security checks.
However, the plugin does have a history of vulnerabilities, with one medium-severity CVE recorded, specifically related to Cross-site Scripting (XSS). While this vulnerability is currently patched, its existence indicates a past weakness in input handling or output neutralization that required correction. The absence of nonce checks and capability checks on its identified entry points (the shortcode) could be a potential concern, even if the static analysis did not identify exploitable flows. This lack of explicit checks could become a risk if the shortcode's functionality evolves or if its context within WordPress changes, potentially opening it up to unauthorized actions or script injection.
In conclusion, while 'mhr-post-ticker' v1.2 demonstrates good secure coding practices in many areas, the past XSS vulnerability and the lack of explicit nonce/capability checks on its shortcode warrant careful consideration. Developers should remain vigilant about input sanitization and output escaping, and ideally, implement proper authorization checks on all shortcode usage to mitigate any future risks.
Key Concerns
- Past medium severity CVE (XSS)
- No nonce checks on shortcode
- No capability checks on shortcode
Mhr Post Ticker Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Mhr Post Ticker <= 1.1 - Authenticated (Admin+) Stored Cross-Site Scripting
Mhr Post Ticker Code Analysis
Output Escaping
Mhr Post Ticker Attack Surface
Shortcodes 1
WordPress Hooks 9
Maintenance & Trust
Mhr Post Ticker Maintenance & Trust
Maintenance Signals
Community Trust
Mhr Post Ticker Alternatives
Post Ticker Ultimate
ticker-ultimate
Add and display horizontal or vertical post ticker on website that work with WordPress posts with the help of shortcode or Gutenberg block.
Post Slider and Post Carousel with Post Vertical Scrolling Widget – A Responsive Post Slider
post-slider-and-carousel
Post Slider and Post Carousel display WordPress post in slider and carousel layouts with shortcode and Latest/Recent vertical post scrolling widget.
WP News and Scrolling Widgets
sp-news-and-widget
A quick, easy way to add an News custom post type, News widget, vertical scrolling news widget to WordPress. Also work with Gutenberg shortcode block.
Text Scroll Widget
text-scrolling-widget
Text Scroll Widget is a plugin to automatically scroll up the content inserted in the description area of the widget.
rss scroller
rss-scroller
This plugin will display RSS feed with simple scroller or ticker. It gradually reveals each item into view from left to right.
Mhr Post Ticker Developer Profile
9 plugins · 1K total installs
How We Detect Mhr Post Ticker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mhr-post-ticker/admin/css/mhr-post-ticker-admin.css/wp-content/plugins/mhr-post-ticker/admin/js/mhr-post-ticker-admin.js/wp-content/plugins/mhr-post-ticker/public/css/mhr-post-ticker-public.css/wp-content/plugins/mhr-post-ticker/public/js/mhr-post-ticker-public.js/wp-content/plugins/mhr-post-ticker/admin/js/mhr-post-ticker-admin.js/wp-content/plugins/mhr-post-ticker/public/js/mhr-post-ticker-public.jsmhr-post-ticker/admin/css/mhr-post-ticker-admin.css?ver=mhr-post-ticker/admin/js/mhr-post-ticker-admin.js?ver=mhr-post-ticker/public/css/mhr-post-ticker-public.css?ver=mhr-post-ticker/public/js/mhr-post-ticker-public.js?ver=HTML / DOM Fingerprints
mhr-post-ticker-containermhr-post-ticker-item<!-- MHR Post Ticker Start --><!-- MHR Post Ticker End -->data-mhr-post-ticker-speeddata-mhr-post-ticker-pauseMhrPostTickermhrPostTicker[mhr_post_ticker]