
How Old Am I Security & Risk Analysis
wordpress.org/plugins/how-old-am-iHow Old Am I calculates and displays ages in several formats.
Is How Old Am I Safe to Use in 2026?
Generally Safe
Score 85/100How Old Am I has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "how-old-am-i" plugin v1.2.0 exhibits a generally good security posture with no known vulnerabilities or CVEs. The static analysis reveals no dangerous functions, no direct SQL queries (all prepared), and no file operations or external HTTP requests, which are positive signs. However, there are significant concerns regarding output escaping and the complete absence of nonces and capability checks. While the attack surface is small, the lack of robust authentication and sanitization on the identified shortcode is a critical weakness. The taint analysis showing unsanitized paths, although not classified as high or critical, indicates potential avenues for malicious input to be processed without proper validation.
Despite the lack of historical vulnerabilities, the current code presents risks. The 33% proper output escaping rate, coupled with unsanitized taint flows, means there's a high probability of cross-site scripting (XSS) vulnerabilities, especially through the shortcode. The absence of nonce checks on any potential AJAX endpoints (even if currently zero) and the lack of capability checks on the shortcode mean that an attacker could potentially trigger plugin functionality without proper authorization or CSRF protection. In conclusion, while the plugin avoids common pitfalls like raw SQL and dangerous functions, its weak input sanitization and output escaping, along with a complete disregard for nonces and capability checks, make it susceptible to XSS and potentially other injection attacks.
Key Concerns
- Unescaped output detected
- Unsanitized paths in taint analysis
- Missing nonce checks
- Missing capability checks
How Old Am I Security Vulnerabilities
How Old Am I Code Analysis
Output Escaping
Data Flow Analysis
How Old Am I Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
How Old Am I Maintenance & Trust
Maintenance Signals
Community Trust
How Old Am I Alternatives
Responsive Mortgage Calculator
responsive-mortgage-calculator
A simple responsive mortgage calculator widget and shortcode.
Mortgage Calculator
mortgage-calculator
It provides an easy to use mortgage calculator widget.
Mortgage Calculators WP
mortgage-calculators-wp
Mortgage Calculators WP provides users with a simple, elegant and responsive solution for users to calculate mortgage values.
Simple Mortgage Calculator
ct-mortgage-calculator
A straightforward and simple responsive mortgage calculator with a clean flat design.
Estatik Mortgage Calculator
estatik-mortgage-calculator
Estatik Mortgage Calculator will allow your website visitors to estimate their mortgage payments. It is great-looking and informative!
How Old Am I Developer Profile
1 plugin · 90 total installs
How We Detect How Old Am I
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/how-old-am-i/how-old-am-i.phpHTML / DOM Fingerprints
Calculates and displays your age in several formats.