
News Announcement Scroll Security & Risk Analysis
wordpress.org/plugins/news-announcement-scrollNews Announcement Scroll is a simple vertical scroll news widget for your WordPress website. Easy to use & no coding knowledge required.
Is News Announcement Scroll Safe to Use in 2026?
Mostly Safe
Score 84/100News Announcement Scroll is generally safe to use though it hasn't been updated recently. 2 past CVEs were resolved. Keep it updated.
The 'news-announcement-scroll' plugin version 9.1.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and performing file operations and external HTTP requests securely (or not at all). The presence of nonce and capability checks, while not comprehensive, indicates an awareness of security measures. However, significant concerns arise from the output escaping, where only 44% of outputs are properly escaped, leaving a substantial portion vulnerable to Cross-Site Scripting (XSS) attacks. The vulnerability history is also a red flag, with two known Common Vulnerabilities and Exposures (CVEs) in the past, specifically related to SQL Injection and XSS. Although currently unpatched CVEs are zero, the recurring nature of these vulnerability types suggests a potential for future exploits if output sanitization is not addressed. While the static analysis reveals no critical taint flows or unsanitized paths, the high percentage of unescaped output coupled with past XSS vulnerabilities presents a notable risk. The plugin has a limited attack surface with only one shortcode, and importantly, no unprotected entry points identified, which mitigates some immediate risk. Overall, while the plugin is built on some secure foundations, the insufficient output escaping is a critical weakness that could be exploited, especially considering its historical vulnerability patterns.
Key Concerns
- High percentage of unescaped output
- History of SQL Injection vulnerabilities
- History of Cross-Site Scripting vulnerabilities
News Announcement Scroll Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
News Announcement Scroll <= 9.0.0 - Authenticated (Contributor+) SQL Injection via Shortcode
News Announcement Scroll <= 8.8.8 - Authenticated (Admininstrator+) Stored Cross-Site Scripting
News Announcement Scroll Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
News Announcement Scroll Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
News Announcement Scroll Maintenance & Trust
Maintenance Signals
Community Trust
News Announcement Scroll Alternatives
News, Magazine and Blog Elements
news-magazine-and-blog-elements
News, Magazine and Blog Elements is shipped as Visual Composer addon , Page builder Widgets, Widgets & Shortcode.
WP News and Scrolling Widgets
sp-news-and-widget
A quick, easy way to add an News custom post type, News widget, vertical scrolling news widget to WordPress. Also work with Gutenberg shortcode block.
Custom News Widget
custom-news-widget
Creates a widget which renders posts from News post type.
Simple News and Slider
simple-news-list-and-slider
A quick, easy and simple way to add an News custom post type, vertical scrolling news list to Wordpress. Also work with Gutenberg shortcode block.
Vertical News Scroller
vertical-news-scroller
Vertical News Scroller is a plugin for display vertical scrolling news for WordPress site. Admin can manage any number of news.
News Announcement Scroll Developer Profile
9 plugins · 132K total installs
How We Detect News Announcement Scroll
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/news-announcement-scroll/gAnnounce/gAnnounce.js/wp-content/plugins/news-announcement-scroll/gAnnounce/gAnnounceform.js/wp-content/plugins/news-announcement-scroll/gAnnounce/noenter.js/wp-content/plugins/news-announcement-scroll/pages/content-management-edit.php/wp-content/plugins/news-announcement-scroll/pages/content-management-add.php/wp-content/plugins/news-announcement-scroll/pages/content-setting.php/wp-content/plugins/news-announcement-scroll/pages/content-management-show.phpgAnnounce/gAnnounce.jsgAnnounce/gAnnounceform.jsgAnnounce/noenter.jsnews-announcement-scroll/gAnnounce/gAnnounce.js?ver=news-announcement-scroll/gAnnounce/gAnnounceform.js?ver=news-announcement-scroll/gAnnounce/noenter.js?ver=HTML / DOM Fingerprints
<!-- IMPORTANT: If you use this plugin for commercial purpose, you MUST buy the commercial version --><!-- It is a simple and easy way to display news or announcements --><!-- It scrolls vertically --><!-- The widget displays an announcement -->+2 moredata-gannouncerdata-iddata-textdata-linkdata-orderdata-status+3 moregNewsAnnouncementtitlegNewsAnnouncementfontgNewsAnnouncementfontsizegNewsAnnouncementfontweightgNewsAnnouncementfontcolorgNewsAnnouncementwidth+10 more