Nepali Date Security & Risk Analysis

wordpress.org/plugins/nepali-date

Nepali Date is a plugin to display the current nepali date on your website.

10 active installs v1.1 PHP + WP 2.8+ Updated Aug 5, 2012
date-nepalinepalinepali-date
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Nepali Date Safe to Use in 2026?

Generally Safe

Score 85/100

Nepali Date has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 13yr ago
Risk Assessment

The 'nepali-date' plugin version 1.1 demonstrates a mixed security posture. On the positive side, it has a very small attack surface with only one identified entry point (a shortcode) and no AJAX handlers or REST API routes. Furthermore, all SQL queries appear to be properly prepared, and there are no recorded vulnerabilities or CVEs, suggesting a generally stable and secure history. However, significant concerns arise from the static analysis of the code. The most critical issue is that 100% of its outputs are not properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. Additionally, the lack of nonce checks and capability checks on its shortcode entry point means that any user, regardless of their role or permissions, could potentially trigger its functionality, further exacerbating the XSS risk. The single file operation also warrants attention, though without further context, its specific risk is unclear but could be a vector if misused.

Key Concerns

  • 0% output escaping
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

Nepali Date Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Nepali Date Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Nepali Date Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped7 total outputs
Attack Surface

Nepali Date Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[nepalidate] nepalidate.php:34
WordPress Hooks 2
actionplugins_loadednepalidate.php:98
filterwidget_textnepalidate.php:99
Maintenance & Trust

Nepali Date Maintenance & Trust

Maintenance Signals

WordPress version tested3.4.2
Last updatedAug 5, 2012
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Nepali Date Developer Profile

govindak

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Nepali Date

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Shortcode Output
[nepalidate]
FAQ

Frequently Asked Questions about Nepali Date