
News Tick-O-Matic Security & Risk Analysis
wordpress.org/plugins/news-tick-o-maticAnimated news ticker—display the newest news a smoothly scrolling sidebar.
Is News Tick-O-Matic Safe to Use in 2026?
Generally Safe
Score 85/100News Tick-O-Matic has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "news-tick-o-matic" plugin, in version 0.2, exhibits a mixed security posture. On the positive side, it demonstrates good practices in database interaction by exclusively using prepared statements for SQL queries, and there are no reported vulnerabilities or CVEs associated with it, suggesting a relatively stable history. Furthermore, the static analysis reveals a minimal attack surface with no exposed AJAX handlers, REST API routes, shortcodes, or cron events that are not properly secured. However, significant concerns arise from the use of the `create_function` dangerous function, which is a known security risk and can lead to arbitrary code execution if not handled with extreme care and sanitization. Additionally, the extremely low percentage of properly escaped output (16%) indicates a high likelihood of Cross-Site Scripting (XSS) vulnerabilities across many of its output operations. The absence of nonce and capability checks on its entry points, although the entry points are zero, is a potential risk should any be added in the future without proper security considerations. The lack of taint analysis results also prevents a thorough understanding of potential data flow vulnerabilities.
Key Concerns
- Dangerous function used (create_function)
- Low percentage of properly escaped output
- No nonce checks on entry points
- No capability checks on entry points
News Tick-O-Matic Security Vulnerabilities
News Tick-O-Matic Release Timeline
News Tick-O-Matic Code Analysis
Dangerous Functions Found
Output Escaping
News Tick-O-Matic Attack Surface
WordPress Hooks 3
Maintenance & Trust
News Tick-O-Matic Maintenance & Trust
Maintenance Signals
Community Trust
News Tick-O-Matic Alternatives
Simple Posts Ticker – Easy, Lightweight & Flexible
simple-posts-ticker
The Simple Posts Ticker plugin is a small tool that shows your most recent posts in a marquee style.
news ticker benaceur
news-ticker-benaceur
This plugin allow you to display the latest posts or latest comments in a bar with twenty seven beautiful animations and effects...
FikraTicker
fikraticker
FikraTicker is a simple and multi-effects newsticker that displays the recent news/posts on your website/blog
FYP News Ticker – Scrolling News Banner & Announcement Bar for WordPress
fyp-news-ticker
Grab attention with scrolling news banners. 3 professional templates, drag-and-drop builder, scheduled announcements. No coding needed.
News Ticker for Elementor
advanced-news-ticker
Advanced News Ticker offers 8 customizable layouts to display news, headlines, and breaking news, fully integrated with Elementor.
News Tick-O-Matic Developer Profile
3 plugins · 140 total installs
How We Detect News Tick-O-Matic
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/news-tick-o-matic/js/jcarousellite_1.0.1.min.js/wp-content/plugins/news-tick-o-matic/css/style.cssjcarousellite_1.0.1.min.jsjcarousellite_1.0.1.min.js?ver=1.0.1style.css?ver=1.0HTML / DOM Fingerprints
NewsTickOMaticnewsboxlatestnewsnewsid="news-tick-o-matic-ticker"class="latestnews"class="news"class="date"news_scripts<div class="newsbox"><div id="-ticker" class="latestnews"><ul class="news">