
Better time-based greetings Widget Security & Risk Analysis
wordpress.org/plugins/better-time-based-greeting-widgetA Widget to show text messages depending on the current time.
Is Better time-based greetings Widget Safe to Use in 2026?
Generally Safe
Score 85/100Better time-based greetings Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'better-time-based-greeting-widget' v1.0 exhibits a mixed security posture. On the positive side, the plugin demonstrates a strong adherence to secure database practices, with 100% of its SQL queries utilizing prepared statements. It also shows no known vulnerability history, indicating a potentially well-maintained codebase in the past. Furthermore, there are no external HTTP requests or file operations, which inherently reduces certain attack vectors. However, several critical concerns are present. The use of the deprecated and insecure `create_function` is a significant security risk, as it can be exploited to execute arbitrary PHP code under certain circumstances. Additionally, a complete lack of output escaping for all identified output points (23 total) is a major vulnerability, exposing the plugin to Cross-Site Scripting (XSS) attacks. The absence of nonce checks and capability checks on any potential entry points, while the static analysis reports zero entry points, suggests that if any were introduced or exist in a way not detected, they would be unprotected. In conclusion, while the plugin has strengths in database security and a clean vulnerability history, the presence of `create_function` and pervasive lack of output escaping are critical weaknesses that require immediate attention.
Key Concerns
- Use of create_function
- No output escaping for any output
- No nonce checks
- No capability checks
Better time-based greetings Widget Security Vulnerabilities
Better time-based greetings Widget Code Analysis
Dangerous Functions Found
Output Escaping
Better time-based greetings Widget Attack Surface
WordPress Hooks 2
Maintenance & Trust
Better time-based greetings Widget Maintenance & Trust
Maintenance Signals
Community Trust
Better time-based greetings Widget Alternatives
Classic Widgets
classic-widgets
Enables the previous "classic" widgets settings screens in Appearance - Widgets and the Customizer. Disables the block editor from managing widgets.
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor
elementskit-lite
Join millions who empower their websites with ElementsKit Elementor Addons. Get templates, & 100+ widgets like header-footer, mega menu, custom widget
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Ultimate Addons for Elementor
header-footer-elementor
Powerful Elementor addon with advanced Elementor widgets, templates, WooCommerce widgets & Header-Footer builder to build professional websites fa …
Smash Balloon Social Photo Feed – Easy Social Feeds Plugin
instagram-feed
Formerly "Instagram Feed". Display clean, customizable, and responsive Instagram feeds from multiple accounts. Supports Instagram oEmbeds.
Better time-based greetings Widget Developer Profile
3 plugins · 50 total installs
How We Detect Better time-based greetings Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
time_based_greetingscurrent-timewhats-ontimed-greet-elementfrom-toid="better-time-based-greeting-widget"name="better-time-based-greeting-widget"jQuery$