
Date Post Title Security & Risk Analysis
wordpress.org/plugins/date-post-titleSets a post title to the publish date if one does not exist when publishing a post.
Is Date Post Title Safe to Use in 2026?
Generally Safe
Score 85/100Date Post Title has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'date-post-title' plugin v1.0 exhibits a generally weak security posture despite having no recorded vulnerabilities or direct indications of dangerous code. The complete lack of output escaping across all identified outputs is a significant concern. This means that any data displayed by the plugin to the user interface could potentially be injected with malicious code, leading to cross-site scripting (XSS) vulnerabilities. Furthermore, the absence of nonce and capability checks across all entry points, while currently having a zero attack surface, leaves the plugin exposed should any new entry points be introduced without proper authorization mechanisms. The plugin's vulnerability history is clean, suggesting it has not been a target or has been developed with a degree of care. However, this does not mitigate the immediate risks identified in the static analysis, particularly the unescaped output. A balanced view would acknowledge the clean vulnerability history but highlight the critical need to address the output escaping issue to prevent potential XSS attacks.
Key Concerns
- No output escaping found
- No nonce checks on entry points
- No capability checks on entry points
Date Post Title Security Vulnerabilities
Date Post Title Code Analysis
Output Escaping
Date Post Title Attack Surface
WordPress Hooks 2
Maintenance & Trust
Date Post Title Maintenance & Trust
Maintenance Signals
Community Trust
Date Post Title Alternatives
No alternatives data available yet.
Date Post Title Developer Profile
34 plugins · 8K total installs
How We Detect Date Post Title
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/date-post-title/languages/HTML / DOM Fingerprints
regular-textcodeplaceholdervalue