Blogtimes Security & Risk Analysis

wordpress.org/plugins/blogtimes

This plugin generates a bar graph image showing when posts are made during a period of time. For this to work <code>wp-images/blogtimes.png</code> must be writable by the web server. Original code by Sanjay Sheth of sastools.com.

10 active installs v0.2 PHP + WP + Updated Jan 20, 2005
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Blogtimes Safe to Use in 2026?

Generally Safe

Score 85/100

Blogtimes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 21yr ago
Risk Assessment

The "blogtimes" plugin v0.2 exhibits a strong static security posture, with no identified attack surface points, dangerous functions, or taint flows. The absence of SQL queries that do not use prepared statements, coupled with 100% properly escaped output, suggests a diligent approach to secure coding practices in these areas. Furthermore, the plugin has no recorded vulnerability history, including CVEs, indicating a clean track record. However, the complete lack of nonce and capability checks, along with no authentication checks on any potential (though currently non-existent) entry points, represents a significant weakness. While there are no immediate vulnerabilities evident in the current version, this lack of authorization checks would be a critical concern if any entry points were to be introduced in future updates. The current version appears safe due to its limited functionality and attack surface, but future development must address authorization and authentication mechanisms.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • No auth checks on entry points
  • 100% SQL not using prepared statements
Vulnerabilities
None known

Blogtimes Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Blogtimes Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries
Attack Surface

Blogtimes Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionpublish_postblogtimes.php:138
Maintenance & Trust

Blogtimes Maintenance & Trust

Maintenance Signals

WordPress version tested
Last updatedJan 20, 2005
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Alternatives

Blogtimes Alternatives

No alternatives data available yet.

Developer Profile

Blogtimes Developer Profile

Automattic

393 plugins · 20.8M total installs

73
trust score
Avg Security Score
91/100
Avg Patch Time
1192 days
View full developer profile
Detection Fingerprints

How We Detect Blogtimes

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Blogtimes