Posts On This Day Security & Risk Analysis

wordpress.org/plugins/posts-on-this-day

Widget to display a list of posts published "on this day" in years past. A good little bit of nostalgia for your blog.

60 active installs v1.5.7 PHP 8.3+ WP 5.6+ Updated Feb 27, 2026
on-this-daywidget
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Posts On This Day Safe to Use in 2026?

Generally Safe

Score 100/100

Posts On This Day has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "posts-on-this-day" plugin v1.5.7 demonstrates a strong security posture based on the provided static analysis. There are no identified attack surface entry points (AJAX, REST API, shortcodes, cron events), no dangerous function usage, and all SQL queries are properly prepared. Furthermore, the plugin shows a high percentage of properly escaped output and avoids file operations and external HTTP requests, all of which are positive security indicators. The absence of any recorded vulnerabilities in its history, including critical or high severity ones, further reinforces this assessment. This indicates diligent development practices and a lack of historical security weaknesses.

However, the static analysis does reveal a complete lack of nonce checks and capability checks across all components. While the current attack surface is zero, this absence represents a significant potential risk if any new entry points are introduced in future versions or if the plugin's functionality changes. The taint analysis also shows no flows were analyzed, which could be a limitation of the analysis tool or indicate a very small plugin footprint. Despite these concerns, the current version appears to be very secure due to its minimal exposed functionality and adherence to safe coding practices for the existing code.

Key Concerns

  • No nonce checks present
  • No capability checks present
  • No taint flows analyzed (potential gap)
Vulnerabilities
None known

Posts On This Day Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Posts On This Day Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
28 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

88% escaped32 total outputs
Attack Surface

Posts On This Day Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionwidgets_initposts-on-this-day.php:27
Maintenance & Trust

Posts On This Day Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 27, 2026
PHP min version8.3
Downloads3K

Community Trust

Rating100/100
Number of ratings2
Active installs60
Developer Profile

Posts On This Day Developer Profile

Jeremy Herve

11 plugins · 2K total installs

90
trust score
Avg Security Score
94/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Posts On This Day

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/posts-on-this-day/build/style.css/wp-content/plugins/posts-on-this-day/build/index.js
Script Paths
/wp-content/plugins/posts-on-this-day/build/index.js
Version Parameters
posts-on-this-day/build/style.css?ver=posts-on-this-day/build/index.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Posts On This Day