News Ticker Widget for Elementor Security & Risk Analysis

wordpress.org/plugins/news-ticker-widget-for-elementor

News ticker widget for elementor helps you showcase your latest news/posts in a marquee or slider format.

4K active installs v1.3.7 PHP 7.0+ WP 5.9+ Updated Dec 10, 2025
elementor-news-tickermarqueenews-headlinesnews-tickerpost-ticker
99
A · Safe
CVEs total1
Unpatched0
Last CVEJan 7, 2025
Safety Verdict

Is News Ticker Widget for Elementor Safe to Use in 2026?

Generally Safe

Score 99/100

News Ticker Widget for Elementor has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jan 7, 2025Updated 3mo ago
Risk Assessment

The 'news-ticker-widget-for-elementor' plugin v1.3.7 exhibits a mixed security posture. On the positive side, it demonstrates strong practices regarding SQL queries, exclusively using prepared statements, and a high percentage of output escaping, which mitigates common cross-site scripting (XSS) risks. The absence of file operations and external HTTP requests also reduces potential attack vectors. However, a significant concern arises from the presence of four AJAX handlers, all of which lack authentication checks. This creates a substantial unprotected attack surface, potentially allowing unauthenticated users to trigger plugin functionalities, which could lead to unintended consequences or provide an entry point for further exploitation.

The vulnerability history shows one previously known CVE, which has since been patched. The nature of the common vulnerability type (XSS) aligns with the potential risks posed by the unprotected AJAX endpoints, as improper input handling in these handlers could facilitate XSS attacks if not properly sanitized. While the current version has no unpatched vulnerabilities, the historical presence of XSS and the current lack of authentication on AJAX handlers indicate a recurring area of weakness that needs careful attention. The plugin's strengths lie in its secure database interactions and output handling, but its security is notably compromised by the unprotected AJAX endpoints, presenting a clear and present risk.

Key Concerns

  • Unprotected AJAX handlers
  • Historically known CVE (patched)
Vulnerabilities
1

News Ticker Widget for Elementor Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-22812medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

News Ticker Widget for Elementor <= 1.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

Jan 7, 2025 Patched in 1.3.3 (8d)
Code Analysis
Analyzed Mar 16, 2026

News Ticker Widget for Elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
32 escaped
Nonce Checks
0
Capability Checks
4
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

97% escaped33 total outputs
Attack Surface
4 unprotected

News Ticker Widget for Elementor Attack Surface

Entry Points4
Unprotected4

AJAX Handlers 4

authwp_ajax_user_dismiss_noticeelementor-news-ticker.php:134
noprivwp_ajax_user_dismiss_noticeelementor-news-ticker.php:135
authwp_ajax_disable_noticeelementor-news-ticker.php:152
noprivwp_ajax_disable_noticeelementor-news-ticker.php:153
WordPress Hooks 8
actionwp_enqueue_scriptselementor-news-ticker.php:25
actionelementor/widgets/registerelementor-news-ticker.php:29
actionadmin_noticeselementor-news-ticker.php:54
actionadmin_noticeselementor-news-ticker.php:59
actionplugins_loadedelementor-news-ticker.php:63
actionadmin_noticeselementor-news-ticker.php:119
actionadmin_headelementor-news-ticker.php:194
actionelementor/initinc\elementor-helper.php:15
Maintenance & Trust

News Ticker Widget for Elementor Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 10, 2025
PHP min version7.0
Downloads38K

Community Trust

Rating80/100
Number of ratings5
Active installs4K
Developer Profile

News Ticker Widget for Elementor Developer Profile

Aezaz Shaikh

4 plugins · 4K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
8 days
View full developer profile
Detection Fingerprints

How We Detect News Ticker Widget for Elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/news-ticker-widget-for-elementor/assets/css/ele-news-ticker.css/wp-content/plugins/news-ticker-widget-for-elementor/assets/css/ticker.css/wp-content/plugins/news-ticker-widget-for-elementor/assets/js/ticker.js
Script Paths
/wp-content/plugins/news-ticker-widget-for-elementor/assets/js/ticker.js
Version Parameters
/wp-content/plugins/news-ticker-widget-for-elementor/assets/css/ele-news-ticker.css?ver=1.0.0/wp-content/plugins/news-ticker-widget-for-elementor/assets/css/ticker.css?ver=1.0.0/wp-content/plugins/news-ticker-widget-for-elementor/assets/js/ticker.js?ver=1.0

HTML / DOM Fingerprints

JS Globals
ajax_object
FAQ

Frequently Asked Questions about News Ticker Widget for Elementor