PJ News Ticker Security & Risk Analysis

wordpress.org/plugins/pj-news-ticker

PJ News Ticker is a small plugin that shows your most recent posts in a marquee style.

3K active installs v1.9.8 PHP + WP 4.6+ Updated Apr 30, 2025
jquery-news-tickermarqueenews-headlinesnews-ticker
100
A · Safe
CVEs total1
Unpatched0
Last CVEFeb 12, 2024
Safety Verdict

Is PJ News Ticker Safe to Use in 2026?

Generally Safe

Score 100/100

PJ News Ticker has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Feb 12, 2024Updated 11mo ago
Risk Assessment

The "pj-news-ticker" plugin v1.9.8 demonstrates a generally good security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is commendable. The high percentage of properly escaped output is also a strong positive indicator. However, the plugin does present a few areas of concern. The complete lack of nonce checks across all entry points is a significant weakness, as it leaves the plugin vulnerable to CSRF attacks if any functionality were to be modified or added without proper authorization checks in the future. Furthermore, the historical vulnerability data indicates a past medium-severity Cross-Site Scripting (XSS) vulnerability, even though it is currently patched. This suggests a potential for input sanitization issues, and while the current static analysis didn't reveal any unsanitized taint flows, it is a pattern worth noting for future analysis.

While the current version appears to have a limited attack surface and good coding practices in place, the historical XSS vulnerability and the complete absence of nonce checks are points that warrant caution. The plugin's strength lies in its limited attack surface and diligent output escaping. Its weakness lies in the potential for CSRF due to missing nonce checks and a past history of input sanitization issues. Overall, the plugin is in a relatively secure state for the analyzed version, but continuous monitoring and attention to these specific areas are advised.

Key Concerns

  • Missing nonce checks on entry points
  • Past medium severity CVE (XSS)
Vulnerabilities
1

PJ News Ticker Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-25094medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

PJ News Ticker <= 1.9.5 - Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode

Feb 12, 2024 Patched in 1.9.6 (246d)
Code Analysis
Analyzed Mar 16, 2026

PJ News Ticker Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
60 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

95% escaped63 total outputs
Attack Surface

PJ News Ticker Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[pj-news-ticker] pj-news-ticker.php:187
WordPress Hooks 5
actionadmin_initadmin\pj-news-ticker-admin.php:12
actionadmin_menuadmin\pj-news-ticker-admin.php:13
actionadmin_enqueue_scriptsadmin\pj-news-ticker-admin.php:14
actionwp_enqueue_scriptspj-news-ticker.php:181
actionwp_body_openpj-news-ticker.php:182
Maintenance & Trust

PJ News Ticker Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.0
Last updatedApr 30, 2025
PHP min version
Downloads78K

Community Trust

Rating90/100
Number of ratings6
Active installs3K
Developer Profile

PJ News Ticker Developer Profile

Primitiv Media

1 plugin · 3K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
246 days
View full developer profile
Detection Fingerprints

How We Detect PJ News Ticker

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/pj-news-ticker/pj-news-ticker.css/wp-content/plugins/pj-news-ticker/pj-news-ticker.js
Script Paths
/wp-content/plugins/pj-news-ticker/pj-news-ticker.js
Version Parameters
pj-news-ticker/pj-news-ticker.css?ver=pj-news-ticker/pj-news-ticker.js?ver=

HTML / DOM Fingerprints

CSS Classes
pj-news-tickerpjnt
Data Attributes
data-speeddata-gapdata-hide-if-emptydata-targetdata-bg-colordata-label-bg-color+19 more
JS Globals
pjnt
FAQ

Frequently Asked Questions about PJ News Ticker