
Newscodes – News, Magazine and Blog Elements – Free Version Security & Risk Analysis
wordpress.org/plugins/newscodes-news-magazine-and-blog-elementsWelcome to the future of your posts! Newscodes will revolutionize how you use and display your posts and improve the way your visitors interact with y …
Is Newscodes – News, Magazine and Blog Elements – Free Version Safe to Use in 2026?
Generally Safe
Score 85/100Newscodes – News, Magazine and Blog Elements – Free Version has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "newscodes-news-magazine-and-blog-elements" v2.0.3 exhibits a concerning security posture primarily due to a significant number of unprotected entry points into its AJAX handlers. While the static analysis shows no direct dangerous functions or SQL injection vulnerabilities, the presence of 3 AJAX handlers that lack any form of authentication or capability checks creates a substantial attack surface. This means that unauthenticated users could potentially interact with these handlers, leading to unintended actions or information disclosure. The taint analysis, though limited in scope (2 flows), identified unsanitized paths, which, combined with the unprotected AJAX handlers, raises a red flag for potential cross-site scripting (XSS) or other injection vulnerabilities if user-supplied data is passed through these paths without proper sanitization and validation within the AJAX handlers themselves.
The absence of any recorded vulnerabilities in the plugin's history is a positive indicator, suggesting that past versions may not have had exploitable flaws or that they were promptly patched. However, this historical data does not mitigate the risks identified in the current static and taint analysis. The plugin demonstrates good practices in terms of SQL query handling, exclusively using prepared statements, and a decent proportion of output escaping. Nevertheless, the critical weakness lies in the insecure handling of its AJAX endpoints, which significantly outweighs these strengths. The current version presents a moderate to high risk due to the readily available attack vectors that could be exploited by malicious actors.
Key Concerns
- 3 AJAX handlers without auth checks
- Taint flows with unsanitized paths
- Zero nonce checks on AJAX handlers
- Zero capability checks on AJAX handlers
- 63% of outputs properly escaped
Newscodes – News, Magazine and Blog Elements – Free Version Security Vulnerabilities
Newscodes – News, Magazine and Blog Elements – Free Version Release Timeline
Newscodes – News, Magazine and Blog Elements – Free Version Code Analysis
Output Escaping
Data Flow Analysis
Newscodes – News, Magazine and Blog Elements – Free Version Attack Surface
AJAX Handlers 3
WordPress Hooks 28
Maintenance & Trust
Newscodes – News, Magazine and Blog Elements – Free Version Maintenance & Trust
Maintenance Signals
Community Trust
Newscodes – News, Magazine and Blog Elements – Free Version Alternatives
Disable Author Pages
disable-author-pages
Disable the author pages
Per Page Sidebars
per-page-sidebars
The Per Page Sidebars (PPS) plugin allows blog administrators to create a unique sidebar for each Page. No template editing is required.
Query Posts
query-posts
A WordPress widget that gives you unlimited control over showing posts and pages.
Per Page Widgets
per-page-widgets
Control widget areas on a per-page / per-post basis.
Bloglovin Follow
bloglovin-follow
Allows the user to display their Bloglovin Follow button in posts/pages/ custom post types or in a widget.
Newscodes – News, Magazine and Blog Elements – Free Version Developer Profile
3 plugins · 170 total installs
How We Detect Newscodes – News, Magazine and Blog Elements – Free Version
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/newscodes-news-magazine-and-blog-elements/css/newscodes-style.css/wp-content/plugins/newscodes-news-magazine-and-blog-elements/css/nc-admin.css/wp-content/plugins/newscodes-news-magazine-and-blog-elements/js/newscodes-frontend.jsNewscodes - Free Version/wp-content/plugins/newscodes-news-magazine-and-blog-elements/js/newscodes-frontend.jsnewscodes-news-magazine-and-blog-elements/css/newscodes-style.css?ver=newscodes-news-magazine-and-blog-elements/css/nc-admin.css?ver=newscodes-news-magazine-and-blog-elements/js/newscodes-frontend.js?ver=HTML / DOM Fingerprints
nc-elementdata-nc-idNewscodesFrontend[nc-latest-posts[nc-tabs[nc-categories[nc-about