
Contenido del dia Security & Risk Analysis
wordpress.org/plugins/contenido-del-diaEste plugins hace que en tu sitio web se muestre el contenido diario, verso, imagen, vídeo y reflexiones; actualizado todos los días por Bibliatodo.
Is Contenido del dia Safe to Use in 2026?
Generally Safe
Score 100/100Contenido del dia has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'contenido-del-dia' plugin v2.3 exhibits a mixed security posture. On one hand, it demonstrates good practices by having no known CVEs, no external HTTP requests, no file operations, and all SQL queries using prepared statements. The limited attack surface, with only one shortcode and no AJAX handlers or REST API routes, is also a positive sign. However, there are significant concerns. The use of the `create_function` is a dangerous function that can lead to remote code execution if user input is not strictly controlled. Furthermore, only 14% of the 14 output escapes are properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The complete lack of nonce and capability checks on its entry points, particularly the shortcode, means that any user, even unauthenticated ones, could potentially trigger unintended behavior or exploit vulnerabilities if the `create_function` or unescaped output is misused.
While the vulnerability history shows no recorded issues, this is likely due to the limited scope of analysis or the absence of extensive public scrutiny rather than an inherent lack of risk. The presence of `create_function` and widespread unescaped output, combined with the absence of critical security checks, presents a substantial risk. The plugin's strengths lie in its limited attack surface and secure database interactions, but these are overshadowed by the immediate threats posed by the dangerous function and XSS potential. A critical review and refactoring of the code, especially concerning `create_function` and output sanitization, are strongly recommended.
Key Concerns
- Dangerous function: create_function
- Low output escaping percentage (14%)
- Missing nonce checks
- Missing capability checks
Contenido del dia Security Vulnerabilities
Contenido del dia Code Analysis
Dangerous Functions Found
Output Escaping
Contenido del dia Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
Contenido del dia Maintenance & Trust
Maintenance Signals
Community Trust
Contenido del dia Alternatives
Concordancia de la Biblia
concordancia-de-la-biblia
Este plugins hace que la búsqueda de cualquier palabra en varias versiones de la Biblia por Bibliatodo.com
Versiculo del dia
versiculo-del-dia
Este plugin muestra un versículo diario de la Santa Palabra de Dios, la Biblia, por Bibliatodo.com.
Bible Search and Audio / Biblia y Concordancia con Audio
biblia-y-concordancia
Este plugin permite buscar en varias versiones de la Biblia e incluye audio.
Diccionario de la Biblia
diccionario-de-la-biblia
Este plugins hace que la búsqueda de cualquier palabra en varios Diccionario de la Biblia por Bibliatodo.com
WP-Bible
wp-bible
Plugin finds Bible references in your posts and changes them for the actual Bible text from any of 38 different translations in 14 languages.
Contenido del dia Developer Profile
8 plugins · 150 total installs
How We Detect Contenido del dia
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
https://www.bibliatodo.com/assets/js/wordpress/es/widget-contenido-dia.jsHTML / DOM Fingerprints
widget_id="cdd_contenidodeldiaWidget"[cdd_contenidodeldia]