
A Year Before Security & Risk Analysis
wordpress.org/plugins/a-year-before"A Year Before" shows a list of articles, which were written a certain time ago. So you can show in a history, what happend in your blog in …
Is A Year Before Safe to Use in 2026?
Generally Safe
Score 85/100A Year Before has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'a-year-before' v1.0.3 exhibits a mixed security posture. On one hand, the absence of known vulnerabilities and CVEs, along with the proper use of prepared statements for SQL queries, suggests a degree of attention to common security pitfalls. The static analysis also indicates no obvious external HTTP requests or file operations, which are often vectors for compromise.
However, significant concerns arise from the code signals. The presence of the 'create_function' dangerous function is a critical red flag, as it can lead to arbitrary code execution if not handled with extreme care, although the static analysis did not reveal any direct taint flows originating from it. Furthermore, a very low percentage of output escaping (6%) indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities. The complete lack of nonce checks and capability checks on entry points (even though the attack surface is reported as zero) leaves potential for future vulnerabilities if the attack surface grows without proper security measures being implemented.
Given the lack of reported vulnerabilities historically, it's possible that the dangerous function is not being exploited, and the XSS issues are either not triggered or have not been discovered. Nevertheless, the identified code weaknesses represent substantial potential risks. The plugin's strengths lie in its SQL handling and lack of historical exploits, while its weaknesses are concentrated in output escaping and the use of dangerous functions.
Key Concerns
- Low output escaping percentage
- Use of dangerous function 'create_function'
- Missing nonce checks
- Missing capability checks
A Year Before Security Vulnerabilities
A Year Before Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
A Year Before Attack Surface
WordPress Hooks 2
Maintenance & Trust
A Year Before Maintenance & Trust
Maintenance Signals
Community Trust
A Year Before Alternatives
Bulk Datetime Change
bulk-datetime-change
Bulk change date/time for posts.
Post Updated Date
post-updated-date
Use Post Updated Date Plugin to display the Last Updated Date in WordPress Posts.
Time Machine
time-machine
Time Machine widget list articles published in past, relative to current date for specified offset of time, including all years of blogging (Ok, at le …
Random Posts Within Date Range Widget
random-posts-within-date-range-widget
Widget that displays the title(w/ link), date(optional), and excerpt(optional) of random posts within a selected date range.
CC-Server-Time
cc-server-time
This plugin adds a server time to all posts types edit screen.
A Year Before Developer Profile
1 plugin · 50 total installs
How We Detect A Year Before
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/a-year-before/a-year-before.php/wp-content/plugins/a-year-before/ayb-posts.phpHTML / DOM Fingerprints
ayb_posts