
Day Spelled Security & Risk Analysis
wordpress.org/plugins/day-spelledThis plugin enables you to insert a multi-lingual date with the day and month spelled out, anywhere in a site where a shortcode can be used.
Is Day Spelled Safe to Use in 2026?
Generally Safe
Score 100/100Day Spelled has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "day-spelled" v1.6 plugin exhibits a generally positive security posture with a minimal attack surface and a complete lack of recorded vulnerabilities. The absence of dangerous functions, external HTTP requests, file operations, and SQL queries utilizing prepared statements are strong indicators of good coding practices.
However, a significant concern arises from the complete absence of output escaping, meaning all six identified output points are potentially vulnerable to cross-site scripting (XSS) attacks. While the static analysis and taint analysis found no immediate critical or high-severity issues, the unescaped output presents a tangible risk. The lack of nonce and capability checks, while not directly tied to entry points in this specific analysis, could become a weakness if new AJAX or REST API endpoints are introduced without proper security considerations.
Given the clean vulnerability history, it suggests diligent maintenance or a lack of targeted attacks. Nevertheless, the unescaped output is a critical flaw that needs immediate attention. The plugin's strengths lie in its limited attack surface and clean track record, but the unescaped output is a significant weakness that detracts from its overall security.
Key Concerns
- All output is unescaped
- No nonce checks
- No capability checks
Day Spelled Security Vulnerabilities
Day Spelled Code Analysis
Output Escaping
Day Spelled Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
Day Spelled Maintenance & Trust
Maintenance Signals
Community Trust
Day Spelled Alternatives
No alternatives data available yet.
Day Spelled Developer Profile
2 plugins · 50 total installs
How We Detect Day Spelled
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
[dayspell when='yyyy-mm-dd']