
Moon Phase Widget Security & Risk Analysis
wordpress.org/plugins/moon-phase-widgetA sidebar widget to display the moon phase.
Is Moon Phase Widget Safe to Use in 2026?
Generally Safe
Score 85/100Moon Phase Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "moon-phase-widget" v1.0 plugin exhibits a mixed security posture. On the positive side, there are no known CVEs, suggesting a historical lack of severe, publicly disclosed vulnerabilities. The absence of external HTTP requests, file operations, and the adherence to prepared statements for all SQL queries are excellent security practices. This indicates a level of care in handling sensitive operations and data.
However, the static analysis reveals significant concerns. The presence of the `create_function` is a critical red flag, as it is deprecated and can lead to code injection vulnerabilities if user input is used within it. Furthermore, the extremely low percentage of properly escaped output (17%) is highly problematic, indicating a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. The lack of any nonce or capability checks across all entry points is also a major weakness, leaving the plugin susceptible to unauthorized actions and privilege escalation if any of its entry points were to become exposed or exploitable.
While the plugin has no recorded vulnerability history, this does not guarantee its current security. The identified code signals, particularly `create_function` and widespread unescaped output, represent immediate and serious risks that overshadow the clean vulnerability history. The plugin's strengths lie in its avoidance of external interactions and its SQL hygiene, but its weaknesses in output sanitization and lack of authorization checks create a substantial attack surface that requires immediate attention.
Key Concerns
- Use of deprecated and dangerous function: create_function
- Low percentage of properly escaped output (17%)
- No nonce checks across all entry points
- No capability checks across all entry points
Moon Phase Widget Security Vulnerabilities
Moon Phase Widget Code Analysis
Dangerous Functions Found
Output Escaping
Moon Phase Widget Attack Surface
WordPress Hooks 1
Maintenance & Trust
Moon Phase Widget Maintenance & Trust
Maintenance Signals
Community Trust
Moon Phase Widget Alternatives
The Moon – Current Phase and Next Eclipse
the-moon
Shows the current phase of The Moon, it's Zodiac sign and the date of the next lunar eclipse.
Moon Calendar Widget
calendrier-lunaire
Display the moon calendar of the day (moon phases, moon rise/set times, ...). Customize the widget (background/border/fonts color) to fit your needs !
WPZOOM Addons for Elementor – Starter Templates & Widgets
wpzoom-elementor-addons
Elementor templates and widgets - Import professionally designed page templates, sections, and widgets. Build stunning pages in minutes.
Star Addons for Elementor
star-addons-for-elementor
A collection of multiple addons for elementor website builder plugin. It also helps you to create template kits for elementor.
Moon Phases
moon-phases
Adds a sidebar widget that display the current moon phase.
Moon Phase Widget Developer Profile
2 plugins · 20 total installs
How We Detect Moon Phase Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
moon_widget_continermoon_widget_sizerid="moon_widget_continer"id="moon_widget_sizer"id="moon_widget_iframe"src="https://dianagarland.com/wdget_moon_phase/"