Scroll rss excerpt Security & Risk Analysis

wordpress.org/plugins/scroll-rss-excerpt

With this plugin we can setup the RSS slider in our website. In the slider we can configure the title and excerpt.

50 active installs v5.0 PHP + WP 3.4+ Updated Dec 1, 2022
marqueevertical
63
C · Use Caution
CVEs total1
Unpatched1
Last CVEDec 29, 2025
Safety Verdict

Is Scroll rss excerpt Safe to Use in 2026?

Use With Caution

Score 63/100

Scroll rss excerpt has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Dec 29, 2025Updated 3yr ago
Risk Assessment

The 'scroll-rss-excerpt' v5.0 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and including a nonce check. There are no identified dangerous functions or file operations, and no external HTTP requests, which are all positive indicators. However, a significant concern is the 61% proper output escaping rate, leaving a substantial portion of outputs potentially vulnerable to cross-site scripting (XSS) attacks. The presence of one unsanitized path in the taint analysis, even without critical or high severity, warrants attention as it could be an entry point for further exploitation.

The plugin's vulnerability history is a critical red flag. With one known medium-severity CVE, specifically an XSS vulnerability, that is currently unpatched, this indicates a recurring pattern of input sanitization issues. The fact that the last vulnerability was dated in the future (2025-12-29) suggests a potential issue with the data accuracy for the vulnerability history, but the existence of an unpatched CVE itself is a serious risk. While the overall attack surface is small and lacks unauthenticated entry points, the combination of imperfect output escaping and an unpatched XSS vulnerability presents a clear and present danger.

In conclusion, while 'scroll-rss-excerpt' v5.0 has some commendable security practices, the unpatched XSS vulnerability and the considerable percentage of unescaped output significantly detract from its security. Users should be extremely cautious, and developers should prioritize addressing the outstanding CVE and improving output sanitization to mitigate potential risks.

Key Concerns

  • Unpatched CVE: Medium severity XSS
  • Output escaping: 39% not properly escaped
  • Taint analysis: Unsaniized path found
Vulnerabilities
1

Scroll rss excerpt Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-68892medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Scroll rss excerpt <= 5.0 - Reflected Cross-Site Scripting

Dec 29, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Scroll rss excerpt Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
11
17 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

61% escaped28 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

3 flows1 with unsanitized paths
srsse_control (scroll-rss-excerpt.php:446)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Scroll rss excerpt Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[scroll-rss-excerpt] scroll-rss-excerpt.php:526
WordPress Hooks 4
actionplugins_loadedscroll-rss-excerpt.php:524
actionplugins_loadedscroll-rss-excerpt.php:525
actionadmin_menuscroll-rss-excerpt.php:529
actionwp_enqueue_scriptsscroll-rss-excerpt.php:530
Maintenance & Trust

Scroll rss excerpt Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedDec 1, 2022
PHP min version
Downloads9K

Community Trust

Rating50/100
Number of ratings4
Active installs50
Developer Profile

Scroll rss excerpt Developer Profile

gopiplus@hotmail.com

8 plugins · 4K total installs

73
trust score
Avg Security Score
79/100
Avg Patch Time
69 days
View full developer profile
Detection Fingerprints

How We Detect Scroll rss excerpt

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/scroll-rss-excerpt/scroll-rss-excerpt.js
Script Paths
/wp-content/plugins/scroll-rss-excerpt/scroll-rss-excerpt.js

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Scroll rss excerpt