
WP-webTicker Security & Risk Analysis
wordpress.org/plugins/wp-webtickerDisplay a rotating list of latest post in a particular category using shortcode.
Is WP-webTicker Safe to Use in 2026?
Generally Safe
Score 85/100WP-webTicker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-webticker" v1.1 plugin exhibits a strong security posture based on the provided static analysis data. The absence of dangerous functions, SQL queries, file operations, and external HTTP requests is commendable. All SQL queries utilize prepared statements, and all outputs are properly escaped, indicating good development practices in preventing common vulnerabilities like SQL injection and cross-site scripting (XSS). The lack of any reported CVEs or historical vulnerabilities further reinforces this positive assessment. However, the analysis reveals a complete absence of nonce and capability checks across all identified entry points, which include one shortcode. This is a significant concern, as it implies that any authenticated user, regardless of their privileges, could potentially trigger the shortcode's functionality without proper authorization. While the attack surface is currently small and has no unprotected entry points directly identified in the static analysis, the lack of these critical security measures leaves it vulnerable to privilege escalation or unauthorized actions if the shortcode's functionality can be manipulated by malicious actors. The overall conclusion is that while the code is technically clean in terms of preventing direct code execution vulnerabilities, the missing authentication and authorization checks on its sole entry point present a clear and present risk that needs immediate attention.
Key Concerns
- Missing capability checks on shortcode
- Missing nonce checks on shortcode
WP-webTicker Security Vulnerabilities
WP-webTicker Release Timeline
WP-webTicker Code Analysis
WP-webTicker Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
WP-webTicker Maintenance & Trust
Maintenance Signals
Community Trust
WP-webTicker Alternatives
WP-feedTicker
wp-feedticker
Display a rotating list of latest post in a particular category using shortcode.
News Ticker Widget for Elementor
news-ticker-widget-for-elementor
News ticker widget for elementor helps you showcase your latest news/posts in a marquee or slider format.
PJ News Ticker
pj-news-ticker
PJ News Ticker is a small plugin that shows your most recent posts in a marquee style.
Advanced Marquee Effect for Elementor
advanced-marquee-effect
Create smooth logo sliders, post sliders, and testimonial carousels in Elementor. No coding required.
Simple Posts Ticker – Easy, Lightweight & Flexible
simple-posts-ticker
The Simple Posts Ticker plugin is a small tool that shows your most recent posts in a marquee style.
WP-webTicker Developer Profile
2 plugins · 20 total installs
How We Detect WP-webTicker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-webticker/jquery.webticker.js/wp-content/plugins/wp-webticker/jquery.webticker.jswp-webticker/jquery.webticker.js?ver=HTML / DOM Fingerprints
tickeroverlay-lefttickeroverlay-righttickercontainermasknewstickerdata-webticker-directiondata-webticker-travelocityjQuery.fx.offjQuery('#wp-webticker-link').hidejQuery('#<ul id="webticker"><li id="wp-webticker-link"><a href="http://jonmifsud.com/web-tools/wp-webticker/">WP Webticker</a></li><script>jQuery(document).ready(function(){jQuery('#wp-webticker-link').hide});</script><script>jQuery(document).ready(function(){jQuery.fx.off=false;jQuery('#