
PJ News Ticker Security & Risk Analysis
wordpress.org/plugins/pj-news-tickerPJ News Ticker is a small plugin that shows your most recent posts in a marquee style.
Is PJ News Ticker Safe to Use in 2026?
Generally Safe
Score 100/100PJ News Ticker has a strong security track record. Known vulnerabilities have been patched promptly.
The "pj-news-ticker" plugin v1.9.8 demonstrates a generally good security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is commendable. The high percentage of properly escaped output is also a strong positive indicator. However, the plugin does present a few areas of concern. The complete lack of nonce checks across all entry points is a significant weakness, as it leaves the plugin vulnerable to CSRF attacks if any functionality were to be modified or added without proper authorization checks in the future. Furthermore, the historical vulnerability data indicates a past medium-severity Cross-Site Scripting (XSS) vulnerability, even though it is currently patched. This suggests a potential for input sanitization issues, and while the current static analysis didn't reveal any unsanitized taint flows, it is a pattern worth noting for future analysis.
While the current version appears to have a limited attack surface and good coding practices in place, the historical XSS vulnerability and the complete absence of nonce checks are points that warrant caution. The plugin's strength lies in its limited attack surface and diligent output escaping. Its weakness lies in the potential for CSRF due to missing nonce checks and a past history of input sanitization issues. Overall, the plugin is in a relatively secure state for the analyzed version, but continuous monitoring and attention to these specific areas are advised.
Key Concerns
- Missing nonce checks on entry points
- Past medium severity CVE (XSS)
PJ News Ticker Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
PJ News Ticker <= 1.9.5 - Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode
PJ News Ticker Code Analysis
Output Escaping
PJ News Ticker Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
PJ News Ticker Maintenance & Trust
Maintenance Signals
Community Trust
PJ News Ticker Alternatives
News Ticker Widget for Elementor
news-ticker-widget-for-elementor
News ticker widget for elementor helps you showcase your latest news/posts in a marquee or slider format.
Simple Posts Ticker – Easy, Lightweight & Flexible
simple-posts-ticker
The Simple Posts Ticker plugin is a small tool that shows your most recent posts in a marquee style.
Advance News Ticker
advance-news-ticker
Provides flexible and advance news ticker. Display it via shortcode and more.
Bytecoder News Ticker
bytecoder-news-ticker
Bytecoder News Ticker is an awesome, super lightweight plugin for your wordpress website.
Lazy News Ticker
lazy-news-ticker
Lazy News Ticker is an awesome, super lightweight plugin for your wordpress website.
PJ News Ticker Developer Profile
1 plugin · 3K total installs
How We Detect PJ News Ticker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pj-news-ticker/pj-news-ticker.css/wp-content/plugins/pj-news-ticker/pj-news-ticker.js/wp-content/plugins/pj-news-ticker/pj-news-ticker.jspj-news-ticker/pj-news-ticker.css?ver=pj-news-ticker/pj-news-ticker.js?ver=HTML / DOM Fingerprints
pj-news-tickerpjntdata-speeddata-gapdata-hide-if-emptydata-targetdata-bg-colordata-label-bg-color+19 morepjnt