Liturgical Day of the Week Security & Risk Analysis

wordpress.org/plugins/liturgical-day-of-the-week

Based on the Catholic Liturgical / Lectionary Calendar, Liturgical Day of the Week (LDotW) presents with a colored background associated with that day …

10 active installs v2.0.2 PHP 8.0+ WP 5.2+ Updated Feb 28, 2026
feastslectionaryliturgicalliturgical-day-of-the-weekmemorials
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Liturgical Day of the Week Safe to Use in 2026?

Generally Safe

Score 100/100

Liturgical Day of the Week has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The liturgical-day-of-the-week plugin version 2.0.2 exhibits a generally good security posture with no known historical vulnerabilities and a commitment to using prepared statements for SQL queries. The static analysis also indicates that all identified entry points (shortcodes) have a low risk of immediate exploitation due to the absence of direct vulnerabilities in the analyzed code signals. However, there are significant areas for concern. Notably, the taint analysis revealed two flows with unsanitized paths, which, while not flagged as critical or high severity in this analysis, represent a potential pathway for attackers to inject malicious code or manipulate data if these paths are not properly handled. Furthermore, the plugin has a concerning lack of security checks, with zero nonce checks and zero capability checks across its entry points. This absence of authorization and integrity checks makes the shortcodes, and potentially other, less obvious, entry points susceptible to unauthorized access and manipulation, especially if the plugin's functionality is sensitive. While the absence of dangerous functions and external HTTP requests is positive, the identified taint flows and the complete lack of security checks are critical weaknesses that require immediate attention.

Key Concerns

  • Flows with unsanitized paths (Taint Analysis)
  • 0 Nonce checks on entry points
  • 0 Capability checks on entry points
  • Only 63% of outputs properly escaped
Vulnerabilities
None known

Liturgical Day of the Week Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Liturgical Day of the Week Release Timeline

v2.0.1
v2.0.0
v1.0.1
Code Analysis
Analyzed Apr 16, 2026

Liturgical Day of the Week Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
10 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

63% escaped16 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
bearlydougplugins_about (functions-bd.php:56)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Liturgical Day of the Week Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[liturgicaldotw] _shortcodes.php:5
[liturgicalcolors] _shortcodes.php:95
WordPress Hooks 4
actionadmin_menufunctions-bd.php:49
actionadmin_menuldotw.php:61
actionadmin_enqueue_scriptsldotw.php:67
actionwp_enqueue_scriptsldotw.php:90
Maintenance & Trust

Liturgical Day of the Week Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 28, 2026
PHP min version8.0
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Liturgical Day of the Week Developer Profile

Douglas "BearlyDoug" Hazard

4 plugins · 50 total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Liturgical Day of the Week

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/liturgical-day-of-the-week/includes/_CSS-ldotw.css/wp-content/plugins/liturgical-day-of-the-week/includes/_CSS-bearlydoug.css/wp-content/plugins/liturgical-day-of-the-week/includes/_JS-bearlydoug.js
Script Paths
/wp-content/plugins/liturgical-day-of-the-week/includes/_JS-ldotwSCBuilder.js
Version Parameters
/wp-content/plugins/liturgical-day-of-the-week/includes/_CSS-ldotw.css?v=1

HTML / DOM Fingerprints

CSS Classes
bdCTRbdTabsbdRadiobdLabelbdTab-contentbdWrapperbdRowbdDColumn+1 more
HTML Comments
bdTabs Navigation Tabs BD LDotW Hidden Fields bdTabs Content Tabs
Data Attributes
ldotwtextWordingldotwtextTypeldotwtextCWheelldotwtextDioceseldotwdenominationWordingldotwtzone+7 more
Shortcode Output
<div id="ldotwDemo" class="ldotwDemo"<span id="ldotwSamplecwheel"<span id="ldotwSampleType"<span id="ldotwSampleTitle"
FAQ

Frequently Asked Questions about Liturgical Day of the Week