
Admin filter posts by year Security & Risk Analysis
wordpress.org/plugins/admin-filter-posts-by-yearIn your admin area, this plugin offers the avaibility to filter your posts by YEARS and not only by MONTHS OF YEARS.
Is Admin filter posts by year Safe to Use in 2026?
Generally Safe
Score 92/100Admin filter posts by year has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "admin-filter-posts-by-year" plugin v2.4 exhibits a generally good security posture in several areas, notably the absence of known CVEs and a lack of direct file operations or external HTTP requests. All SQL queries utilize prepared statements, which is a strong indicator of good database interaction practices. However, the static analysis reveals significant concerns. The complete lack of output escaping across all identified output points is a critical weakness that could lead to cross-site scripting (XSS) vulnerabilities. Furthermore, the taint analysis indicates that all four flows analyzed have unsanitized paths, though thankfully, none reached a critical or high severity in this specific analysis. The absence of capability checks and nonce checks is also a concern, as it leaves potential entry points vulnerable if they were to exist, though the current attack surface appears to be zero.
While the plugin has no recorded vulnerability history, the current code analysis presents notable risks. The 100% unescaped output is a serious oversight. The presence of unsanitized paths in all taint flows, even without immediately exploitable high-severity issues, suggests potential for future vulnerabilities if the code evolves or new attack vectors are discovered. The complete lack of capability and nonce checks, while not directly exploitable due to the zero reported entry points, indicates a lack of robust security hardening that could become an issue if the plugin's functionality expands or is integrated with other components.
In conclusion, the plugin benefits from a clean vulnerability history and secure database practices. However, the critical failure in output escaping and the presence of unsanitized taint flows present immediate risks. The absence of capability and nonce checks suggests a potential for future vulnerabilities. Addressing the output escaping is paramount, and a review of taint flows and security checks is recommended for long-term security.
Key Concerns
- Unescaped output detected
- Unsanitized paths in taint flows
- Missing capability checks
- Missing nonce checks
Admin filter posts by year Security Vulnerabilities
Admin filter posts by year Release Timeline
Admin filter posts by year Code Analysis
Output Escaping
Data Flow Analysis
Admin filter posts by year Attack Surface
WordPress Hooks 6
Maintenance & Trust
Admin filter posts by year Maintenance & Trust
Maintenance Signals
Community Trust
Admin filter posts by year Alternatives
Post Category Filter (WP Admin)
admin-category-filter
Quickly search and filter categories and taxonomies inside the WordPress admin.
Ajax Filter Search
ajax-filter-search
Displays posts or custom post types in a friendly, filterable format using ajax so there's no page reload!
Admin post tag filter
admin-post-tag-filter
Allowed admin to filter the posts or pages using tags.
WP Many Posts
wp-many-posts
WP Many Posts helps admin to manage blogs with thousands of posts in seconds and save hours of work in bulk actions.
Persistent Filters
persistent-filters
Preserves admin list filters for Posts, Pages, and WooCommerce Products. Filters like search terms, ordering and statuses are remembered per user.
Admin filter posts by year Developer Profile
3 plugins · 4K total installs
How We Detect Admin filter posts by year
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
edit-phpjQuery