
Advanced Dates Security & Risk Analysis
wordpress.org/plugins/advanced-datesAllows publishers to easily customize the publication year of posts and pages.
Is Advanced Dates Safe to Use in 2026?
Generally Safe
Score 85/100Advanced Dates has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "advanced-dates" plugin v1.0.1 exhibits a strong security posture in several key areas, notably the complete absence of identified vulnerabilities in its history and a commitment to secure coding practices like prepared statements for all SQL queries. The static analysis also indicates a minimal attack surface with no registered AJAX handlers, REST API routes, shortcodes, or cron events, and importantly, all identified entry points have authentication checks. The presence of nonce and capability checks further bolsters its defenses.
However, a significant concern arises from the output escaping. With 100% of the 19 identified output points being unescaped, this plugin presents a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data that is displayed on the frontend without proper sanitization or escaping could be manipulated by attackers to inject malicious scripts. The taint analysis showing zero flows, while positive, is based on a very small sample size (0 flows analyzed) and should be viewed with caution given the widespread output escaping issue. The lack of vulnerability history is a positive sign, suggesting good past development, but it does not negate the current, clearly identifiable risk.
In conclusion, while the "advanced-dates" plugin has a solid foundation regarding its attack surface and SQL query security, the critical flaw in output escaping represents a substantial risk that needs immediate attention. Developers should prioritize implementing robust output escaping mechanisms to mitigate the high likelihood of XSS attacks.
Key Concerns
- 100% of outputs unescaped
Advanced Dates Security Vulnerabilities
Advanced Dates Release Timeline
Advanced Dates Code Analysis
Output Escaping
Advanced Dates Attack Surface
WordPress Hooks 9
Maintenance & Trust
Advanced Dates Maintenance & Trust
Maintenance Signals
Community Trust
Advanced Dates Alternatives
Dynamic Month & Year into Posts
dynamic-month-year-into-posts
Automate SEO and content with dynamic shortcodes for dates, years, months, age calculations, seasons and countdowns in content, titles and meta.
Calendar Translation
calendar-translation
Replaces the_time, get_the_time, the_date and get_the_date functions to translate date and time.
Easy Updates Manager
stops-core-theme-and-plugin-updates
Manage all your WordPress updates, including individual updates, automatic updates, logs, and loads more. This also works very well with WordPress Mul …
InfiniteWP Client
iwp-client
Install this plugin on unlimited sites and manage them all from a central dashboard. This plugin communicates with your InfiniteWP Admin Panel.
Advanced Automatic Updates
automatic-updater
Adds extra options to WordPress' built-in Automatic Updates feature.
Advanced Dates Developer Profile
3 plugins · 150 total installs
How We Detect Advanced Dates
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/advanced-dates/css/style.css/wp-content/plugins/advanced-dates/js/functions.jsadvanced-dates/css/style.css?ver=advanced-dates/js/functions.js?ver=HTML / DOM Fingerprints
learn-morepp-smallxid="logo2"id="instructions"id="meta-instructions"uncheck2uncheck3toggle