
SM News Ticker Security & Risk Analysis
wordpress.org/plugins/sm-news-tickerThe SM News Tickr is a wordpress plugin to show post as Jquery News Ticker. It is a very nice Ticker. jQuery News Ticker used to show the letest or im …
Is SM News Ticker Safe to Use in 2026?
Generally Safe
Score 85/100SM News Ticker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "sm-news-ticker" v1.0.0 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is commendable. Furthermore, the plugin uses prepared statements for all SQL queries and the majority of its output is properly escaped, which are excellent security practices. The lack of any recorded vulnerabilities or CVEs in its history suggests a mature and well-maintained codebase.
However, there are several areas that warrant attention. The plugin has a total of 1 entry point, which is a shortcode, and it lacks any capability checks or nonce checks. While the static analysis did not find any taint flows or unsanitized paths, the absence of these essential security measures on its single entry point is a significant concern. This could leave the plugin vulnerable to various attacks if the shortcode's functionality is not inherently secure or if malicious input can be injected and processed without proper validation.
In conclusion, while the plugin avoids common pitfalls like raw SQL and dangerous functions, the lack of authentication and authorization checks on its shortcode is a notable weakness. The good practices observed in SQL handling and output escaping are positive, but they do not fully mitigate the risk introduced by the unprotected entry point. A comprehensive security audit that focuses on the shortcode's implementation would be beneficial.
Key Concerns
- Missing capability checks
- Missing nonce checks
- Unescaped output (20% of outputs)
SM News Ticker Security Vulnerabilities
SM News Ticker Code Analysis
Output Escaping
SM News Ticker Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
SM News Ticker Maintenance & Trust
Maintenance Signals
Community Trust
SM News Ticker Alternatives
WP Shortcodes Plugin — Shortcodes Ultimate
shortcodes-ultimate
A comprehensive collection of visual components for your site
MW WP Form
mw-wp-form
MW WP Form is shortcode base contact form plugin. This plugin have many features. For example you can use many validation rules, inquiry data saving, …
Shortcoder — Create Shortcodes for Anything
shortcoder
Create custom "Shortcodes" easily for HTML, JavaScript, CSS code snippets and use the shortcodes within posts, pages & widgets
Display Posts – Easy lists, grids, navigation, and more
display-posts-shortcode
Add a listing of content on your website using a simple shortcode. Filter the results by category, author, and more.
WP Show Posts
wp-show-posts
Add posts to your website from any post type using a simple shortcode.
SM News Ticker Developer Profile
10 plugins · 650 total installs
How We Detect SM News Ticker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sm-news-ticker/assets/includes/jquery.ticker.js/wp-content/plugins/sm-news-ticker/assets/styles/ticker-style.css/wp-content/plugins/sm-news-ticker/assets/styles/admin.css/wp-content/plugins/sm-news-ticker/assets/includes/jquery.ticker.jsHTML / DOM Fingerprints
js-hiddennews-itemid="js-news"SMjQ=jQuery.noConflict();<ul id="js-news" class="js-hidden"><li class="news-item">