AADMY – Add Auto Date Month Year Into Posts Security & Risk Analysis

wordpress.org/plugins/auto-date-year-month

Short Description: Automatically add dynamic dates, months, and years to your WordPress posts using shortcodes.

500 active installs v2.0.5 PHP 7.4+ WP 6.0+ Updated May 29, 2025
contentmarketingseoshortcodewriting
98
A · Safe
CVEs total1
Unpatched0
Last CVEOct 14, 2024
Safety Verdict

Is AADMY – Add Auto Date Month Year Into Posts Safe to Use in 2026?

Generally Safe

Score 98/100

AADMY – Add Auto Date Month Year Into Posts has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Oct 14, 2024Updated 10mo ago
Risk Assessment

The plugin "auto-date-year-month" v2.0.5 exhibits a mixed security posture. On the positive side, the static analysis reveals no dangerous functions, no SQL queries executed without prepared statements, and no file operations or external HTTP requests, which are excellent indicators of secure coding practices in these areas. The absence of taint analysis findings further suggests no immediately apparent critical vulnerabilities in data flow. However, a significant concern is the low percentage of properly escaped output (26%), indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the complete lack of nonce checks and capability checks on its 25 shortcodes presents a substantial attack surface for potential unauthorized actions or information disclosure if the shortcodes have any sensitive functionality. The vulnerability history, including one previously reported high-severity vulnerability of Code Injection, and the fact that a vulnerability was disclosed as recently as October 2024, suggests a pattern of security weaknesses that require careful attention. While the plugin has strengths in avoiding common pitfalls like raw SQL and dangerous functions, the output escaping and lack of authorization checks on shortcodes are critical areas of concern.

In conclusion, while the plugin demonstrates good practices in database interactions and avoidance of known dangerous functions, the significant weakness in output escaping and the lack of robust authorization mechanisms for its shortcodes pose considerable security risks. The historical vulnerability for code injection and the recent disclosure date are also red flags. Users should be cautious, and the developers should prioritize addressing the output escaping and authorization for shortcodes to improve the plugin's overall security posture.

Key Concerns

  • Insufficient output escaping
  • No nonce checks on shortcodes
  • No capability checks on shortcodes
  • 1 high severity historical vulnerability
  • Bundled outdated library: Freemius v1.0
Vulnerabilities
1

AADMY – Add Auto Date Month Year Into Posts Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

High
1

1 total CVE

CVE-2024-9837high · 7.3Improper Control of Generation of Code ('Code Injection')

AADMY – Add Auto Date Month Year Into Posts <= 2.0.1 - Unauthenticated Arbitrary Shortcode Execution

Oct 14, 2024 Patched in 2.0.2 (1d)
Code Analysis
Analyzed Mar 16, 2026

AADMY – Add Auto Date Month Year Into Posts Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
20
7 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

Output Escaping

26% escaped27 total outputs
Attack Surface

AADMY – Add Auto Date Month Year Into Posts Attack Surface

Entry Points25
Unprotected0

Shortcodes 25

[countdown] aadmy-shortcodes\aadmy-countdown.php:57
[cdown_short] aadmy-shortcodes\aadmy-countdown.php:113
[offset] aadmy-shortcodes\aadmy-offsets.php:17
[st] aadmy-shortcodes\aadmy-other-functions.php:10
[fcr] aadmy-shortcodes\aadmy-other-functions.php:18
[cs] aadmy-shortcodes\aadmy-other-functions.php:25
[post_modified] aadmy-shortcodes\aadmy-other-functions.php:35
[post_mdt] aadmy-shortcodes\aadmy-other-functions.php:44
[age] aadmy-shortcodes\aadmy-other-functions.php:67
[aadmy_event] aadmy-shortcodes\aadmy-other-functions.php:95
[copy] aadmy-shortcodes\aadmy-other-functions.php:130
[paste] aadmy-shortcodes\aadmy-other-functions.php:151
[cy] auto-date-year-month.php:87
[cm] auto-date-year-month.php:95
[pd] auto-date-year-month.php:103
[day] auto-date-year-month.php:111
[nd] auto-date-year-month.php:119
[cd] auto-date-year-month.php:125
[sd] auto-date-year-month.php:132
[today] auto-date-year-month.php:140
[tomorrow] auto-date-year-month.php:160
[py] auto-date-year-month.php:168
[ny] auto-date-year-month.php:176
[nm] auto-date-year-month.php:183
[pm] auto-date-year-month.php:191
WordPress Hooks 30
actionadmin_menuaadmy-includes\aadmy-menu.php:11
actionadmin_noticesaadmy-includes\aadmy-notices\aadmy-donation.php:44
filterwp_get_attachment_image_attributesauto-date-year-month.php:199
filterthe_titleauto-date-year-month.php:204
filtersingle_post_titleauto-date-year-month.php:205
filterwp_titleauto-date-year-month.php:206
filterthe_contentauto-date-year-month.php:207
filterthe_excerptauto-date-year-month.php:208
filterwidget_text_contentauto-date-year-month.php:211
filterwidget_textauto-date-year-month.php:212
filterwp_nav_menuauto-date-year-month.php:215
actionwp_headauto-date-year-month.php:218
actionwp_footerauto-date-year-month.php:219
filtercomment_textauto-date-year-month.php:222
filterget_archives_linkauto-date-year-month.php:227
filterget_search_formauto-date-year-month.php:230
filterlogin_formauto-date-year-month.php:233
filterlogout_urlauto-date-year-month.php:234
actionelementor/widget/render_contentauto-date-year-month.php:238
filterelementor/widget/text-editor/parse_textauto-date-year-month.php:243
filterelementor/widget/shortcode/renderauto-date-year-month.php:244
filterelementor/frontend/the_contentauto-date-year-month.php:247
filterpre_comment_contentauto-date-year-month.php:253
filterseopress_titles_titleauto-date-year-month.php:258
filterseopress_titles_descauto-date-year-month.php:259
filterwpseo_titleauto-date-year-month.php:262
filterwpseo_metadescauto-date-year-month.php:263
filterrank_math/frontend/titleauto-date-year-month.php:269
filterrank_math/frontend/descriptionauto-date-year-month.php:270
filterplugin_action_linksauto-date-year-month.php:279
Maintenance & Trust

AADMY – Add Auto Date Month Year Into Posts Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 29, 2025
PHP min version7.4
Downloads9K

Community Trust

Rating100/100
Number of ratings4
Active installs500
Developer Profile

AADMY – Add Auto Date Month Year Into Posts Developer Profile

NUMAN RASHEED

3 plugins · 550 total installs

99
trust score
Avg Security Score
99/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect AADMY – Add Auto Date Month Year Into Posts

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Shortcode Output
[cy][cm][pd][day]
FAQ

Frequently Asked Questions about AADMY – Add Auto Date Month Year Into Posts