
Archives by Category and Date Security & Risk Analysis
wordpress.org/plugins/archives-by-category-and-dateThis plugin shows archives in a categorized way that is archives are categorized under category name and date.
Is Archives by Category and Date Safe to Use in 2026?
Generally Safe
Score 85/100Archives by Category and Date has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "archives-by-category-and-date" v1.0.4 plugin demonstrates a generally strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the code analysis shows no dangerous functions, no unescaped file operations, no external HTTP requests, and critically, no raw SQL queries – all queries utilize prepared statements. This adherence to secure coding practices is commendable and indicates a proactive approach to security by the developers.
However, the analysis does reveal some areas for improvement. While the number of output escapes is relatively low (18 total), a significant portion (22%) are not properly escaped. This could lead to cross-site scripting (XSS) vulnerabilities if the unescaped output is rendered in the browser, especially if the input is user-controllable. The lack of nonce checks and capability checks, while not directly indicating a vulnerability in the absence of entry points, suggests a potential weakness if new entry points are added in future versions without corresponding security measures. The vulnerability history is a blank slate, with zero known CVEs, which is an excellent indicator of a well-maintained and secure plugin over time.
In conclusion, the plugin's strengths lie in its minimal attack surface and its secure handling of database operations. The primary concern is the unescaped output, which represents a potential XSS risk. The absence of any historical vulnerabilities is a significant positive, but the lack of robust authorization checks on the few existing code signals could be a future concern. Overall, the plugin is likely safe to use for its current functionality, but the unescaped output warrants attention.
Key Concerns
- Unescaped output found
- Missing nonce checks
- Missing capability checks
Archives by Category and Date Security Vulnerabilities
Archives by Category and Date Code Analysis
Output Escaping
Archives by Category and Date Attack Surface
WordPress Hooks 3
Maintenance & Trust
Archives by Category and Date Maintenance & Trust
Maintenance Signals
Community Trust
Archives by Category and Date Alternatives
Disable Unused Pages
disable-unused-features
Redirect to 404: Author archives, Date archives, Attachment page, Category archives, Tag archives or Search page. Easy, safe and fast!
Mundoon Taxonomy Filter Checkbox
mundoon-simple-taxonomy-filter-checkbox
Quickly create taxonomies filters for custom post types templates!
Search & Filter
search-filter
Search and Filtering for Custom Posts, Categories, Tags, Taxonomies, Post Dates and Post Types
Advanced AJAX Product Filters
woocommerce-ajax-filters
Fast and flexible AJAX product filters for WooCommerce. Filter by categories, attributes, price, tags, rating, and more. No page reloads.
Allow HTML in Category Descriptions
allow-html-in-category-descriptions
This plugin allows you to use unfiltered HTML in your category descriptions by disabling selected WordPress filters.
Archives by Category and Date Developer Profile
47 plugins · 26K total installs
How We Detect Archives by Category and Date
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/archives-by-category-and-date/css/acd-style.css