
Daily Tarot Security & Risk Analysis
wordpress.org/plugins/daily-tarotDaily Tarot helps you publish, schedule, and share tarot readings on WordPress - perfect for creating a consistent Card of the Day experience.
Is Daily Tarot Safe to Use in 2026?
Generally Safe
Score 100/100Daily Tarot has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "daily-tarot" plugin version 1.1.13 exhibits a mixed security posture. While it shows strengths in using prepared statements for the vast majority of SQL queries and proper output escaping, significant concerns arise from its attack surface. A substantial number of AJAX handlers (23 out of 27) and REST API routes (2 out of 2) lack authentication checks, creating a broad entry point for potential unauthorized actions.
The taint analysis reveals 4 flows with unsanitized paths, although thankfully none are flagged as critical or high severity in this analysis. This indicates a potential for vulnerabilities related to file operations or external requests if these paths are exposed to user input without proper sanitization. The absence of any recorded vulnerability history is a positive sign, suggesting a proactive approach to security or a lack of past exploitable issues. However, the large number of unprotected entry points still poses a latent risk.
In conclusion, the plugin demonstrates good practices in core coding areas like SQL and output handling. Nevertheless, the significant exposure of its AJAX and REST API endpoints without proper authorization is a critical weakness that could be exploited. The presence of unsanitized paths in the taint analysis, even at lower severities, warrants attention. This plugin's security can be significantly improved by implementing robust authorization checks on all its entry points.
Key Concerns
- Unprotected AJAX handlers
- Unprotected REST API routes
- Flows with unsanitized paths (4 total)
- Bundled Freemius v1.0 library
Daily Tarot Security Vulnerabilities
Daily Tarot Release Timeline
Daily Tarot Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Daily Tarot Attack Surface
AJAX Handlers 27
REST API Routes 2
Shortcodes 13
WordPress Hooks 117
Maintenance & Trust
Daily Tarot Maintenance & Trust
Maintenance Signals
Community Trust
Daily Tarot Alternatives
Tarot, Oracle cards, Tarot readings, Tarokina
tarokina-free
The best tarot plugin for wordpress. Intuitive and easy to use. Provides accurate tarot readings.
Tarot Card Oracle
card-oracle
Create tarot, oracle, cartouche, and rune readings on your WordPress site using your own decks, spreads, and meanings.
Divine Astro
horoscope-and-tarot
Divineapi.com is a leading API platform for services like Daily Horoscope, Tarot reading, Kundali, Panchang, Natal Chart, Fortune Cookie, Coffee Cup r …
Tarot Online
tarot-online
This plugin allows you to use Tarot Online app on your WordPress website and read Tarot Online for free. Join to affiliate program and start earning m …
EZ Horoscope Professional
ez-horoscope
Astrologically accurate horoscopes with cosmic insights, advice, birth charts, and AI voice agents for chatting about readings.
Daily Tarot Developer Profile
1 plugin · 0 total installs
How We Detect Daily Tarot
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/daily-tarot/build/admin.css/wp-content/plugins/daily-tarot/build/admin.js/wp-content/plugins/daily-tarot/build/frontend.css/wp-content/plugins/daily-tarot/build/frontend.jsdaily-tarot/build/admin.css?ver=daily-tarot/build/admin.js?ver=daily-tarot/build/frontend.css?ver=daily-tarot/build/frontend.js?ver=HTML / DOM Fingerprints
dtarot-dashboarddtarot-calendardtarot-contentdtarot-spreadsdtarot-bookingsdtarot-sidebardtarot-main-contentdtarot-tarot-card+4 more<!-- Daily Tarot Admin Menu --><!-- Daily Tarot Dashboard Widget --><!-- Daily Tarot Frontend Rendering -->data-dtarot-carddata-dtarot-spreaddata-dtarot-meaningwindow.dtarotConfigwindow.dtarotFrontend/wp-json/daily-tarot/v1/cards/wp-json/daily-tarot/v1/spreads/wp-json/daily-tarot/v1/readings[daily_tarot_card][daily_tarot_reading][daily_tarot_spread]