WP fade in text news Security & Risk Analysis

wordpress.org/plugins/wp-fade-in-text-news

This plugin will create the fadein and out effect in the text. It is an superb excellent way to transition between announcements.

300 active installs v12.1 PHP + WP 3.4+ Updated Oct 28, 2023
fade-infadeinnewswidget
84
B · Generally Safe
CVEs total1
Unpatched0
Last CVEOct 30, 2023
Safety Verdict

Is WP fade in text news Safe to Use in 2026?

Mostly Safe

Score 84/100

WP fade in text news is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved. Keep it updated.

1 known CVELast CVE: Oct 30, 2023Updated 2yr ago
Risk Assessment

The plugin wp-fade-in-text-news v12.1 presents a mixed security posture. While it demonstrates good practices in minimizing its attack surface, with only one shortcode entry point and no unprotected AJAX handlers or REST API routes, and a strong adherence to prepared statements for SQL queries (97%), significant concerns arise from its output escaping. A mere 17% of outputs are properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the site. The plugin's vulnerability history reveals a past high-severity SQL Injection vulnerability, suggesting a pattern of potential weaknesses in handling user input for database operations, even though this specific instance is patched. The lack of capability checks is also a notable omission that could be exploited if any of the entry points were to gain unauthorized access. Overall, the plugin has strengths in its limited attack surface and SQL query sanitization, but the prevalent issue with output escaping and past SQL injection vulnerability necessitates caution.

Key Concerns

  • Low percentage of properly escaped outputs
  • Past high-severity SQL Injection vulnerability
  • No capability checks on entry points
Vulnerabilities
1

WP fade in text news Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

High
1

1 total CVE

CVE-2023-5437high · 8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

WP fade in text news <= 12.0 - Authenticated (Subscriber+) SQL Injection via Shortcode

Oct 30, 2023 Patched in 12.1 (85d)
Code Analysis
Analyzed Mar 16, 2026

WP fade in text news Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
28 prepared
Unescaped Output
40
8 escaped
Nonce Checks
4
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

97% prepared29 total queries

Output Escaping

17% escaped48 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
<content-management-show> (pages\content-management-show.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WP fade in text news Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[fadein-text] wp-fade-in-text-news.php:192
WordPress Hooks 6
actionplugins_loadedwp-fade-in-text-news.php:339
actionadmin_menuwp-fade-in-text-news.php:340
actionwp_enqueue_scriptswp-fade-in-text-news.php:341
actionplugins_loadedwp-fade-in-text-news.php:342
actionadmin_menuwp-fade-in-text-news.php:345
actionadmin_enqueue_scriptswp-fade-in-text-news.php:346
Maintenance & Trust

WP fade in text news Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedOct 28, 2023
PHP min version
Downloads30K

Community Trust

Rating94/100
Number of ratings3
Active installs300
Developer Profile

WP fade in text news Developer Profile

gopiplus

52 plugins · 19K total installs

76
trust score
Avg Security Score
83/100
Avg Patch Time
70 days
View full developer profile
Detection Fingerprints

How We Detect WP fade in text news

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-fade-in-text-news/
Script Paths
/wp-content/plugins/wp-fade-in-text-news/wp-fade-in-text-news.js
Version Parameters
wp-fade-in-text-news.js?ver=

HTML / DOM Fingerprints

CSS Classes
FadeIn_CSS
JS Globals
FadeIn_LinksFadeIn_TitlesFadeIn_FadeOutFadeIn_FadeInFadeIn_FadeFadeIn_FadeStep+2 more
Shortcode Output
<div id="FadeIn_CSS" style="padding:5px;"> <a href="#" id="FadeIn_Link">
FAQ

Frequently Asked Questions about WP fade in text news