Current Year Shortcode (for Post Titles) Security & Risk Analysis

wordpress.org/plugins/current-year-shortcode-for-post-titles

Display the current year in post and page titles. Make sure you check the "Enable Shortcode in titles" option in the plugin settings page to …

10 active installs v1.1 PHP 7.0+ WP 5.5+ Updated Mar 19, 2024
automatic-current-yearcurrent-year-in-titlecurrent-year-shortcodeshow-current-year-in-post-title
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Current Year Shortcode (for Post Titles) Safe to Use in 2026?

Generally Safe

Score 85/100

Current Year Shortcode (for Post Titles) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The 'current-year-shortcode-for-post-titles' plugin, version 1.1, demonstrates a strong security posture based on the provided static analysis. The code appears to follow good practices by not utilizing dangerous functions, employing prepared statements for any potential (though absent in this analysis) SQL queries, and ensuring all output is properly escaped. The absence of file operations and external HTTP requests further reduces the attack surface. The plugin's limited attack surface, with only one shortcode and no AJAX handlers or REST API routes, is a positive indicator. Furthermore, the lack of recorded vulnerabilities in its history suggests a history of stable and secure development.

While the static analysis reveals no immediate threats such as dangerous functions, SQL injection vulnerabilities, or unescaped output, the absence of explicit capability checks and nonce checks on its single shortcode entry point is a minor concern. Although the taint analysis found no issues, this might be due to the limited functionality and lack of external input processing. The plugin's simplicity is a strength, but the lack of robust authentication checks on its shortcode could be a potential, albeit low, risk if the shortcode were to evolve to handle user-supplied data in the future. Overall, the plugin appears safe for its intended purpose, with a very low risk profile.

Key Concerns

  • Missing capability checks on shortcode
  • Missing nonce checks on shortcode
Vulnerabilities
None known

Current Year Shortcode (for Post Titles) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Current Year Shortcode (for Post Titles) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Current Year Shortcode (for Post Titles) Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[wcyear] wc-current-year-shortcode.php:138
WordPress Hooks 4
actionadmin_menuwc-current-year-shortcode.php:27
actionadmin_initwc-current-year-shortcode.php:28
filterthe_titlewc-current-year-shortcode.php:128
filterwpseo_titlewc-current-year-shortcode.php:132
Maintenance & Trust

Current Year Shortcode (for Post Titles) Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedMar 19, 2024
PHP min version7.0
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Current Year Shortcode (for Post Titles) Developer Profile

wcdev

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Current Year Shortcode (for Post Titles)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Data Attributes
id="enable_shortcode_in_titles_0"id="enable_shortcode_in_yoast_seo_plugin_1"
Shortcode Output
[wcyear]
FAQ

Frequently Asked Questions about Current Year Shortcode (for Post Titles)