
Scroll rss excerpt Security & Risk Analysis
wordpress.org/plugins/scroll-rss-excerptWith this plugin we can setup the RSS slider in our website. In the slider we can configure the title and excerpt.
Is Scroll rss excerpt Safe to Use in 2026?
Use With Caution
Score 63/100Scroll rss excerpt has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The 'scroll-rss-excerpt' v5.0 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and including a nonce check. There are no identified dangerous functions or file operations, and no external HTTP requests, which are all positive indicators. However, a significant concern is the 61% proper output escaping rate, leaving a substantial portion of outputs potentially vulnerable to cross-site scripting (XSS) attacks. The presence of one unsanitized path in the taint analysis, even without critical or high severity, warrants attention as it could be an entry point for further exploitation.
The plugin's vulnerability history is a critical red flag. With one known medium-severity CVE, specifically an XSS vulnerability, that is currently unpatched, this indicates a recurring pattern of input sanitization issues. The fact that the last vulnerability was dated in the future (2025-12-29) suggests a potential issue with the data accuracy for the vulnerability history, but the existence of an unpatched CVE itself is a serious risk. While the overall attack surface is small and lacks unauthenticated entry points, the combination of imperfect output escaping and an unpatched XSS vulnerability presents a clear and present danger.
In conclusion, while 'scroll-rss-excerpt' v5.0 has some commendable security practices, the unpatched XSS vulnerability and the considerable percentage of unescaped output significantly detract from its security. Users should be extremely cautious, and developers should prioritize addressing the outstanding CVE and improving output sanitization to mitigate potential risks.
Key Concerns
- Unpatched CVE: Medium severity XSS
- Output escaping: 39% not properly escaped
- Taint analysis: Unsaniized path found
Scroll rss excerpt Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Scroll rss excerpt <= 5.0 - Reflected Cross-Site Scripting
Scroll rss excerpt Code Analysis
Output Escaping
Data Flow Analysis
Scroll rss excerpt Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
Scroll rss excerpt Maintenance & Trust
Maintenance Signals
Community Trust
Scroll rss excerpt Alternatives
Vertical marquee post title
vertical-marquee-post-title
If you want your post title to move vertically (scroll upward or downwards) in the screen use this plugin.
Easy Accordion – Responsive Accordion FAQ Builder and Product FAQ
easy-accordion-free
Easily create Accordions, FAQs, and Product FAQ for WooCommerce. Customizable drag & drop WordPress FAQ builder plugin.
OoohBoi Steroids for Elementor
ooohboi-steroids-for-elementor
Boost your Elementor with some fresh and yet innovative options.
Cool Timeline (Horizontal & Vertical Timeline)
cool-timeline
Showcase your story or company history, events, and roadmap in an interactive timeline using the powerful Cool Timeline plugin.
Vertical Timeline Widget for Elementor
3r-elementor-timeline-widget
Use a vertical timeline widget for Elementor to showcase your journey, story, milestones, or roadmap directly inside Elementor.
Scroll rss excerpt Developer Profile
8 plugins · 4K total installs
How We Detect Scroll rss excerpt
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/scroll-rss-excerpt/scroll-rss-excerpt.js/wp-content/plugins/scroll-rss-excerpt/scroll-rss-excerpt.js