
Wp-marquee Security & Risk Analysis
wordpress.org/plugins/wp-marqueeA very simple but useful widget, that use jquery to make the effect transition, you can chose the category and number of titles to display.
Is Wp-marquee Safe to Use in 2026?
Generally Safe
Score 85/100Wp-marquee has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-marquee" v1.0 plugin, based on the provided static analysis, exhibits a mixed security posture. Its strengths lie in the complete absence of SQL injection vulnerabilities due to the exclusive use of prepared statements and a lack of file operations or external HTTP requests. Furthermore, the static analysis did not identify any critical or high severity taint flows, which is a positive indicator. The plugin also has no recorded historical vulnerabilities, suggesting a potentially stable and well-maintained codebase in that regard.
However, there are notable areas for improvement. The presence of the `create_function` in the code signals a potential risk. While not directly leading to a vulnerability in this analysis, `create_function` is deprecated and can be a source of security issues, particularly if user-supplied data is used within it. More concerning is the significantly low percentage (25%) of properly escaped output. This indicates a high likelihood of cross-site scripting (XSS) vulnerabilities, where unsanitized data displayed to users could be exploited.
In conclusion, while the plugin avoids common severe vulnerabilities like SQL injection and has a clean vulnerability history, the substantial amount of unescaped output represents a significant security weakness that requires immediate attention. The use of `create_function` is a secondary concern that should also be addressed to improve overall code quality and security.
Key Concerns
- High percentage of unescaped output
- Use of dangerous function 'create_function'
Wp-marquee Security Vulnerabilities
Wp-marquee Code Analysis
Dangerous Functions Found
Output Escaping
Wp-marquee Attack Surface
WordPress Hooks 4
Maintenance & Trust
Wp-marquee Maintenance & Trust
Maintenance Signals
Community Trust
Wp-marquee Alternatives
Widget Builder
widget-builder
Widget Builder uses native WordPress editing interface to provide a unique tool to build custom widgets for your site(s).
Simple Page to Sidebar
simple-page-to-sidebar
Simple Page to Sidebar lets you simply add page content to a sidebar. No more, no less.
last updated
last-updated
Mark posts as significantly updated an display them in a widget.
Multiple Sidebar Generator
multiple-sidebar-generator
Easily assign custom, widget-enabled sidebars to any page.
Ownyourblog Banner Widget
ownyourblog-banner-widget
Simple, but powerful widget to show any banner you want in your sidebar. One-click solution!
Wp-marquee Developer Profile
1 plugin · 10 total installs
How We Detect Wp-marquee
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-marquee/css/marquee.css/wp-content/plugins/wp-marquee/javascript/jquery.marquee.min.js/wp-content/plugins/wp-marquee/javascript/iniMarquee.js/wp-content/plugins/wp-marquee/javascript/jquery.marquee.min.js/wp-content/plugins/wp-marquee/javascript/iniMarquee.jsHTML / DOM Fingerprints
marqueemarquecina_contmarquesinamarquesina_infomarquesina_tit