
Say hello Security & Risk Analysis
wordpress.org/plugins/greeting-by-day-timeGreet your website visitors by time of day with shortcode on pages or posts.
Is Say hello Safe to Use in 2026?
Generally Safe
Score 100/100Say hello has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "greeting-by-day-time" plugin v1.0 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, SQL queries, file operations, and external HTTP requests is a significant positive. Furthermore, all SQL queries use prepared statements, and all output is properly escaped, mitigating common risks like SQL injection and Cross-Site Scripting (XSS).
However, the analysis does reveal a notable concern: the complete lack of nonce checks and capability checks across all identified entry points (10 shortcodes). While there are no AJAX handlers or REST API routes to directly exploit in this specific version, the presence of shortcodes as entry points without any authorization checks creates a significant potential vulnerability. If any of these shortcodes were to process user-supplied data or have any administrative functionality, it could be exploited without authentication or proper authorization.
The plugin's vulnerability history is clean, with no recorded CVEs. This, combined with the absence of critical taint flows and dangerous functions in the code analysis, suggests that the developers have a good understanding of secure coding practices. Nevertheless, the identified lack of authorization checks on shortcodes is a critical weakness that needs to be addressed to ensure comprehensive security.
Key Concerns
- Missing nonce checks on shortcodes
- Missing capability checks on shortcodes
Say hello Security Vulnerabilities
Say hello Code Analysis
Output Escaping
Say hello Attack Surface
Shortcodes 10
Maintenance & Trust
Say hello Maintenance & Trust
Maintenance Signals
Community Trust
Say hello Developer Profile
18 plugins · 330 total installs
How We Detect Say hello
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
Guten MorgenGuten TagGuten Abendصبح به خیر