
AADMY – Add Auto Date Month Year Into Posts Security & Risk Analysis
wordpress.org/plugins/auto-date-year-monthShort Description: Automatically add dynamic dates, months, and years to your WordPress posts using shortcodes.
Is AADMY – Add Auto Date Month Year Into Posts Safe to Use in 2026?
Generally Safe
Score 98/100AADMY – Add Auto Date Month Year Into Posts has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin "auto-date-year-month" v2.0.5 exhibits a mixed security posture. On the positive side, the static analysis reveals no dangerous functions, no SQL queries executed without prepared statements, and no file operations or external HTTP requests, which are excellent indicators of secure coding practices in these areas. The absence of taint analysis findings further suggests no immediately apparent critical vulnerabilities in data flow. However, a significant concern is the low percentage of properly escaped output (26%), indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the complete lack of nonce checks and capability checks on its 25 shortcodes presents a substantial attack surface for potential unauthorized actions or information disclosure if the shortcodes have any sensitive functionality. The vulnerability history, including one previously reported high-severity vulnerability of Code Injection, and the fact that a vulnerability was disclosed as recently as October 2024, suggests a pattern of security weaknesses that require careful attention. While the plugin has strengths in avoiding common pitfalls like raw SQL and dangerous functions, the output escaping and lack of authorization checks on shortcodes are critical areas of concern.
In conclusion, while the plugin demonstrates good practices in database interactions and avoidance of known dangerous functions, the significant weakness in output escaping and the lack of robust authorization mechanisms for its shortcodes pose considerable security risks. The historical vulnerability for code injection and the recent disclosure date are also red flags. Users should be cautious, and the developers should prioritize addressing the output escaping and authorization for shortcodes to improve the plugin's overall security posture.
Key Concerns
- Insufficient output escaping
- No nonce checks on shortcodes
- No capability checks on shortcodes
- 1 high severity historical vulnerability
- Bundled outdated library: Freemius v1.0
AADMY – Add Auto Date Month Year Into Posts Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
AADMY – Add Auto Date Month Year Into Posts <= 2.0.1 - Unauthenticated Arbitrary Shortcode Execution
AADMY – Add Auto Date Month Year Into Posts Code Analysis
Bundled Libraries
Output Escaping
AADMY – Add Auto Date Month Year Into Posts Attack Surface
Shortcodes 25
WordPress Hooks 30
Maintenance & Trust
AADMY – Add Auto Date Month Year Into Posts Maintenance & Trust
Maintenance Signals
Community Trust
AADMY – Add Auto Date Month Year Into Posts Alternatives
ContentPen
contentpen
AI-Powered SEO Content Writing Assistant
Semrush SEO Writing Assistant
semrush-seo-writing-assistant
The Semrush SEO Writing Assistant provides instant recommendations for content optimization based on the best-performing articles in Google's top 10.
Dynamic Month & Year into Posts
dynamic-month-year-into-posts
Automate SEO and content with dynamic shortcodes for dates, years, months, age calculations, seasons and countdowns in content, titles and meta.
Surfer – WordPress Plugin
surferseo
Connect Surfer's Content Editor to WordPress. Write and optimize your articles for SEO, find new keyword ideas and publish straight to WordPress.
Semrush Content Toolkit
semrush-contentshake
Create SEO-friendly content that brings traffic.
AADMY – Add Auto Date Month Year Into Posts Developer Profile
3 plugins · 550 total installs
How We Detect AADMY – Add Auto Date Month Year Into Posts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
[cy][cm][pd][day]