Logo Scheduler – Great for holidays, events, and more Security & Risk Analysis

wordpress.org/plugins/logo-scheduler-great-for-holidays-events-and-more

Change your logo on a schedule by saving different versions for holidays and special events. Set the dates and this plugin will switch them out.

100 active installs v1.2.3 PHP + WP 4.9.10+ Updated Jul 26, 2023
holidayholidayslogoschedulescheduler
85
A · Safe
CVEs total1
Unpatched0
Last CVEApr 26, 2023
Safety Verdict

Is Logo Scheduler – Great for holidays, events, and more Safe to Use in 2026?

Generally Safe

Score 85/100

Logo Scheduler – Great for holidays, events, and more has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Apr 26, 2023Updated 2yr ago
Risk Assessment

The "logo-scheduler-great-for-holidays-events-and-more" plugin v1.2.3 exhibits a mixed security posture. On the positive side, the plugin has a remarkably small attack surface with no apparent AJAX handlers, REST API routes, shortcodes, or cron events. This significantly limits the potential entry points for attackers. Furthermore, all SQL queries are confirmed to use prepared statements, which is a critical defense against SQL injection. The code also includes at least one capability check, indicating some awareness of WordPress's permission system.

However, the static analysis reveals a concerning weakness in output escaping, with only 36% of outputs being properly escaped. This significantly increases the risk of Cross-Site Scripting (XSS) vulnerabilities, especially given the plugin's history of a medium-severity XSS CVE. The taint analysis also identified one flow with unsanitized paths, though it was not flagged as critical or high severity. The plugin's vulnerability history, while having no currently unpatched CVEs, shows a past XSS vulnerability, reinforcing the concern about output sanitization.

In conclusion, while the plugin has strengths in its limited attack surface and secure SQL handling, the insufficient output escaping presents a notable risk. The past XSS vulnerability, coupled with the current analysis showing poor escaping, suggests a recurring pattern that requires attention. Users should be cautious and consider this plugin's potential for XSS, especially if it handles user-provided or dynamic content that is displayed on the frontend.

Key Concerns

  • Low output escaping (36%)
  • Taint flow with unsanitized paths
  • Past medium severity XSS vulnerability
Vulnerabilities
1

Logo Scheduler – Great for holidays, events, and more Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2023-30875medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Logo Scheduler <= 1.2.0 - Authenticated (Administrator+) Stored Cross-Site Scripting

Apr 26, 2023 Patched in 1.2.1 (272d)
Code Analysis
Analyzed Mar 16, 2026

Logo Scheduler – Great for holidays, events, and more Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
4 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

36% escaped11 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<search-list-table-display> (inc\admin\views\search-list-table-display.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Logo Scheduler – Great for holidays, events, and more Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionplugins_loadedinc\core\class-init.php:97
actionadmin_enqueue_scriptsinc\core\class-init.php:111
actionadmin_enqueue_scriptsinc\core\class-init.php:112
actionadmin_menuinc\core\class-init.php:115
actionadmin_initinc\core\class-init.php:116
actionadmin_initinc\core\class-init.php:117
actionadmin_noticesinc\core\class-init.php:120
actionwp_enqueue_scriptsinc\core\class-init.php:149
actionwp_enqueue_scriptsinc\core\class-init.php:150
actionwp_footerinc\core\class-init.php:153
Maintenance & Trust

Logo Scheduler – Great for holidays, events, and more Maintenance & Trust

Maintenance Signals

WordPress version tested
Last updatedJul 26, 2023
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs100
Developer Profile

Logo Scheduler – Great for holidays, events, and more Developer Profile

kizinko

1 plugin · 100 total installs

69
trust score
Avg Security Score
85/100
Avg Patch Time
272 days
View full developer profile
Detection Fingerprints

How We Detect Logo Scheduler – Great for holidays, events, and more

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/logo-scheduler-great-for-holidays-events-and-more/inc/admin/css/amwnlogos-admin.css/wp-content/plugins/logo-scheduler-great-for-holidays-events-and-more/inc/admin/js/jquery-ui-timepicker-addon.min.js/wp-content/plugins/logo-scheduler-great-for-holidays-events-and-more/inc/admin/css/jquery-ui.min.css/wp-content/plugins/logo-scheduler-great-for-holidays-events-and-more/inc/admin/css/jquery-ui-timepicker-addon.min.css
Script Paths
inc/admin/js/jquery-ui-timepicker-addon.min.js
Version Parameters
amwnlogos-admin?ver=jquery-ui-timepicker?ver=jquery-ui-theme-smoothness?ver=jquery-ui-timepicker?ver=

HTML / DOM Fingerprints

CSS Classes
amwnlogos-admin
HTML Comments
<!-- BEGIN Logo Scheduler Options --><!-- END Logo Scheduler Options -->
Data Attributes
data-amwnlogos-namedata-amwnlogos-start-datedata-amwnlogos-end-datedata-amwnlogos-repeatdata-amwnlogos-logo-holderdata-amwnlogos-replacement-logo+1 more
JS Globals
amwnlogos_nameamwnlogos_start_dateamwnlogos_end_dateamwnlogos_repeatamwnlogos_logo_holderamwnlogos_replacement_logo+1 more
FAQ

Frequently Asked Questions about Logo Scheduler – Great for holidays, events, and more