
Earth Observatory IOTD Widget Security & Risk Analysis
wordpress.org/plugins/earth-observatory-iotd-widgetProvides a widget to display the NASA Earth Observatory's Image of the Day and/or the RSS feed on your sidebar.
Is Earth Observatory IOTD Widget Safe to Use in 2026?
Generally Safe
Score 100/100Earth Observatory IOTD Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "earth-observatory-iotd-widget" v1.0 plugin exhibits a concerning security posture due to the presence of dangerous functions and a significant lack of output escaping, despite a clean vulnerability history and seemingly limited attack surface. The use of `create_function` is a major red flag, as it is deprecated and can be exploited for arbitrary code execution if user input is not rigorously sanitized before being passed to it. Furthermore, the low percentage of properly escaped output indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the website.
While the plugin has no recorded vulnerabilities and no obvious direct entry points like AJAX handlers or REST API routes without authentication, the internal code quality issues pose an indirect but substantial risk. The absence of capability checks and nonce checks, while not directly tied to exposed entry points in this static analysis, further weakens the overall security by not enforcing necessary checks on potentially sensitive operations. The plugin's strengths lie in its lack of external HTTP requests and the use of prepared statements for SQL queries, but these are overshadowed by the critical flaws in code execution and output handling.
Key Concerns
- Presence of dangerous functions (create_function)
- Low percentage of properly escaped output
- No nonce checks
- No capability checks
Earth Observatory IOTD Widget Security Vulnerabilities
Earth Observatory IOTD Widget Code Analysis
Dangerous Functions Found
Output Escaping
Earth Observatory IOTD Widget Attack Surface
WordPress Hooks 2
Maintenance & Trust
Earth Observatory IOTD Widget Maintenance & Trust
Maintenance Signals
Community Trust
Earth Observatory IOTD Widget Alternatives
Bible Verse of the Day
bible-verse-of-the-day
Shows the daily inspiring Bible verse or a random Bible verse from DailyVerses.net. In English, Spanish, Portuguese, German, French, Italian, Polish, …
DayOfWeek
day-of-week
This plugin provides an easy, lightweight way to show content based on the day of the week.
Daily Readings
daily-readings
Get the Mass daily readings on your website, automatically. 17 languages, 8 main liturgical rites available. This plugin allows you to embed the readi …
WP Post of the Day
wp-post-of-the-day
Shows a new post every day.
NASA Picture of the Day
nasa-astrology-picture-of-the-day
Allow your readers to enjoy NASA's Astronomy Picture of the Day on your blog with this easy to use and setup plugin.
Earth Observatory IOTD Widget Developer Profile
2 plugins · 2K total installs
How We Detect Earth Observatory IOTD Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/earth-observatory-iotd-widget/cache/HTML / DOM Fingerprints
eoiod_imgid="eoiod_img"name="eoiod_img"