Current Age Plugin Security & Risk Analysis

wordpress.org/plugins/current-age

This plugin shows the current age based upon date passed through shortcode . Language and template capable.

60 active installs v1.7 PHP + WP 3.0.1+ Updated Sep 29, 2025
99
A · Safe
CVEs total1
Unpatched0
Last CVESep 22, 2025
Safety Verdict

Is Current Age Plugin Safe to Use in 2026?

Generally Safe

Score 99/100

Current Age Plugin has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Sep 22, 2025Updated 6mo ago
Risk Assessment

The 'current-age' plugin v1.7 exhibits a generally good security posture based on the static analysis. The absence of dangerous functions, SQL injection vulnerabilities, file operations, and external HTTP requests is commendable. The plugin also demonstrates good practices with its extensive use of prepared statements for SQL queries and a high percentage of properly escaped output. The presence of nonce checks and a clean taint analysis further contributes to its security. However, the lack of capability checks for its single shortcode is a potential area of concern, as this represents an unprotected entry point into the plugin's functionality. The vulnerability history reveals one medium-severity Cross-Site Request Forgery (CSRF) vulnerability in the past. While there are no currently unpatched vulnerabilities, this historical pattern suggests that CSRF might be an area that requires ongoing vigilance and potentially more robust handling in future updates. Overall, the plugin is relatively secure, but the absence of capability checks on the shortcode warrants attention to mitigate any potential misuse.

Key Concerns

  • Missing capability checks on shortcode
  • One past medium severity CSRF vulnerability
Vulnerabilities
1

Current Age Plugin Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-58687medium · 4.3Cross-Site Request Forgery (CSRF)

Current Age Plugin <= 1.6 - Cross-Site Request Forgery

Sep 22, 2025 Patched in 1.7 (9d)
Code Analysis
Analyzed Mar 16, 2026

Current Age Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
21 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

88% escaped24 total outputs
Data Flows
All sanitized

Data Flow Analysis

3 flows
currentage_save_settings (functions.php:40)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Current Age Plugin Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[showcurrentage] currentage.php:169
WordPress Hooks 5
actionadmin_menucurrentage.php:26
actioninitcurrentage.php:171
filterwidget_textcurrentage.php:176
actionadmin_post_currentage_save_settingsfunctions.php:39
actionadmin_post_currentage_language_processfunctions.php:49
Maintenance & Trust

Current Age Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 29, 2025
PHP min version
Downloads4K

Community Trust

Rating100/100
Number of ratings6
Active installs60
Alternatives

Current Age Plugin Alternatives

No alternatives data available yet.

Developer Profile

Current Age Plugin Developer Profile

WP CMS Ninja

4 plugins · 680 total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
9 days
View full developer profile
Detection Fingerprints

How We Detect Current Age Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Shortcode Output
[showcurrentage][showcurrentage month="1"][showcurrentage day="1"][showcurrentage year="2000"]
FAQ

Frequently Asked Questions about Current Age Plugin