
Current Year, Month & Copyright Shortcode Security & Risk Analysis
wordpress.org/plugins/et-current-year-month-copyright-shortcodeIt is a Wordpress Plugins to show current year and month using shortcode. It can also show previous and nex year and month dynamically.
Is Current Year, Month & Copyright Shortcode Safe to Use in 2026?
Generally Safe
Score 100/100Current Year, Month & Copyright Shortcode has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "et-current-year-month-copyright-shortcode" plugin version 1.0.1 demonstrates a generally good security posture based on the provided static analysis. The code shows an adherence to secure coding practices, with no dangerous functions identified and all SQL queries utilizing prepared statements. Crucially, output escaping appears to be handled correctly, and there are no identified file operations or external HTTP requests that could introduce vulnerabilities. The absence of any recorded vulnerabilities in its history further reinforces this positive assessment, suggesting a stable and well-maintained codebase.
Despite these strengths, a significant concern arises from the lack of explicit capability checks and nonce checks across its 24 shortcodes. While the static analysis reported no unprotected entry points, this absence of checks means that even if the shortcodes themselves don't inherently process untrusted input in a dangerous way, they are not actively preventing unauthorized users or lower-privileged roles from executing them. This could potentially lead to unintended behavior or information disclosure if the shortcode's output is sensitive or if its execution has side effects. The taint analysis also reporting zero flows, while seemingly positive, might be limited in its scope if the static analysis tools did not cover all potential input vectors for the shortcodes.
In conclusion, the plugin's core code appears robust and free from common vulnerabilities. However, the reliance on WordPress's default access control for shortcode execution, without specific capability checks, represents a potential area for improvement. The lack of recorded vulnerabilities is a strong positive, but developers should consider adding explicit checks for enhanced security, especially if shortcodes interact with user-specific data or perform actions beyond simple display.
Key Concerns
- Missing capability checks on shortcodes
- Missing nonce checks on shortcodes
Current Year, Month & Copyright Shortcode Security Vulnerabilities
Current Year, Month & Copyright Shortcode Code Analysis
Current Year, Month & Copyright Shortcode Attack Surface
Shortcodes 24
WordPress Hooks 7
Maintenance & Trust
Current Year, Month & Copyright Shortcode Maintenance & Trust
Maintenance Signals
Community Trust
Current Year, Month & Copyright Shortcode Alternatives
Current Year, Symbols and IP Shortcode
current-year-shortcode
Useful shortcode for WordPress. Current year, copyright, symbols and user IP with shortcode.
Current Year Shortcode (for Post Titles)
current-year-shortcode-for-post-titles
Display the current year in post and page titles. Make sure you check the "Enable Shortcode in titles" option in the plugin settings page to …
Current Year, Month & Copyright Shortcode Developer Profile
3 plugins · 0 total installs
How We Detect Current Year, Month & Copyright Shortcode
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/et-current-year-month-copyright-shortcode/assets/css/backend.csset-current-year-month-copyright-shortcode/assets/css/backend.css?ver=