WP Posts Ticker Security & Risk Analysis

wordpress.org/plugins/wp-posts-ticker

Show Latest posts news ticker Admin Option Page Option to change Background Color Option to change Text Color Option to choose categories RTL Suppor …

10 active installs v1.1 PHP 5.2.4+ WP 4.6+ Updated Sep 26, 2017
blognewsnewstickerpostsrotate
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Posts Ticker Safe to Use in 2026?

Generally Safe

Score 85/100

WP Posts Ticker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The "wp-posts-ticker" v1.1 plugin exhibits a generally strong security posture based on the static analysis results. The complete absence of identified dangerous functions, raw SQL queries, file operations, and external HTTP requests are positive indicators. Furthermore, the presence of capability checks suggests an awareness of WordPress security best practices. However, a significant concern is the low percentage of properly escaped output (40%). This means a substantial portion of data displayed to users may not be adequately sanitized, potentially leading to cross-site scripting (XSS) vulnerabilities if user-controlled data is displayed without proper escaping. The lack of identified taint flows and a clean vulnerability history are encouraging, but the unescaped output remains a notable weakness.

Key Concerns

  • Insufficient output escaping
Vulnerabilities
None known

WP Posts Ticker Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP Posts Ticker Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
9
6 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

40% escaped15 total outputs
Attack Surface

WP Posts Ticker Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_initnewsticker.php:38
actionadmin_menunewsticker.php:40
actionwp_footernewsticker.php:163
actionwp_enqueue_scriptspublic\frontend_enqueue.php:17
actionadmin_enqueue_scriptspublic\frontend_enqueue.php:33
Maintenance & Trust

WP Posts Ticker Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedSep 26, 2017
PHP min version5.2.4
Downloads2K

Community Trust

Rating70/100
Number of ratings2
Active installs10
Developer Profile

WP Posts Ticker Developer Profile

hamzarauf

3 plugins · 30 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP Posts Ticker

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-posts-ticker/public/css/style.css/wp-content/plugins/wp-posts-ticker/public/js/app.js
Script Paths
/wp-content/plugins/wp-posts-ticker/public/js/app.js

HTML / DOM Fingerprints

CSS Classes
news_ticker_wrapcontainer_hr_newsticker_timernewsh1ticker_newsnews_post_title
Data Attributes
data-default-color
Shortcode Output
<div class="news_ticker_wrap"<marquee onmouseover="this.stop();" onmouseout="this.start();">
FAQ

Frequently Asked Questions about WP Posts Ticker