Vertical News Scroller Security & Risk Analysis

wordpress.org/plugins/vertical-news-scroller

Vertical News Scroller is a plugin for display vertical scrolling news for WordPress site. Admin can manage any number of news.

5K active installs v1.25 PHP + WP 3.0+ Updated Dec 19, 2025
free-scrolling-news-wordpress-pluginscrolling-news-wordpressvertical-newsvertical-scrolling-newswordpress-dynamic-news
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Vertical News Scroller Safe to Use in 2026?

Generally Safe

Score 100/100

Vertical News Scroller has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The plugin 'vertical-news-scroller' v1.25 exhibits a generally strong security posture based on the static analysis and vulnerability history. The complete absence of known CVEs and a history free of past vulnerabilities suggest a well-maintained and security-conscious development process. The code signals indicate good practices, with 100% of SQL queries utilizing prepared statements, a high percentage of output properly escaped (83%), and the presence of nonce and capability checks. The limited attack surface, consisting of only one shortcode with no identified unprotected entry points, further bolsters its security.

However, a minor concern arises from the 83% output escaping rate. While high, this still leaves approximately 17% of outputs potentially unescaped. This could present a risk of cross-site scripting (XSS) vulnerabilities if user-supplied data is rendered directly without proper sanitization. The taint analysis revealed no critical or high severity flows, which is a positive indicator, but the limited scope of analysis (2 flows) means this doesn't definitively rule out all potential taint issues. The plugin's reliance on a single shortcode as its primary entry point, though currently appearing secure, means any future vulnerabilities introduced there could have a significant impact.

In conclusion, 'vertical-news-scroller' v1.25 is a strong candidate for a secure plugin, evidenced by its clean vulnerability history and robust internal security measures like prepared statements and capability checks. The primary area for improvement is ensuring 100% output escaping to mitigate the risk of XSS. The limited attack surface and absence of critical code signals are significant strengths, making the plugin a relatively low-risk option. Continued vigilance in development and testing for complete output sanitization is recommended.

Key Concerns

  • Unescaped output exists
Vulnerabilities
None known

Vertical News Scroller Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Vertical News Scroller Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
22 prepared
Unescaped Output
76
381 escaped
Nonce Checks
3
Capability Checks
7
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared22 total queries

Output Escaping

83% escaped457 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
vns_managenews (newsScroller.php:329)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Vertical News Scroller Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[print_vertical_news_scroll] newsScroller.php:15
WordPress Hooks 11
actionadmin_menunewsScroller.php:16
filterwidget_textnewsScroller.php:17
actionwidgets_initnewsScroller.php:19
actionplugins_loadednewsScroller.php:21
actionwp_enqueue_scriptsnewsScroller.php:22
actionupgrader_process_completenewsScroller.php:24
filterwidget_text_contentnewsScroller.php:26
filterthe_contentnewsScroller.php:28
filtermap_meta_capnewsScroller.php:35
filteruser_has_capnewsScroller.php:36
filterrender_blocknewsScroller.php:1687
Maintenance & Trust

Vertical News Scroller Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 19, 2025
PHP min version
Downloads175K

Community Trust

Rating86/100
Number of ratings16
Active installs5K
Developer Profile

Vertical News Scroller Developer Profile

Nks

19 plugins · 23K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
350 days
View full developer profile
Detection Fingerprints

How We Detect Vertical News Scroller

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/vertical-news-scroller/css/newsscrollcss.css/wp-content/plugins/vertical-news-scroller/js/jv.js/wp-content/plugins/vertical-news-scroller/js/i13_newsTicker.js
Version Parameters
newsscrollcss.css?ver=jv.js?ver=i13_newsTicker.js?ver=

HTML / DOM Fingerprints

Shortcode Output
[print_vertical_news_scroll]
FAQ

Frequently Asked Questions about Vertical News Scroller