Daily Maxim 365 Security & Risk Analysis

wordpress.org/plugins/daily-maxim-365

This plugin displays various short quotes. It can display quotes randomly on a daily or monthly basis.

10 active installs v1.0.0 PHP 7.0+ WP 5.0+ Updated Apr 16, 2021
dailymaximphrasequotationsquotes
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Daily Maxim 365 Safe to Use in 2026?

Generally Safe

Score 85/100

Daily Maxim 365 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The "daily-maxim-365" v1.0.0 plugin exhibits a generally good security posture based on the provided static analysis. The plugin demonstrates strong adherence to best practices, with a high percentage of SQL queries using prepared statements and a significant majority of outputs being properly escaped. The presence of nonce and capability checks, alongside no external HTTP requests, further contributes to its defensibility. The attack surface is minimal, with only one shortcode identified as an entry point, and importantly, no unprotected entry points were found.

However, the taint analysis reveals a critical area of concern. All four analyzed flows have unsanitized paths and are classified as high severity. This indicates potential vulnerabilities where user-supplied data might be processed without adequate sanitization, leading to risks such as arbitrary file read, code injection, or directory traversal. The absence of any recorded vulnerability history is a positive sign, suggesting the developers have a track record of building secure code, but it does not negate the findings from the taint analysis.

In conclusion, while the plugin shows strengths in its use of prepared statements, output escaping, and authentication checks, the high-severity unsanitized flows identified by taint analysis represent a significant risk that must be addressed. The developer's apparent history of security is a positive indicator, but the immediate need is to rectify the identified taint flow issues to ensure the plugin's continued secure operation.

Key Concerns

  • High severity unsanitized taint flows
Vulnerabilities
None known

Daily Maxim 365 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Daily Maxim 365 Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
21 prepared
Unescaped Output
18
270 escaped
Nonce Checks
4
Capability Checks
5
File Operations
5
External Requests
0
Bundled Libraries
0

SQL Query Safety

95% prepared22 total queries

Output Escaping

94% escaped288 total outputs
Data Flows
4 unsanitized

Data Flow Analysis

4 flows4 with unsanitized paths
register_settings (app\controllers\admin\class-admin-phrases.php:141)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Daily Maxim 365 Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[daily-maxim-365] app\controllers\frontend\class-frontend-phrases.php:44
WordPress Hooks 21
actionadmin_menuapp\controllers\admin\class-admin-phrases.php:56
actionadmin_initapp\controllers\admin\class-admin-phrases.php:64
actionadmin_menuapp\controllers\admin\class-admin-settings.php:56
actionadmin_initapp\controllers\admin\class-admin-settings.php:69
actionadmin_menuapp\controllers\admin\class-admin-sources.php:56
actionadmin_initapp\controllers\admin\class-admin-sources.php:63
actionadmin_menuapp\controllers\admin\class-phrases-list.php:73
actiontoplevel_page_daily-maxim-365app\controllers\admin\class-phrases-list.php:76
actiontoplevel_page_daily-maxim-365app\controllers\admin\class-phrases-list.php:77
actionadmin_initapp\controllers\admin\class-phrases-list.php:84
actionadmin_menuapp\controllers\admin\class-sources-list.php:72
actionadmin_initapp\controllers\admin\class-sources-list.php:80
actionwp_enqueue_scriptsapp\controllers\frontend\class-frontend-phrases.php:41
actionwp_enqueue_scriptsapp\controllers\frontend\class-frontend-phrases.php:42
actioninitcore\class-router.php:63
actionwpcore\class-router.php:64
actioninitcore\class-router.php:66
actionwpcore\class-router.php:67
actionadmin_noticesdaily-maxim-365.php:54
actionplugins_loadedincludes\class-daily-maxim-365.php:135
actionplugins_loadedincludes\class-daily-maxim-365.php:157
Maintenance & Trust

Daily Maxim 365 Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedApr 16, 2021
PHP min version7.0
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Daily Maxim 365 Developer Profile

Mineaki Masuko

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Daily Maxim 365

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/daily-maxim-365/assets/css/admin/daily-maxim-365.css/wp-content/plugins/daily-maxim-365/assets/js/admin/daily-maxim-365.js
Script Paths
/wp-content/plugins/daily-maxim-365/assets/js/admin/daily-maxim-365.js
Version Parameters
daily-maxim-365/assets/css/admin/daily-maxim-365.css?ver=daily-maxim-365/assets/js/admin/daily-maxim-365.js?ver=

HTML / DOM Fingerprints

JS Globals
msdm3_localize_text
FAQ

Frequently Asked Questions about Daily Maxim 365