A Year Ago Today Security & Risk Analysis

wordpress.org/plugins/a-year-ago-today

Sidebar widget that shows links to posts from exactly one year ago on the same date.

10 active installs v1.0.2 PHP + WP 3.3+ Updated Feb 20, 2013
old-postssidebarwidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is A Year Ago Today Safe to Use in 2026?

Generally Safe

Score 85/100

A Year Ago Today has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 13yr ago
Risk Assessment

The "a-year-ago-today" plugin v1.0.2 exhibits a generally good security posture based on the provided static analysis. The plugin has no known vulnerabilities, no critical or high-severity taint flows, and a minimal attack surface with zero entry points lacking authentication checks. This indicates diligent coding practices and a focus on secure development. However, there are areas for improvement. The presence of raw SQL queries without prepared statements is a notable concern, as it could lead to SQL injection vulnerabilities if user input is directly incorporated into the query. Furthermore, a significant portion of output is not properly escaped, raising concerns about potential Cross-Site Scripting (XSS) vulnerabilities. While the plugin has no vulnerability history, the identified code signals suggest a need for more robust data sanitization and output escaping to achieve a truly secure state. The absence of nonce and capability checks on potential, albeit currently non-existent, entry points also warrants attention should the plugin evolve to include such features.

Key Concerns

  • Raw SQL query without prepared statements
  • Low percentage of properly escaped output
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

A Year Ago Today Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

A Year Ago Today Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
7
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

36% escaped11 total outputs
Attack Surface

A Year Ago Today Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionwidgets_inityear_ago.php:13
Maintenance & Trust

A Year Ago Today Maintenance & Trust

Maintenance Signals

WordPress version tested3.5.2
Last updatedFeb 20, 2013
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

A Year Ago Today Developer Profile

jerimiw

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect A Year Ago Today

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
jaw_year_ago_widget_class
FAQ

Frequently Asked Questions about A Year Ago Today