Slider Text Scroll Security & Risk Analysis

wordpress.org/plugins/slider-text-scroll

Easy to add Slider Text Scroll via shortcode [sts] for every WordPress theme. Slider Text Scroll plugin will help you to enable Slider Text Scroll is …

300 active installs v1.1.1 PHP + WP 5.2+ Updated Feb 10, 2025
carouselslider-text-scrolltext-carouseltext-scrolltext-slider
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Slider Text Scroll Safe to Use in 2026?

Generally Safe

Score 92/100

Slider Text Scroll has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "slider-text-scroll" plugin v1.1.1 exhibits a mixed security posture. On the positive side, it shows strong adherence to secure coding practices by utilizing prepared statements for all SQL queries and a high percentage of properly escaped output. The absence of file operations and external HTTP requests also reduces potential attack vectors. Furthermore, the plugin has no recorded vulnerabilities, suggesting a history of stable and secure development.

However, significant concerns arise from the attack surface. The plugin exposes two AJAX handlers, both of which lack authentication checks. This creates a direct entry point for unauthenticated attackers to potentially trigger code execution or manipulate plugin functionality. The lack of nonce checks on these AJAX handlers further exacerbates this risk, making them susceptible to Cross-Site Request Forgery (CSRF) attacks. The absence of taint analysis results and the limited attack surface analysis (0 flows analyzed) make it difficult to definitively assess the risk of more complex vulnerabilities.

In conclusion, while the plugin demonstrates good practices in database interaction and output handling, the unprotected AJAX endpoints represent a clear and present security risk. The lack of historical vulnerabilities is a positive indicator, but it doesn't mitigate the immediate dangers posed by the exposed AJAX handlers. Users should be aware of these risks and consider whether the functionality provided by the plugin justifies the potential exposure.

Key Concerns

  • Unprotected AJAX handlers
  • AJAX handlers without nonce checks
  • Limited taint analysis data
Vulnerabilities
None known

Slider Text Scroll Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Slider Text Scroll Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
42
225 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

84% escaped267 total outputs
Attack Surface
2 unprotected

Slider Text Scroll Attack Surface

Entry Points4
Unprotected2

AJAX Handlers 2

authwp_ajax_ests_its_get_cat_ids_by_post_typepost_type_infinity_scroll.php:367
noprivwp_ajax_ests_its_get_cat_ids_by_post_typepost_type_infinity_scroll.php:368

Shortcodes 2

[its] post_type_infinity_scroll.php:164
[sts] slider-text-scroll.php:206
WordPress Hooks 5
actioninitpost_type_infinity_scroll.php:98
actionadmin_enqueue_scriptsslider-text-scroll.php:116
actionadmin_menuslider-text-scroll.php:120
actionwp_enqueue_scriptsslider-text-scroll.php:179
actionwp_enqueue_scriptsslider-text-scroll.php:202
Maintenance & Trust

Slider Text Scroll Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedFeb 10, 2025
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings2
Active installs300
Developer Profile

Slider Text Scroll Developer Profile

Tanvir Md. Al Amin

2 plugins · 310 total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Slider Text Scroll

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/slider-text-scroll/css/sts-admin-style.css/wp-content/plugins/slider-text-scroll/js/sts.marquee.min.js/wp-content/plugins/slider-text-scroll/js/sts.typed.js/wp-content/plugins/slider-text-scroll/js/ests_admin_custom.js/wp-content/plugins/slider-text-scroll/css/sts-style.css/wp-content/plugins/slider-text-scroll/js/ests_custom.js
Script Paths
js/sts.marquee.min.jsjs/sts.typed.jsjs/ests_admin_custom.jsjs/ests_custom.js
Version Parameters
slider-text-scroll/css/sts-admin-style.css?ver=slider-text-scroll/js/sts.marquee.min.js?ver=slider-text-scroll/js/sts.typed.js?ver=slider-text-scroll/js/ests_admin_custom.js?ver=slider-text-scroll/css/sts-style.css?ver=slider-text-scroll/js/ests_custom.js?ver=

HTML / DOM Fingerprints

CSS Classes
marquee_texthero_title
HTML Comments
Plugin Option Page Style >>>> Dashboard Left side menu <<<<
Data Attributes
data-tDirdata-tDurdata-tGapdata-visidata-stTextdata-stTypeSpeed+4 more
JS Globals
estsObjAdminestsCustomData
FAQ

Frequently Asked Questions about Slider Text Scroll