SuperMarquee | Lite Security & Risk Analysis

wordpress.org/plugins/supermarquee-wp-lite

Create stunning, fully customizable marquee effects in WordPress – lightweight, responsive, and built for performance.

20 active installs v1.0 PHP 7.2+ WP 6.0+ Updated Aug 8, 2025
animationimagemarqueeslidertext
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is SuperMarquee | Lite Safe to Use in 2026?

Generally Safe

Score 92/100

SuperMarquee | Lite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The Supermarquee WP Lite v1.0 plugin exhibits a strong security posture based on the provided static analysis. A significant strength is the complete absence of dangerous functions and the proper escaping of all output, which are critical for preventing common web vulnerabilities. The plugin also makes good use of prepared statements for its SQL queries, minimizing the risk of SQL injection. Furthermore, the lack of any recorded historical vulnerabilities, including CVEs, suggests a well-maintained and secure codebase.

While the overall security is impressive, there is one area for potential concern: the absence of capability checks on its single shortcode. Although the attack surface is minimal with only one entry point and no unprotected AJAX or REST API routes, a shortcode could potentially be used to inject or display sensitive information or trigger actions that require specific user permissions. This lack of authorization check, while minor given the limited attack surface, could represent a theoretical vector for privilege escalation or unauthorized data access if the shortcode's functionality were to be expanded in future versions or if an attacker could manipulate its input without proper checks.

In conclusion, Supermarquee WP Lite v1.0 is a commendably secure plugin with excellent adherence to best practices in output sanitization and SQL query handling. Its clean vulnerability history further reinforces its reliability. The primary, albeit minor, weakness lies in the lack of capability checks on its shortcode, a point that warrants attention to maintain this high security standard as the plugin evolves.

Key Concerns

  • Missing capability checks on shortcode
Vulnerabilities
None known

SuperMarquee | Lite Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

SuperMarquee | Lite Release Timeline

v1.0Current
Code Analysis
Analyzed Mar 16, 2026

SuperMarquee | Lite Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
4 prepared
Unescaped Output
0
387 escaped
Nonce Checks
4
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

67% prepared6 total queries

Output Escaping

100% escaped387 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
admin_page (includes\class-supewp82-supermarquee-wp-lite-admin.php:32)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

SuperMarquee | Lite Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[supermarquee-lite] includes\class-supewp82-supermarquee-wp-lite.php:4
WordPress Hooks 8
actionadmin_menuincludes\class-supewp82-supermarquee-wp-lite-admin.php:7
actionadmin_initincludes\class-supewp82-supermarquee-wp-lite-admin.php:8
actionwp_enqueue_scriptsincludes\class-supewp82-supermarquee-wp-lite.php:5
actionplugins_loadedsupermarquee-lite-plugin.php:29
actionadmin_enqueue_scriptssupermarquee-lite-plugin.php:67
actionadmin_noticessupermarquee-lite-plugin.php:82
actioninitsupermarquee-lite-plugin.php:177
actionwp_footersupermarquee-lite-plugin.php:189
Maintenance & Trust

SuperMarquee | Lite Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.6
Last updatedAug 8, 2025
PHP min version7.2
Downloads523

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

SuperMarquee | Lite Developer Profile

superplugin

1 plugin · 20 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SuperMarquee | Lite

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/supermarquee-wp-lite/assets/js/admin-script.js/wp-content/plugins/supermarquee-wp-lite/assets/js/SuperMarquee.js/wp-content/plugins/supermarquee-wp-lite/assets/css/supermarquee-admin-style.css
Version Parameters
/wp-content/plugins/supermarquee-wp-lite/assets/js/admin-script.js?ver=1.0/wp-content/plugins/supermarquee-wp-lite/assets/js/SuperMarquee.js?ver=1.0/wp-content/plugins/supermarquee-wp-lite/assets/css/supermarquee-admin-style.css?ver=1.0

HTML / DOM Fingerprints

CSS Classes
notice-successis-dismissible
Data Attributes
supermarquee_submitsupermarquee_idsupermarquee_marqueeTypesupermarquee_internalNamesupermarquee_compiled_settingssupermarquee_save+7 more
JS Globals
SP_SUPERMARUQUEES_LITE
FAQ

Frequently Asked Questions about SuperMarquee | Lite