
Koyomi Security & Risk Analysis
wordpress.org/plugins/koyomiDisplay current moon phase, dates, and Japanese old dates with graphical images.
Is Koyomi Safe to Use in 2026?
Generally Safe
Score 85/100Koyomi has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "koyomi" v0.0.4 demonstrates a generally strong security posture from a static analysis perspective. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits its attack surface. Furthermore, the code exhibits good practices regarding SQL queries by exclusively using prepared statements and a lack of dangerous functions or file operations.
However, a notable concern arises from the output escaping. With only 29% of identified outputs being properly escaped, there is a significant risk of cross-site scripting (XSS) vulnerabilities. The lack of nonces and capability checks on any potential entry points (though none were identified) also represents a weakness, as any future expansion of the plugin's functionality without these security measures would be immediately vulnerable. The clean vulnerability history is positive, indicating a lack of known exploits, but this should not overshadow the identified code-level risks.
In conclusion, while "koyomi" v0.0.4 has a minimal attack surface and uses prepared statements for SQL, the prevalent issue of unescaped output presents a clear and present danger of XSS. The absence of any identified entry points is a strength, but the lack of essential security checks like nonces and capability checks in the existing code base is a notable weakness that needs attention.
Key Concerns
- Insufficient output escaping (29% proper)
- Lack of nonce checks
- Lack of capability checks
Koyomi Security Vulnerabilities
Koyomi Code Analysis
Output Escaping
Koyomi Attack Surface
WordPress Hooks 1
Maintenance & Trust
Koyomi Maintenance & Trust
Maintenance Signals
Community Trust
Koyomi Alternatives
Custom Sidebars – Dynamic Sidebar Classic Widget Area Manager
custom-sidebars
Flexible sidebars for custom classic widget configurations on any page or post. Create custom sidebars with ease!
Image Widget
image-widget
A simple image widget that uses the native WordPress media manager to add image widgets to your site.
Widget Logic
widget-logic
Widget Logic lets you control on which pages widgets appear using WP's conditional tags.
WooSidebars
woosidebars
WooSidebars adds functionality to display different widgets in a sidebar, according to a context (for example, a specific page or a category).
Fixed Widget and Sticky Elements for WordPress
q2w3-fixed-widget
More attention and a higher ad performance with fixed sticky widgets.
Koyomi Developer Profile
10 plugins · 110 total installs
How We Detect Koyomi
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/koyomi/image/moon/HTML / DOM Fingerprints
koyomi_todaykoyomi_oldid="widget_j_koyomi"id="koyomi_outer"id="moonphase"<div id="koyomi_outer"<div id="moonphase"