
Date Range Filter Security & Risk Analysis
wordpress.org/plugins/date-range-filterEasily filter the admin list of post and custom post type with a date range.
Is Date Range Filter Safe to Use in 2026?
Generally Safe
Score 85/100Date Range Filter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "date-range-filter" plugin, version 0.0.11, presents a generally positive security posture, marked by the absence of any known vulnerabilities or common attack vectors in its history. The static analysis reveals a very limited attack surface with no apparent AJAX handlers, REST API routes, shortcodes, or cron events, all of which are beneficial for security as they reduce potential entry points. The code also shows a positive sign with one capability check, indicating some level of access control.
However, there are notable concerns. The plugin utilizes one SQL query without any prepared statements, which is a significant risk that could lead to SQL injection vulnerabilities, especially if user input is involved. While the taint analysis found no issues, the presence of a raw SQL query is a direct indicator of potential danger. Furthermore, the output escaping, while at 71%, still leaves 29% of outputs unescaped, which could expose the site to cross-site scripting (XSS) vulnerabilities. The complete lack of nonce checks is also a concern, particularly if any functionality were to be added in the future that handles user actions.
In conclusion, while the plugin benefits from a small attack surface and a clean vulnerability history, the direct use of raw SQL and a significant percentage of unescaped output are substantial risks that need immediate attention. These code-level weaknesses, despite the lack of recorded CVEs, represent actionable security flaws.
Key Concerns
- Raw SQL query without prepared statements
- Significant percentage of unescaped output
- No nonce checks
Date Range Filter Security Vulnerabilities
Date Range Filter Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Date Range Filter Attack Surface
WordPress Hooks 5
Maintenance & Trust
Date Range Filter Maintenance & Trust
Maintenance Signals
Community Trust
Date Range Filter Alternatives
Error Log Monitor
error-log-monitor
Adds a Dashboard widget that displays the latest messages from your PHP error log. It can also send logged errors to email.
Hide Admin Notices
hide-admin-notices
Hide – or show – WordPress Dashboard Notices, Messages, Update Nags etc. ... for everything!
Hide Dashboard Notifications
wp-hide-backed-notices
Warnings and notices can be helpful for developers as they notify them for debugging issues with their code. Though these notices can be sometimes inf …
Disable WP Notification
disable-wp-notification
Best wordpress plugin to remove all the admin panel notifications in just one click. Including the theme and plugin update notification.
Widget Disable
wp-widget-disable
Disable sidebar and dashboard widgets with an easy to use interface.
Date Range Filter Developer Profile
5 plugins · 710 total installs
How We Detect Date Range Filter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/date-range-filter/css/datepicker.css/wp-content/plugins/date-range-filter/css/admin.css/wp-content/plugins/date-range-filter/js/admin.js/wp-content/plugins/date-range-filter/js/admin.jsdate-range-filter/css/datepicker.css?ver=date-range-filter/css/admin.css?ver=date-range-filter/js/admin.js?ver=HTML / DOM Fingerprints
date-intervalfield-predefineddate-inputsboxdate-removefield-fromconnectorfield-todata-placeholderdata-fromdata-to